PCI DSS compliance scans
Ed Heron <[email protected]> Thu, 07 Jun 2012 12:35:49 -0600
| Newsgroups | gmane.org.user-groups.nmlug |
|---|---|
| Message-ID | <[email protected]> |
While this isn't completely on topic, I use Linux for my firewalls and I expect/hope people on this list are more knowledgeable... Does anybody know of a PCI (Payment Card Industry) ASV (Approved Scanning Vendor) that can do a wireless scan? It seems that all the PCI ASV's that I can find with Google are external scans only. Aren't we supposed to do wireless scans quarterly? Though I'm not confident the scans could find unauthorized wireless access points if the people setting them up weren't stupid about it... I'm supposed to do a physical scan for unauthorized equipment but it would be so easy to 'see me coming' if they only attached them at restricted times, though obviously that would make them less convenient (I have to assume an unauthorized WAP would be there for convenience). Also, if our employees have any idea how to setup a WAP, I'd think I'd have have gotten some hint before. (and if they are hiding technical abilities, I'd think they could get a better paying job) I don't think the company I work for is a sufficiently large target to entice people to break in to tap into my network or tap into the Internet circuit. Certainly, with the company being in multiple states, other than a quick remote scan for new equipment, I can't do much. I hope that all we're really looking for is a third party to certify I don't have glaringly obvious wireless security holes. I try to get the laptop people to turn off their wireless cards when they hard wire into the network... Anybody have experience with any PCI ASV's for those external scans? _______________________________________________ NMLUG mailing list [email protected] http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug