PCI DSS compliance scans

Ed Heron <[email protected]> Thu, 07 Jun 2012 12:35:49 -0600
Newsgroups gmane.org.user-groups.nmlug
Message-ID <[email protected]>
  While this isn't completely on topic, I use Linux for my firewalls and
I expect/hope people on this list are more knowledgeable...

  Does anybody know of a PCI (Payment Card Industry) ASV (Approved
Scanning Vendor) that can do a wireless scan?  It seems that all the PCI
ASV's that I can find with Google are external scans only.  Aren't we
supposed to do wireless scans quarterly?  Though I'm not confident the
scans could find unauthorized wireless access points if the people
setting them up weren't stupid about it...

  I'm supposed to do a physical scan for unauthorized equipment but it
would be so easy to 'see me coming' if they only attached them at
restricted times, though obviously that would make them less convenient
(I have to assume an unauthorized WAP would be there for convenience).
Also, if our employees have any idea how to setup a WAP, I'd think I'd
have have gotten some hint before.  (and if they are hiding technical
abilities, I'd think they could get a better paying job)

  I don't think the company I work for is a sufficiently large target to
entice people to break in to tap into my network or tap into the
Internet circuit.  Certainly, with the company being in multiple states,
other than a quick remote scan for new equipment, I can't do much.

  I hope that all we're really looking for is a third party to certify I
don't have glaringly obvious wireless security holes.  I try to get the
laptop people to turn off their wireless cards when they hard wire into
the network...

  Anybody have experience with any PCI ASV's for those external scans?


_______________________________________________
NMLUG mailing list
[email protected]
http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug