Re: PCI DSS compliance scans

Ed Heron <[email protected]> Fri, 08 Jun 2012 08:50:03 -0600
Newsgroups gmane.org.user-groups.nmlug
Message-ID <[email protected]>
On Thu, 2012-06-07 at 17:27 -0400, nick pitlosh wrote:
> A long while ago I did these for a carrier data center. It's actually
> a racket of sorts. Essentially you need to set up an automated process
> for picking up unauthorized wifi frames and mac addresses. Many
> network sniffers do this however you're missing the fundamental idea
> that sec scanning is a generally passive process, eliminating any
> opportunity for active malevolent communication. A good network is
> always open and always listening. Review your strategy. If you're
> looking for pci scans, go get certified yourself, or just stay ahead
> of the curve. Never assume.

  My strategy for wireless is just put it outside the firewall...

  By "sec scanning is a generally passive process", I'm guessing you're
talking intrusion detection/prevention systems?

> That's what the bad guys are hoping to teach you. Learn it before you
> are bent over. Also segment your network. 

  I used to segment just for performance reasons, but it is handy to
ensure a failure only takes down part of your system.

> On Thursday, June 7, 2012, Ed Heron wrote:
>          While this isn't completely on topic, I use Linux for my
>         firewalls and
>         I expect/hope people on this list are more knowledgeable...
>         
>          Does anybody know of a PCI (Payment Card Industry) ASV
>         (Approved
>         Scanning Vendor) that can do a wireless scan?  It seems that
>         all the PCI
>         ASV's that I can find with Google are external scans only.
>          Aren't we
>         supposed to do wireless scans quarterly?  Though I'm not
>         confident the
>         scans could find unauthorized wireless access points if the
>         people
>         setting them up weren't stupid about it...
>         
>          I'm supposed to do a physical scan for unauthorized equipment
>         but it
>         would be so easy to 'see me coming' if they only attached them
>         at
>         restricted times, though obviously that would make them less
>         convenient
>         (I have to assume an unauthorized WAP would be there for
>         convenience).
>         Also, if our employees have any idea how to setup a WAP, I'd
>         think I'd
>         have have gotten some hint before.  (and if they are hiding
>         technical
>         abilities, I'd think they could get a better paying job)
>         
>          I don't think the company I work for is a sufficiently large
>         target to
>         entice people to break in to tap into my network or tap into
>         the
>         Internet circuit.  Certainly, with the company being in
>         multiple states,
>         other than a quick remote scan for new equipment, I can't do
>         much.
>         
>          I hope that all we're really looking for is a third party to
>         certify I
>         don't have glaringly obvious wireless security holes.  I try
>         to get the
>         laptop people to turn off their wireless cards when they hard
>         wire into
>         the network...
>         
>          Anybody have experience with any PCI ASV's for those external
>         scans?



_______________________________________________
NMLUG mailing list
[email protected]
http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug