Re: PCI DSS compliance scans
Ed Heron <[email protected]> Fri, 08 Jun 2012 08:50:03 -0600
| Newsgroups | gmane.org.user-groups.nmlug |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 2012-06-07 at 17:27 -0400, nick pitlosh wrote: > A long while ago I did these for a carrier data center. It's actually > a racket of sorts. Essentially you need to set up an automated process > for picking up unauthorized wifi frames and mac addresses. Many > network sniffers do this however you're missing the fundamental idea > that sec scanning is a generally passive process, eliminating any > opportunity for active malevolent communication. A good network is > always open and always listening. Review your strategy. If you're > looking for pci scans, go get certified yourself, or just stay ahead > of the curve. Never assume. My strategy for wireless is just put it outside the firewall... By "sec scanning is a generally passive process", I'm guessing you're talking intrusion detection/prevention systems? > That's what the bad guys are hoping to teach you. Learn it before you > are bent over. Also segment your network. I used to segment just for performance reasons, but it is handy to ensure a failure only takes down part of your system. > On Thursday, June 7, 2012, Ed Heron wrote: > While this isn't completely on topic, I use Linux for my > firewalls and > I expect/hope people on this list are more knowledgeable... > > Does anybody know of a PCI (Payment Card Industry) ASV > (Approved > Scanning Vendor) that can do a wireless scan? It seems that > all the PCI > ASV's that I can find with Google are external scans only. > Aren't we > supposed to do wireless scans quarterly? Though I'm not > confident the > scans could find unauthorized wireless access points if the > people > setting them up weren't stupid about it... > > I'm supposed to do a physical scan for unauthorized equipment > but it > would be so easy to 'see me coming' if they only attached them > at > restricted times, though obviously that would make them less > convenient > (I have to assume an unauthorized WAP would be there for > convenience). > Also, if our employees have any idea how to setup a WAP, I'd > think I'd > have have gotten some hint before. (and if they are hiding > technical > abilities, I'd think they could get a better paying job) > > I don't think the company I work for is a sufficiently large > target to > entice people to break in to tap into my network or tap into > the > Internet circuit. Certainly, with the company being in > multiple states, > other than a quick remote scan for new equipment, I can't do > much. > > I hope that all we're really looking for is a third party to > certify I > don't have glaringly obvious wireless security holes. I try > to get the > laptop people to turn off their wireless cards when they hard > wire into > the network... > > Anybody have experience with any PCI ASV's for those external > scans? _______________________________________________ NMLUG mailing list [email protected] http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug