官术网_书友最值得收藏!

PCI penetration testing guide

Things just got real for companies that need to comply with PCI requirements. Not only is PCI v3.2 mandated, the PCI Standards Security Council has issued guidance on using penetration testing as part of vulnerability-management programs.

In April 2016, the Payment Card Industry Security Standards Council (PCI SSC) released PCI Data Security Standard (PCI DSS) version 3.2. With the updates came clarification to requirements, additional guidance, and seven additional new requirements. 

To address issues related to cardholder data breaches and protect against existing exploits, PCI DSS v.3.2 includes various changes, most of which are specific to service providers. This includes new penetration testing requirements that now require segmentation testing for Service Providers to now be performed at least every six months or after any significant changes to segmentation controls/methods. In addition, there are several requirements to ensure that service providers are continuously monitoring and maintaining critical security controls throughout the year.

主站蜘蛛池模板: 齐河县| 五大连池市| 大渡口区| 河西区| 宾川县| 商丘市| 安丘市| 景宁| 津市市| 临漳县| 泽普县| 嘉禾县| 襄樊市| 汾阳市| 三穗县| 将乐县| 耿马| 东乡县| 琼中| 平江县| 成安县| 嵊州市| 弥渡县| 宁晋县| 晋宁县| 伽师县| 正定县| 梁平县| 嘉峪关市| 错那县| 泰顺县| 鹤岗市| 日土县| 唐海县| 新平| 江源县| 临沭县| 无锡市| 灯塔市| 当阳市| 通榆县|