top of page
  • Facebook
  • Twitter
  • Linkedin
©
Search

Mandatory & Timely Risk Assessment & Management process requirement for PCI DSS Standards .

manju devaraj

Updated: Oct 6, 2020

Mandatory requirements around Scan & testing which has to be taken care .


1. Internal VA Scans

For all in Scope Systems, ex. Nessus

Quarterly

2. External ASV Scan

For Public interfaces of CDE , Ex. Qualys

Quarterly

3.Wireless Scan

If AWS & other PCI DSS DC provider are used it will be not applicable for customer , AWS & other SP might be covering this part already for customer under Infra /platform as a service .

Quarterly

4.Internal PT

Web & Network layer along with Segmentation test(half Yearly) .

Yearly

5.External PT

Both Web & Network layer test to be executed .

Yearly

6.Data Discovery Scan on CDE Server’s

Scan performed on CDE to show there is no CHD Data on other systems than what was defined to store such .

Yearly

Note :

All the above 4 Reports should be in good state .

· ASV Scan , PT - All High & medium Risk should be remediated . Retesting report required to prove the same .

· Internal Scan - All High to be remediated, rescan report/results required post remediation .

 
 
 

Recent Posts

See All

802.11 Wi-Fi Architecture

Introduction Wireless networks often extend an existing wired infrastructure. The wired infrastructure may be quite complex to begin...

Yorumlar


Contact Us

Thanks for submitting!

REGIONAL OFFICES : 

HQ (SG) :  Secure Logic Pte Ltd.

11 Floor, Wisma Atria, 435 Orchard Road,Singapore, 238877

Tel: +65 92390085 

(IN)  : Secure Logic India Private Ltd. 

 # 77, Condor Spinn , 1st Floor , Residency Rd, Shanthala Nagar, Ashok Nagar, Bengaluru, Karnataka 560025

Tel: +91 80 42170170 

(MY) : Secure Logic InfoSec Sdn. Bhd.

1 Sentral, Level 16, Jalan Stesen Sentral 5, KL Sentral, Kuala Lumpur, 50470 Malaysia

Tel : +60 19-370 0420

International Contact : 

Tel : +1 559 345 5998

     

Email:

           sales@securelogicgroup.asia

           hr@securelogicgroup.co

           info@securelogicgroup.asia

           sales@securelogicgroup.co

            

© 2023 Secure Logic 

https://www.securelogicgroup.co

Privacy Policy 

bottom of page