December 12, 2017 • Published by Duane Reeves
Compliance • Network Security • Vulnerability Management
If your business accepts credit card payments, there’s a strong chance you need to undergo a penetration test to be compliant with the PCI DSS. Unfortunately, the penetration test cost can be a sore spot for many business leaders.
Many ask, “Is the test really necessary?” and “How often must we do it?”
The primary driver behind these two questions is almost always the penetration test cost. Due to their manual nature, penetration tests are more time-intensive to conduct than other security tests such as vulnerability scans.
Penetration tests have always had a higher price tag, but their overall cost to you is about to increase in 2018.
In September 2017, the PCI Security Standards Council issued a comprehensive Penetration Test Guidance document to help organizations fully realize the test’s security benefits. Prior to this guidance, many pen tests were conducted under the assumption that validating network segmentation was the singular goal.
According to the new guidance, the penetration test should go well beyond segmentation validation to ensure that all devices within the cardholder data environment (CDE) are truly off-limits to data thieves. This means that along with testing your security barriers remotely, your penetration testing vendor may also need to conduct an on-site visit.
The Penetration Testing Guidance, Section 2.2.2 makes it very clear:
“In cases where there is an internal CDE perimeter, the scope of testing will need to consider the CDE perimeter as well as critical systems within and outside of the CDE.”
This is a departure from the previous guidance, which only required that the segmentation of the CDE from non-CDE be tested.
Penetration testing isn’t an option. As a merchant, your business will be expected to undergo these tests at your expense. However, there are ways to curb your spending in this area.
Here are three tips for containing your penetration testing spend in 2018 and beyond:
In today’s complex IT environments, penetration testing is a must for not only PCI compliance, but a strengthened overall security posture. Want to learn more about the value of pen testing for your business? Click here or give us a call at 800-825-3301, ext. 2. We’re happy to help.