Transcription of Penetration Testing Guidance - PCI Security Standards
{{id}} {{{paragraph}}}
Standard: PCI Data Security Standard (PCI DSS) Version: Date: September 2017 Author: Penetration Test Guidance Special Interest Group PCI Security Standards Council Information Supplement: Penetration Testing Guidance Information Supplement Penetration Testing Guidance September 2017 The intent of this document is to provide supplemental information. Information provided here does not replace or supersede requirements in any PCI SSC Standard. i Document Changes Date Document Version Description Pages March 2015 Initial release All September 2017 A number of clarifications, including: Clarified intent of social engineering in Terminology. Clarified Guidance on black-box Testing . Restructured Section for better flow, and clarified language describing intent of PCI DSS Requirement Expanded Guidance related to back-end APIs. Updated references to PCI SSC resources.
(including scoping the test, critical systems to test, application and network-layer test inclusions, etc.). The document then moves on to practical guidance on selecting a penetration tester, methodologies that are used before, during, and after a test, guidelines for reporting and evaluating test results. The document concludes
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}