Example: bachelor of science

Penetration Testing Guidance - PCI Security Standards

Standard: PCI Data Security Standard (PCI DSS) Version: Date: September 2017 Author: Penetration Test Guidance Special Interest Group PCI Security Standards Council Information Supplement: Penetration Testing Guidance Information Supplement Penetration Testing Guidance September 2017 The intent of this document is to provide supplemental information. Information provided here does not replace or supersede requirements in any PCI SSC Standard. i Document Changes Date Document Version Description Pages March 2015 Initial release All September 2017 A number of clarifications, including: Clarified intent of social engineering in Terminology.

Standard: PCI Data Security Standard (PCI DSS) Version: 1.1 Date: September 2017 Author: Penetration Test Guidance Special Interest Group PCI Security Standards Council . Information Supplement: Penetration Testing Guidance

Tags:

  Security, Standards, Testing, Guidance, Penetration, Pci security standards, Penetration testing guidance

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Penetration Testing Guidance - PCI Security Standards

1 Standard: PCI Data Security Standard (PCI DSS) Version: Date: September 2017 Author: Penetration Test Guidance Special Interest Group PCI Security Standards Council Information Supplement: Penetration Testing Guidance Information Supplement Penetration Testing Guidance September 2017 The intent of this document is to provide supplemental information. Information provided here does not replace or supersede requirements in any PCI SSC Standard. i Document Changes Date Document Version Description Pages March 2015 Initial release All September 2017 A number of clarifications, including: Clarified intent of social engineering in Terminology.

2 Clarified Guidance on black-box Testing . Restructured Section for better flow, and clarified language describing intent of PCI DSS Requirement Expanded Guidance related to back-end APIs. Updated references to PCI SSC resources. Minor grammatical updates. Various Information Supplement Penetration Testing Guidance September 2017 The intent of this document is to provide supplemental information. Information provided here does not replace or supersede requirements in any PCI SSC Standard. ii Table of Contents 1 Introduction .. 4 Objective .. 4 Intended Audience.

3 4 4 Navigating this Document .. 5 2 Penetration Testing Components .. 6 How does a Penetration test differ from a vulnerability scan? .. 6 Scope .. 7 External Penetration Test .. 8 Internal Penetration Test .. 8 Testing Segmentation Controls .. 8 Critical Systems .. 9 Application-Layer and Network-Layer Testing .. 9 Authentication .. 9 PA-DSS Compliant Applications .. 9 Web Applications .. 10 Separate Testing Environment .. 10 Segmentation Checks .. 10 Social Engineering .. 11 What is considered a significant change ? .. 11 3 Qualifications of a Penetration Tester.

4 12 12 Past Experience .. 12 4 Methodology .. 14 Pre-Engagement .. 14 Scoping .. 14 Documentation .. 14 Rules of Engagement .. 15 Third-Party-Hosted / Cloud Environments .. 16 Success Criteria .. 16 Review of Past Threats and Vulnerabilities .. 16 Avoid scan interference on Security appliances.. 17 Engagement: Penetration 17 Application Layer .. 18 Network 18 Segmentation .. 19 What to do when cardholder data is encountered .. 19 Information Supplement Penetration Testing Guidance September 2017 The intent of this document is to provide supplemental information.

5 Information provided here does not replace or supersede requirements in any PCI SSC Standard. iii Post-Exploitation .. 19 Post-Engagement .. 19 Remediation Best Practices .. 19 Retesting Identified Vulnerabilities .. 20 Cleaning up the Environment .. 20 Additional Resources .. 20 5 Reporting and Documentation .. 21 Identified Vulnerability Reporting .. 21 Assigning a Severity 21 Industry Standard References .. 22 Reporting Guidelines .. 22 Penetration Test Report Outline .. 22 Retesting Considerations and Report Outline .. 23 Evidence retention .. 24 What is considered evidence?

6 24 Retention .. 24 Penetration Test Report Evaluation Tool .. 25 6 Case Studies / Scoping Examples .. 27 E-commerce Penetration Test Case Study .. 27 Hosting Provider Penetration Test Case Study .. 30 Retail Merchant Penetration Test Case Study .. 35 Appendix A: Quick-Reference Table to Guidance on PCI DSS Penetration Testing Requirements .. 40 Acknowledgements .. 41 About the PCI Security Standards Council .. 43 Information Supplement Penetration Testing Guidance September 2017 The intent of this document is to provide supplemental information. Information provided here does not replace or supersede requirements in any PCI SSC Standard.

7 4 1 Introduction Objective This information supplement provides general Guidance and guidelines for Penetration Testing . The Guidance focuses on the following: Penetration Testing Components: Understanding of the different components that make up a Penetration test and how this differs from a vulnerability scan including scope, application and network-layer Testing , segmentation checks, and social engineering. Qualifications of a Penetration Tester: Determining the qualifications of a Penetration tester, whether internal or external, through their past experience and certifications.

8 Penetration Testing Methodologies: Detailed information related to the three primary parts of a Penetration test: pre-engagement, engagement, and post-engagement. Penetration Testing Reporting Guidelines: Guidance for developing a comprehensive Penetration test report that includes the necessary information to document the test as well as a checklist that can be used by the organization or the assessor to verify whether the necessary content is included. The information in this document is intended as supplemental Guidance and does not supersede, replace, or extend PCI DSS requirements.

9 The current version of PCI DSS at the time of publication is ; however, the general pri nciples and practices offered here may also be applicable to other versions of PCI DSS. Intended Audience This Guidance is intended for entities that are required to conduct a Penetration test whether they use an internal or external resource. In addition, this document is intended for companies that specialize in offering Penetration test services, and for assessors who help scope Penetration tests and review final test reports. The Guidance is applicable to organizations of all sizes, budgets, and industries.

10 Terminology The following terms are used throughout this document: Application-layer Testing : Testing that typically includes websites, web applications, thick clients, or other applications. Black-box Testing : Testing performed without prior knowledge of the internal structure/design/implementation of the object being tested. Common Vulnerability Scoring System (CVSS): Provides an open framework for communicating the characteristics and impacts of IT vulnerabilities. Grey-box Testing : Testing performed with partial knowledge of the internal structure/design/implementation of the object being tested.


Related search queries