Results 1 to 4 of 4

Hybrid View

  1. #1
    Join Date
    Feb 2007
    Posts
    53
    Plugin Contributions
    0

    Default PCI Compliance-Site Scanning, McAfee, etc

    I am working towards getting my website PCI Compliant. I know authorize.net and my merchant bank are both PCI Compliant. Also, I don't store credit cards on my website or office computer and I have a private SSL.
    I am using a shared plan with HostGator but am switching to a VPS hosting plan with HostGator.
    I have done a lot of research and have posted on here before and it seems a missing piece is I have to have a scan done of my website and also fill out a huge questionaire and then submit it along with my scan results to my merchant bank to become PCI Compliant.
    Am I correct about the above?
    What this comes back to is site scanning. I have looked at many services including McAfee, Security Metrics, ControlScan, and TrustWave.
    Most of my research so far has been with McAfee. They have a service for $319/yr which includes quarterly scans and manual scans as often as I desire. The are no logos with it for my website.
    They also offer a full service for $959/year or $1289/2 years for a discount. This full service includes their PCI Scanning but also it includes their McAfee Secure scanning. The scanning is done daily and also with the McAfee Secure scanning you get a McAfee trust logo for your website.
    With HostGator's shared plan for free I get the McAfee secure scanning with logo and it includes the PCI scanning but also once I change to VPS hosting I likely will lose this.
    I am interested in opinions of the various options for scanning, MCafee, Security Metrics, and ControlScan, and also Trustwave and also if I go with MCafee is their higher plan worth it? They claim I'll see an increase in sales but is that likely to be true? Thank you for your thoughts on the above.

  2. #2
    Join Date
    Aug 2005
    Location
    Arizona
    Posts
    27,755
    Plugin Contributions
    9

    Default Re: PCI Compliance-Site Scanning, McAfee, etc

    fill out a huge questionaire
    Check the PCI/DSS site for the "Self Assessment" one answer them correctly and you should be compliant as a merchant by default because you are using a gateway and not storing any CC details

    This is just my opinion
    I really think that most of this for the small online merchant as youself that are using SSL and a gateway is a scam and unnecessary.
    The whole thing was designed to control large concerns that do store CC details the majority of it does not apply to those that do not.

    See the self assessment and see if you don't agree
    Zen-Venom Get Bitten

  3. #3
    Join Date
    Feb 2007
    Posts
    53
    Plugin Contributions
    0

    Default Re: PCI Compliance-Site Scanning, McAfee, etc

    I'll take a look at it. It just seems it's hard on the small merchant. I see companies offering to do offsite credit card processing to save you hundreds of thousands of dollars. I think some of that is a scam. I just don't want to chance not being compliant but will look at the site and questionaire.

  4. #4
    Join Date
    Mar 2004
    Posts
    16,042
    Plugin Contributions
    5

    Default Re: PCI Compliance-Site Scanning, McAfee, etc

    If you go with McAfee dont go for the big package,
    their scans are a joke and are NOT done daily
    Zen cart PCI compliant Hosting

 

 

Similar Threads

  1. v151 How do I check my site for PCI Compliance?
    By riolas in forum General Questions
    Replies: 6
    Last Post: 4 Jun 2016, 08:44 AM
  2. PCI Compliance issues reported by scanning company
    By NEAPMS in forum General Questions
    Replies: 5
    Last Post: 2 Sep 2013, 01:31 AM
  3. Replies: 4
    Last Post: 22 Apr 2009, 05:13 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg