Results 1 to 7 of 7
  1. #1
    Join Date
    Oct 2009
    Posts
    66
    Plugin Contributions
    0

    Default How do I check my site for PCI Compliance?

    HI,

    I have used QualysGuard PCI but that seems to check my hosting for PCI compliance.

    How do I check my actual site for PCI compliance?

    Thank you.

  2. #2
    Join Date
    Aug 2005
    Location
    Arizona
    Posts
    27,761
    Plugin Contributions
    9

    Default Re: How do I check my site for PCI Compliance?

    I believe that this is manual and involves the PCI SAQ - Self Assessment Questionnaire
    Zen-Venom Get Bitten

  3. #3
    Join Date
    Oct 2009
    Posts
    66
    Plugin Contributions
    0

    Default Re: How do I check my site for PCI Compliance?

    Hi,

    Thanks. So, there is no way to scan my site/pages to determine if it is PCI compliant?

  4. #4
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: How do I check my site for PCI Compliance?

    Quote Originally Posted by riolas View Post
    So, there is no way to scan my site/pages to determine if it is PCI compliant?
    Please explain EXACTLY what YOU think PCI compliance means.

    ... cuz I don't think you're thinking it means the same thing as we think it means.


    What exactly is the "business problem" you think you're solving by "scanning each page for compliance"? What exactly is this compliance YOU are referring to?
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  5. #5
    Join Date
    Oct 2009
    Posts
    66
    Plugin Contributions
    0

    Default Re: How do I check my site for PCI Compliance?

    Payment Card Industry Data Security Standard. Known as PCI DSS.

    Our site will have an official PFI report soon at the request of Visa and before they scan our site to ensure it passes their measures, I want to scan myself ahead of time to ensure it passes and doesn't contain any 'breaches'.

    I have already scanned our hosting and found possible problems there which are being fixed now but I want to know how I scan our site for possible beaches too.

    Thanks.

  6. #6
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: How do I check my site for PCI Compliance?

    Quote Originally Posted by riolas View Post
    Payment Card Industry Data Security Standard. Known as PCI DSS.

    Our site will have an official PFI report soon at the request of Visa and before they scan our site to ensure it passes their measures, I want to scan myself ahead of time to ensure it passes and doesn't contain any 'breaches'.

    I have already scanned our hosting and found possible problems there which are being fixed now but I want to know how I scan our site for possible beaches too.

    Thanks.
    If you want your own scans done independently of what your Visa service is doing, then you'll need to hire your own scanning vendor to have them do the scan for you.

    (Or you could set up your own separate server, configure it with professionally-purchased software that can do scans, learn how to do the scans, and then perform those scans. Then take the courses to study what the scan results mean and how to identify "real" issues vs "false positives". But all of that will cost you a *lot* more time and money than hiring someone who's already doing it professionally. I only mention it for the sake of thoroughness. I would say 99.9% of people would never dare take this on themselves unless it were part of their profession.)

    So, yes, the simple and most accurate and appropriate answer to your question is: hire someone.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  7. #7
    Join Date
    Apr 2006
    Location
    West Salem, IL
    Posts
    2,748
    Plugin Contributions
    0

    Default Re: How do I check my site for PCI Compliance?

    I agree with the Doctor, there is no tool you can use to scan your site yourself. If you are required by your merchant account to be scanned, then get scanned...when it fails, and it will fail, fix the problems...most of which will be things that the host needs to fix, and scan again until all your left with are the false positives and submit those. Then you can ready yourself for failing every quarter, over and over and over because the scan changes constantly and the scanning vendors are at times implementing rules into the scan that don't actually have an implementation date until sometime far out in the future, like a year away. enjoy.
    Mike
    GeekHost - Zen Cart Certified & PCI Compliant Hosting
    The Zen Cart Forum...Better than a monitor covered with post-it notes!

 

 

Similar Threads

  1. How do I disable PCI Compliance?
    By Ripper in forum General Questions
    Replies: 6
    Last Post: 1 Mar 2013, 08:30 AM
  2. PCI Compliance-Site Scanning, McAfee, etc
    By markw10 in forum General Questions
    Replies: 3
    Last Post: 18 Feb 2010, 06:48 AM
  3. Replies: 4
    Last Post: 22 Apr 2009, 05:13 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR