SlideShare a Scribd company logo
Protect Cardholder Data and Maintain PCI Compliance with PCI Penetration Testing
PCI DSS (Payment Card Industry Data
Security Standard)
• Requirements and guidelines to ensure credit card information is
properly secured
• Hot topic due to recent large scale payment card data breaches
• Not only retailers are affected
• Any organization that takes credit card payments should be in
compliance with latest PCI guidance, PCI DSS 3.1
– Zoos
– Airlines
– Banks
– Etc.
PCI DSS Version 3.1
• Effective July 1, 2015
• Includes minor updates and clarifications
– Addresses vulnerabilities within the SSL encryption protocol that can put
payment data at risk
• Requirements 11.3.1 and 11.3.2 encourage penetration testing
annually or after any significant change to IT environment
– Can include any upgrade or modification that could affect the security of
cardholder data
– Aims to ensure that controls assumed to be in place continue to work
effectively after updates
Where Companies Fail
“Compliance with the Payment Card Industry Data Security Standard
continues to improve, but four out of five companies still fail at
interim assessment. This indicates that they’ve failed to sustain the
security controls they put in place.”
Verizon 2015 PCI Compliance Report
• Find and fix your vulnerabilities before an attacker does
– Vulnerability scanning alone is not sufficient
– Penetration testing reduces false positive results by discovering which
weaknesses could actually result in an exploit
• Maintain the controls put in place for continued security
TraceSecurity PCI Penetration Testing
• Follows PCI guideline best practice methodology to include a/an:
– Engagement Interview
– Network Documentation Collection
– Network Scope
– Segmentation Checks
– Application and Network Testing
– Immediate Notification of Critical Risks and/or Encountering Cardholder Data
– Post-Engagement Retesting and Environment Clean-Up
• PCI test results are provided in an extensive report
TraceSecurity PCI Penetration Testing (cont’d)
• Better equips organizations to prevent cybersecurity attacks and
maintain PCI compliance
• Since 2004, TraceSecurity has performed nearly 10,000
penetration tests
• Our information security analysts maintain certifications suggested
by PCI guidelines that include but are not limited to:
– Offensive Security Certified Professional (OSCP)
– Certified Ethical Hacker (CEH)
Educational Webinar and Blog
• Join TraceSecurity for a free webinar. Learn how you can protect
your customers’ payment data and comply with new PCI
standards.
– This webinar explores some of today’s most publicized card data breaches
and discusses how organizations can effectively evaluate and test the security
of both internal and external systems that are involved in the processing or
protection of cardholder data to ensure they maintain PCI compliance.
• Read TraceSecurity's blog titled “TraceSecurity PCI Penetration
Testing Meets PCI DSS 3.1.”
CLICK HERE TO
REGISTER/WATCH
CLICK HERE TO READ
BLOG
thought leadership
webinars on-demand
our blog
our monthly newsletter
www.tracesecurity.com ©2015 TraceSecurity, Inc. All rights reserved worldwide.
Connect with us!
DOWNLOAD
WATCH
READ
RECEIVE
Access more educational content from TraceSecurity,

More Related Content

PPTX
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
PDF
Broadening Your Cybersecurity Mindset
PPTX
Card Data Discovery and PCI DSS
PPTX
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
PPTX
Log Monitoring and File Integrity Monitoring
PPTX
How to do pci compliance in google apps presentation
PDF
How to do pci compliance in google apps
PDF
Master Class Cyber Compliance IE Law School IE Busines School
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
Broadening Your Cybersecurity Mindset
Card Data Discovery and PCI DSS
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
Log Monitoring and File Integrity Monitoring
How to do pci compliance in google apps presentation
How to do pci compliance in google apps
Master Class Cyber Compliance IE Law School IE Busines School

What's hot (19)

PDF
Hernan huwyler - Recovering From a Breach
PDF
Qa Financials - 10 Smart Controls for Software Development
PDF
PCI Certification and remediation services
PDF
Digital defence ds-vciso-supplychain
PPTX
Continual Compliance Monitoring– PCI DSS, HIPAA, FERC/NERC, EI3PA, ISO 27001 ...
PPTX
Log Monitoring, FIM– PCI DSS, ISO 27001, HIPAA, FISMA and EI3PA
PPTX
Integrated Compliance
PPTX
PCI DSSand PA DSS
DOC
Uop cis 349 final exam guide set 1 new
PPTX
PCI DSS and PA DSS
PDF
Metric stream elevating your compliance program with technology
PDF
Outpost24 Webinar - To agent or not to agent
PPTX
What Data Center Compliance Means for Your Business
PPTX
PCI Compliance in the Cloud
PPTX
General Data Protection Regulation (GDPR)
PPTX
EU's General Data Protection Regulation (GDPR)
PPT
Audit Practice at CipherTechs
PDF
Boards of Directors and GDPR Prof. Hernan Huwyler, MBA CPA
PPTX
Tymor Total Care
Hernan huwyler - Recovering From a Breach
Qa Financials - 10 Smart Controls for Software Development
PCI Certification and remediation services
Digital defence ds-vciso-supplychain
Continual Compliance Monitoring– PCI DSS, HIPAA, FERC/NERC, EI3PA, ISO 27001 ...
Log Monitoring, FIM– PCI DSS, ISO 27001, HIPAA, FISMA and EI3PA
Integrated Compliance
PCI DSSand PA DSS
Uop cis 349 final exam guide set 1 new
PCI DSS and PA DSS
Metric stream elevating your compliance program with technology
Outpost24 Webinar - To agent or not to agent
What Data Center Compliance Means for Your Business
PCI Compliance in the Cloud
General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)
Audit Practice at CipherTechs
Boards of Directors and GDPR Prof. Hernan Huwyler, MBA CPA
Tymor Total Care
Ad

Similar to Protect Cardholder Data and Maintain PCI Compliance with PCI Penetration Testing (20)

PDF
PCI DSS and PA DSS Version 3.0 Changes
PPTX
Is your business PCI DSS compliant? You’re digging your own grave if not
PPTX
What Everybody Ought to Know About PCI DSS and PA-DSS
PPTX
PCI DSS & PA DSS Version 3.0
PDF
Reduce PCI Scope - Maximise Conversion - Whitepaper
PDF
PCI-DSS for IDRBT
PPTX
PCI DSS & PA DSS Version 3.0 Changes Webinar
PDF
PCI DSS: What it is, and why you should care
PDF
PCI DSS 3.0 Overview and Key Updates
PDF
Pci dss v3-2-1
PDF
Understanding Your PCI DSS Guidelines: Successes and Failures
PDF
Requirements and Security Assessment Procedure for C7 To Be PCI DSS Compliant
PPTX
SFISSA - PCI DSS 3.0 - A QSA Perspective
DOCX
PCI DSS 6 Key Objectives You Must Know for Compliance.docx
PDF
Adventures in PCI Wonderland
PDF
MTBiz May-June 2019
PPTX
Making Compliance Business as Usual
PPTX
Securing Your Customers' Credit Card Information
PPTX
PCI DSS 4.0 Webinar Final.pptx
PPTX
PruebaJLF.pptx
PCI DSS and PA DSS Version 3.0 Changes
Is your business PCI DSS compliant? You’re digging your own grave if not
What Everybody Ought to Know About PCI DSS and PA-DSS
PCI DSS & PA DSS Version 3.0
Reduce PCI Scope - Maximise Conversion - Whitepaper
PCI-DSS for IDRBT
PCI DSS & PA DSS Version 3.0 Changes Webinar
PCI DSS: What it is, and why you should care
PCI DSS 3.0 Overview and Key Updates
Pci dss v3-2-1
Understanding Your PCI DSS Guidelines: Successes and Failures
Requirements and Security Assessment Procedure for C7 To Be PCI DSS Compliant
SFISSA - PCI DSS 3.0 - A QSA Perspective
PCI DSS 6 Key Objectives You Must Know for Compliance.docx
Adventures in PCI Wonderland
MTBiz May-June 2019
Making Compliance Business as Usual
Securing Your Customers' Credit Card Information
PCI DSS 4.0 Webinar Final.pptx
PruebaJLF.pptx
Ad

Recently uploaded (20)

PDF
Nekopoi APK 2025 free lastest update
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 41
PDF
Softaken Excel to vCard Converter Software.pdf
PPT
Introduction Database Management System for Course Database
PDF
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
PPTX
ai tools demonstartion for schools and inter college
PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PPTX
ISO 45001 Occupational Health and Safety Management System
PDF
PTS Company Brochure 2025 (1).pdf.......
PDF
Upgrade and Innovation Strategies for SAP ERP Customers
PPTX
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PPTX
Odoo POS Development Services by CandidRoot Solutions
PDF
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
PPTX
ManageIQ - Sprint 268 Review - Slide Deck
PPTX
history of c programming in notes for students .pptx
PDF
Understanding Forklifts - TECH EHS Solution
PPTX
VVF-Customer-Presentation2025-Ver1.9.pptx
PDF
System and Network Administration Chapter 2
PDF
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
Nekopoi APK 2025 free lastest update
Internet Downloader Manager (IDM) Crack 6.42 Build 41
Softaken Excel to vCard Converter Software.pdf
Introduction Database Management System for Course Database
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
ai tools demonstartion for schools and inter college
Which alternative to Crystal Reports is best for small or large businesses.pdf
ISO 45001 Occupational Health and Safety Management System
PTS Company Brochure 2025 (1).pdf.......
Upgrade and Innovation Strategies for SAP ERP Customers
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
Odoo POS Development Services by CandidRoot Solutions
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
ManageIQ - Sprint 268 Review - Slide Deck
history of c programming in notes for students .pptx
Understanding Forklifts - TECH EHS Solution
VVF-Customer-Presentation2025-Ver1.9.pptx
System and Network Administration Chapter 2
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus

Protect Cardholder Data and Maintain PCI Compliance with PCI Penetration Testing

  • 2. PCI DSS (Payment Card Industry Data Security Standard) • Requirements and guidelines to ensure credit card information is properly secured • Hot topic due to recent large scale payment card data breaches • Not only retailers are affected • Any organization that takes credit card payments should be in compliance with latest PCI guidance, PCI DSS 3.1 – Zoos – Airlines – Banks – Etc.
  • 3. PCI DSS Version 3.1 • Effective July 1, 2015 • Includes minor updates and clarifications – Addresses vulnerabilities within the SSL encryption protocol that can put payment data at risk • Requirements 11.3.1 and 11.3.2 encourage penetration testing annually or after any significant change to IT environment – Can include any upgrade or modification that could affect the security of cardholder data – Aims to ensure that controls assumed to be in place continue to work effectively after updates
  • 4. Where Companies Fail “Compliance with the Payment Card Industry Data Security Standard continues to improve, but four out of five companies still fail at interim assessment. This indicates that they’ve failed to sustain the security controls they put in place.” Verizon 2015 PCI Compliance Report • Find and fix your vulnerabilities before an attacker does – Vulnerability scanning alone is not sufficient – Penetration testing reduces false positive results by discovering which weaknesses could actually result in an exploit • Maintain the controls put in place for continued security
  • 5. TraceSecurity PCI Penetration Testing • Follows PCI guideline best practice methodology to include a/an: – Engagement Interview – Network Documentation Collection – Network Scope – Segmentation Checks – Application and Network Testing – Immediate Notification of Critical Risks and/or Encountering Cardholder Data – Post-Engagement Retesting and Environment Clean-Up • PCI test results are provided in an extensive report
  • 6. TraceSecurity PCI Penetration Testing (cont’d) • Better equips organizations to prevent cybersecurity attacks and maintain PCI compliance • Since 2004, TraceSecurity has performed nearly 10,000 penetration tests • Our information security analysts maintain certifications suggested by PCI guidelines that include but are not limited to: – Offensive Security Certified Professional (OSCP) – Certified Ethical Hacker (CEH)
  • 7. Educational Webinar and Blog • Join TraceSecurity for a free webinar. Learn how you can protect your customers’ payment data and comply with new PCI standards. – This webinar explores some of today’s most publicized card data breaches and discusses how organizations can effectively evaluate and test the security of both internal and external systems that are involved in the processing or protection of cardholder data to ensure they maintain PCI compliance. • Read TraceSecurity's blog titled “TraceSecurity PCI Penetration Testing Meets PCI DSS 3.1.” CLICK HERE TO REGISTER/WATCH CLICK HERE TO READ BLOG
  • 8. thought leadership webinars on-demand our blog our monthly newsletter www.tracesecurity.com ©2015 TraceSecurity, Inc. All rights reserved worldwide. Connect with us! DOWNLOAD WATCH READ RECEIVE Access more educational content from TraceSecurity,