1 Stop PCI Scan recognizes that the PCI DSS uses a defense-in-depth approach to promoting PCI compliance. True PCI compliance involves more than just quarterly external PCI scanning. Yearly penetration testing is also a requirement for almost all businesses.
Penetration testing involves simulating an actual attack on the customer’s network. This type of testing helps to determine what a malicious person may actually accomplish in a real world hacking effort.
PCI compliance calls for businesses to “regularly test security systems and processes. Section 11 of the PCI DSS enumerates each of the requirements that fall under the “regularly test security systems and processes” component of overall PCI compliance. Section 11.3.1 of the PCI DSS v3 reads:
“Perform external penetration testing at least annually and after any significant infrastructure or application upgrade or modification.”
Section 11.3.2 follows up by referring to internal penetration testing as an annual requirement as well.
1 Stop PCI Scan offers penetration testing at a low cost and each member of our skilled testing team is an Offensive Security Certified Professional (OSCP). The pricing for penetration testing cannot be described in a standard rate that applies to all customers. Penetration testing is not a strictly automated process. In comparison to external PCI scanning, there are more variables involved in the pen-testing process, and pen-testing involves significantly more manual work. Interested customers should contact 1 Stop PCI Scan for more information and customized pricing.
For more information, including a discussion on considerations that come into play with PCI penetration test pricing, see our penetration test cost page.
If you are curious about the difference between PCI scanning and PCI penetration testing, take a look at our discussion on this topic here: “PCI Penetration Testing Vs. PCI Scanning“.
1 Stop PCI Scan – A Division of Backbone Security, Inc.
Cookie | Duration | Description |
---|---|---|
cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |