<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PCI DSS 11.3: Penetration Testing Requirements Clarified</title>
	<atom:link href="http://www.pcidssguru.com/penetration-testing/pci-dss-113-penetration-testing-requirements-clarified/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pcidssguru.com/penetration-testing/pci-dss-113-penetration-testing-requirements-clarified/</link>
	<description>Practical Implementation Guidance on the Payment Card Industry Data Security Standard</description>
	<lastBuildDate>Thu, 23 May 2013 07:10:13 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.2</generator>
	<item>
		<title>By: Blue Host Review</title>
		<link>http://www.pcidssguru.com/penetration-testing/pci-dss-113-penetration-testing-requirements-clarified/comment-page-1/#comment-53351</link>
		<dc:creator>Blue Host Review</dc:creator>
		<pubDate>Thu, 02 May 2013 21:12:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=4#comment-53351</guid>
		<description>When someone writes an article he/she maintains the idea 
of a user in his/her brain that how a user can be aware of it.
So that&#039;s why this paragraph is outstdanding. Thanks!</description>
		<content:encoded><![CDATA[<p>When someone writes an article he/she maintains the idea<br />
of a user in his/her brain that how a user can be aware of it.<br />
So that&#8217;s why this paragraph is outstdanding. Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blue Host Coupon</title>
		<link>http://www.pcidssguru.com/penetration-testing/pci-dss-113-penetration-testing-requirements-clarified/comment-page-1/#comment-53350</link>
		<dc:creator>Blue Host Coupon</dc:creator>
		<pubDate>Thu, 02 May 2013 21:11:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=4#comment-53350</guid>
		<description>What&#039;s up friends, its impressive piece of writing on the topic of cultureand completely defined, keep it up all the time.</description>
		<content:encoded><![CDATA[<p>What&#8217;s up friends, its impressive piece of writing on the topic of cultureand completely defined, keep it up all the time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blue Host Reviews</title>
		<link>http://www.pcidssguru.com/penetration-testing/pci-dss-113-penetration-testing-requirements-clarified/comment-page-1/#comment-53349</link>
		<dc:creator>Blue Host Reviews</dc:creator>
		<pubDate>Thu, 02 May 2013 21:07:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=4#comment-53349</guid>
		<description>Spot on with this write-up, I truly feel this site needs a great deal more attention.

I&#039;ll probably be returning to read through more, thanks for the info!</description>
		<content:encoded><![CDATA[<p>Spot on with this write-up, I truly feel this site needs a great deal more attention.</p>
<p>I&#8217;ll probably be returning to read through more, thanks for the info!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christian Louboutin Shoes</title>
		<link>http://www.pcidssguru.com/penetration-testing/pci-dss-113-penetration-testing-requirements-clarified/comment-page-1/#comment-51336</link>
		<dc:creator>Christian Louboutin Shoes</dc:creator>
		<pubDate>Wed, 10 Apr 2013 04:19:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=4#comment-51336</guid>
		<description>Good day! Do you know if they make any plugins to help with SEO? I&#039;m trying to get my blog to rank for some targeted keywords but I&#039;m not seeing very good gains. If you know of any please share. Kudos!</description>
		<content:encoded><![CDATA[<p>Good day! Do you know if they make any plugins to help with SEO? I&#8217;m trying to get my blog to rank for some targeted keywords but I&#8217;m not seeing very good gains. If you know of any please share. Kudos!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wykrywacze metalu</title>
		<link>http://www.pcidssguru.com/penetration-testing/pci-dss-113-penetration-testing-requirements-clarified/comment-page-1/#comment-50398</link>
		<dc:creator>wykrywacze metalu</dc:creator>
		<pubDate>Fri, 29 Mar 2013 16:41:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=4#comment-50398</guid>
		<description>I would like to uslysht a bit a lot more on this subject</description>
		<content:encoded><![CDATA[<p>I would like to uslysht a bit a lot more on this subject</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pracowniaarchitektonic</title>
		<link>http://www.pcidssguru.com/penetration-testing/pci-dss-113-penetration-testing-requirements-clarified/comment-page-1/#comment-50148</link>
		<dc:creator>pracowniaarchitektonic</dc:creator>
		<pubDate>Tue, 26 Mar 2013 11:31:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=4#comment-50148</guid>
		<description>Does your website have a contact page? I&#039;m having problems locating it but, I&#039;d like to shoot you an e-mail. I&#039;ve got some suggestions for your blog you might be interested in hearing. Either way, great website and I look forward to seeing it develop over time. pracownia architektoniczna http://www.katalogfirmy.net/340,Cdom_Budynki_uslugowe,wpis.html</description>
		<content:encoded><![CDATA[<p>Does your website have a contact page? I&#8217;m having problems locating it but, I&#8217;d like to shoot you an e-mail. I&#8217;ve got some suggestions for your blog you might be interested in hearing. Either way, great website and I look forward to seeing it develop over time. pracownia architektoniczna <a href="http://www.katalogfirmy.net/340,Cdom_Budynki_uslugowe,wpis.html" rel="nofollow">http://www.katalogfirmy.net/340,Cdom_Budynki_uslugowe,wpis.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joseph Pierini</title>
		<link>http://www.pcidssguru.com/penetration-testing/pci-dss-113-penetration-testing-requirements-clarified/comment-page-1/#comment-9700</link>
		<dc:creator>Joseph Pierini</dc:creator>
		<pubDate>Fri, 18 Nov 2011 19:06:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=4#comment-9700</guid>
		<description>Your definition of the scope is incorrect.

The scope of penetration testing is the Cardholder Data Environment (CDE) and all systems and networks connected to it. The PCI Security Standards Council defines the CDE as “The people, processes and technology that store, process or transmit cardholder data or sensitive authentication data, including any connected system components.”

As recommended by the PCI Security Standards Council’s Information Supplement: Requirement 11.3 Penetration Testing dated April 2008, testing should include locations of cardholder data, key applications that store, process, or transmit cardholder data, key network connections, key access points and other targets appropriate for the complexity and size of the organization.

Testing should not be performed inside the CDE.</description>
		<content:encoded><![CDATA[<p>Your definition of the scope is incorrect.</p>
<p>The scope of penetration testing is the Cardholder Data Environment (CDE) and all systems and networks connected to it. The PCI Security Standards Council defines the CDE as “The people, processes and technology that store, process or transmit cardholder data or sensitive authentication data, including any connected system components.”</p>
<p>As recommended by the PCI Security Standards Council’s Information Supplement: Requirement 11.3 Penetration Testing dated April 2008, testing should include locations of cardholder data, key applications that store, process, or transmit cardholder data, key network connections, key access points and other targets appropriate for the complexity and size of the organization.</p>
<p>Testing should not be performed inside the CDE.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Information Secuity</title>
		<link>http://www.pcidssguru.com/penetration-testing/pci-dss-113-penetration-testing-requirements-clarified/comment-page-1/#comment-8904</link>
		<dc:creator>Information Secuity</dc:creator>
		<pubDate>Fri, 04 Nov 2011 06:33:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=4#comment-8904</guid>
		<description>India has called for global coordination to ensure that internet continues to thrive without the fear of its misuse at the London Internatinal Cyber Conference that give the nature of the task and the fact that IT networks can be attacked from anywhere in the world.</description>
		<content:encoded><![CDATA[<p>India has called for global coordination to ensure that internet continues to thrive without the fear of its misuse at the London Internatinal Cyber Conference that give the nature of the task and the fact that IT networks can be attacked from anywhere in the world.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mohamed Farid</title>
		<link>http://www.pcidssguru.com/penetration-testing/pci-dss-113-penetration-testing-requirements-clarified/comment-page-1/#comment-328</link>
		<dc:creator>Mohamed Farid</dc:creator>
		<pubDate>Mon, 18 May 2009 17:45:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=4#comment-328</guid>
		<description>Regarding the external pen test - the pen tester will evaluate the Scope from the Internet or through any Public Connection ...

What about the Internal Pen Testing - Will it be evaluated from the DMZ towards the Scope ( Live Production ) ? or internally from the Scope Directly ?

My Concern is Evaluating it from inside is ignoring the Firewalls and the Access-lists around the scope - and also it will give a lot of false positives which are already protected using the boundary security products.</description>
		<content:encoded><![CDATA[<p>Regarding the external pen test &#8211; the pen tester will evaluate the Scope from the Internet or through any Public Connection &#8230;</p>
<p>What about the Internal Pen Testing &#8211; Will it be evaluated from the DMZ towards the Scope ( Live Production ) ? or internally from the Scope Directly ?</p>
<p>My Concern is Evaluating it from inside is ignoring the Firewalls and the Access-lists around the scope &#8211; and also it will give a lot of false positives which are already protected using the boundary security products.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Penetration Testing</title>
		<link>http://www.pcidssguru.com/penetration-testing/pci-dss-113-penetration-testing-requirements-clarified/comment-page-1/#comment-13</link>
		<dc:creator>Penetration Testing</dc:creator>
		<pubDate>Wed, 06 Aug 2008 19:26:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=4#comment-13</guid>
		<description>What are your thoughts on situations where Operational Security and other areas of Information Security have separate reporting lines - i.e. they may have separate line management but report into the same CSO or head of security? Would it still be feasible to have non-ops infosec conducting penetration testing in your opinion?</description>
		<content:encoded><![CDATA[<p>What are your thoughts on situations where Operational Security and other areas of Information Security have separate reporting lines &#8211; i.e. they may have separate line management but report into the same CSO or head of security? Would it still be feasible to have non-ops infosec conducting penetration testing in your opinion?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: basic
Database Caching using disk: basic
Object Caching 465/472 objects using disk: basic

Served from: www.pcidssguru.com @ 2013-05-25 13:50:08 -->