Results 1 to 5 of 5

Thread: Pci-dss

  1. #1

    Default Pci-dss

    Arggg, dreaded PCI-DSS questionnaire

    Driving me crazy....

    Example:
    2.6 Is only one primary function implemented per server? (SAQ #2.2.1)

    The "one primary function" rule applies to all servers that are in-scope and it must be part of the written configuration standard. Multiple primary functions (like: "web server", or "authentication server") cannot be running on a single system.
    So what implications does this have for my dedicated server that runs webserver, database, etc?

  2. #2
    Join Date
    Oct 2006
    Location
    localhost
    Posts
    3,375

    Post

    Quote Originally Posted by JonoB View Post
    Arggg, dreaded PCI-DSS questionnaire

    Driving me crazy....

    Example:
    2.6 Is only one primary function implemented per server? (SAQ #2.2.1)

    The "one primary function" rule applies to all servers that are in-scope and it must be part of the written configuration standard. Multiple primary functions (like: "web server", or "authentication server") cannot be running on a single system.
    So what implications does this have for my dedicated server that runs webserver, database, etc?
    Hi,

    Whom is this PCI-DSS scanning being done from? ie: Cisco, Verizon? They are the strictest ones when it comes to such scanning. A more relaxed but valued scanning method can be performed from Hacker Guardian, McAfee, Comodo, etc. There are other vendors too which provide free PCI compliance scanning for your website/servers.. Regarding this query of having "one primary function" or one service per server, it's not mandatory & you can safely ignore it if it isnt listed as a Critical issue with the server security..

    Rock _a.k.a._ Jack
    Windows Hosting || Windows Reseller Hosting
    Cloud Hosting 100% UPTIME! || Powerful Dedicated Servers
    Follow eUKhost on Twitter || Join eUKhost Community on Facebook

    For complaints, grievances or suggestions kindly email our FeedBack Dept.
    Proper action will be taken accordingly & instantaneously!

  3. #3

    Default

    Does hackerSafe is offering free PCI scanning, I contacted them and they asked for roughly $1700... if you have a link for the free service it would be appreciated.

  4. #4
    Join Date
    Oct 2006
    Location
    localhost
    Posts
    3,375

    Question

    Quote Originally Posted by RuthSam View Post
    Does hackerSafe is offering free PCI scanning, I contacted them and they asked for roughly $1700... if you have a link for the free service it would be appreciated.
    Did you try McAfee or HackerGuardian yet?

    Rock _a.k.a._ Jack
    Windows Hosting || Windows Reseller Hosting
    Cloud Hosting 100% UPTIME! || Powerful Dedicated Servers
    Follow eUKhost on Twitter || Join eUKhost Community on Facebook

    For complaints, grievances or suggestions kindly email our FeedBack Dept.
    Proper action will be taken accordingly & instantaneously!

  5. #5

    Default

    Sorry not yet, have been looking at McAfee, however, they are also not free as far as I know.

    I'm in general not a big believer of Free PCI security scans, have been taking a trial with our current host which offered it for $50 compared to qualys who charge 10 times the fee I must say you also get 10 times the service and security level.

    Anyway, I'm on to try some of the free services just to compare them and check if they are really doing what they say they do.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •