<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security: Tag QSA</title>
    <link>http://blog.clearnetsec.com/articles/tag/qsa</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>True penetration testing?</title>
      <description>&lt;p&gt;
This from the new 
&lt;a href="https://www.pcisecuritystandards.org/pdfs/infosupp_11_3_penetration_testing.pdf"&gt;PCI information supplement&lt;/a&gt;: (regarding the required annual penetration testing for compliance)
&lt;/p&gt;
&lt;img src="http://blog.clearnetsec.com/files/paperBag.jpg" align="right"&gt;
&lt;blockquote&gt;
The penetration tests should attempt to exploit vulnerabilities [&#8230;] attempting to penetrate both at the network level and key applications
&lt;/blockquote&gt;
&lt;p&gt;
Really?  I laughed when I read this, seriously.  It made me think for a second about how many consultants &lt;b&gt;&lt;i&gt;really&lt;/i&gt;&lt;/b&gt; have the skills to chef-boy-ar-dee exploits under pressure.  It&#8217;s clear too; this is not about a vulnerability sweep, they want you to bust in.
&lt;/p&gt;
&lt;blockquote&gt;
Penetration testing [..] should occur from both outside the network trying to come in (external testing) and from inside the network.
&lt;/blockquote&gt;
&lt;p&gt;
Wow.  &lt;b&gt;&lt;i&gt;True penetration testing&lt;/i&gt;&lt;/b&gt; from inside the network?  How many internal networks have you seen that would survive a blitzkrieg attack from a good penetration test team?      
&lt;/p&gt;
PCI states:
&lt;blockquote&gt;
&#8220;resources must be experienced penetration testers&#8221;
&lt;/blockquote&gt;
&lt;p&gt;
What does that mean?  
&lt;/p&gt;
&lt;p&gt;
I&#8217;m sure the PCI council is of compos mentis, and I&#8217;m not trying to rain on the PCI council or ASVs or QSAs, though it&#8217;s funny the council points out that &lt;i&gt;&#8220;The PCI DSS does not require that a QSA or ASV perform the penetration test&#8221;&lt;/i&gt;.  That statement wouldn&#8217;t be because most of them couldn&#8217;t penetration test there way out of a paper bag even if they were handed a loaded metasploit gun, right?    
&lt;/p&gt;
&lt;p&gt;
With the huge number of companies bemoaning PCI compliance, I just don&#8217;t see most getting a &lt;b&gt;&lt;i&gt;true&lt;/i&gt;&lt;/b&gt; penetration test.  I guess I could be reading too much into this.  Maybe the skills bar level I consider for experienced penetration testers is way higher than what the PCI council considers experienced or what others consider experienced or good?
&lt;/p&gt;
&lt;p&gt;
Do you have penetration testing skills?  What does that mean to you?  Do you think most of the companies that buy a penetration test actually get one?
&lt;/p&gt;

</description>
      <pubDate>Sun, 04 May 2008 22:45:00 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:470c8a22-8394-42f3-865f-16f2cea23a84</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2008/05/04/true-penetration-testing</link>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>ClearNet</category>
      <category>security</category>
      <category>Penetration Testing</category>
      <category>PCI</category>
      <category>ASV</category>
      <category>QSA</category>
      <category>vulnerability</category>
      <category>exploits</category>
    </item>
  </channel>
</rss>
