Penetration Testing for Credit Card 'Terminal' Computer

Spapro

Free Member
Nov 21, 2009
258
19
Hi,

We are a small single office business to business trader and are just coming up to our annual PCI compliance and need to understand penetration testing as follows:

We have a single workstation PC on a segmented area of our network (not accessible from the rest of the network). On that PC we use Sagepay terminal to enter MOTO not present card transactions.

Do we need to engage someone to complete a penetration test to check the durability of our segmentation and confirm its secure enough ? as PCI compliance is asking me to confirm this has been done.

If so, what do others do on this and is there a quick, cheap service I can employ to run the penetration test ? What do others use ?
 

EmC007

Free Member
Jun 3, 2017
90
5
York
My understanding is that the you can select a supplier who will carry this out. This is normally the best way so that you can demonstrate that the person that carried out the test is trained and certified. I do know a company that does that kind of thing if you wanted an introduction.
 
Upvote 0

Latest Articles

Join UK Business Forums for free business advice