See more news releases in: High Tech Security, Internet Technology, Computer Electronics, Multimedia & Internet, Networks, Surveys, Polls and Research
New PCI Compliance Rules to Impose Significant Burdens on Merchants
netVigilance Issues Urgent Bulletin: Ten Actions Merchants Must Immediately Take To Avoid PCI Failure
BEAVERTON, Ore., April 2 /PRNewswire/ -- netVigilance, the only vulnerability assessment and PCI Approved Scanning Vendor (ASV) vendor that goes Beyond Compliance to detect up to 97% of all common vulnerabilities, today issued an urgent bulletin warning all merchants and retailers subject to PCI-DSS Compliance that new PCI regulations significantly increase their chances of PCI failure during mandatory quarterly external vulnerability scans, unless merchants take corrective actions. Full details can be found in the press release (http://bit.ly/bTZEPz) or slide presentation (http://bit.ly/9LVnmv).
Ten Actions Merchants Must Immediately Take To Avoid PCI Failure
- Ensure and verify previously out-of-scope components will pass PCI before your next quarterly scan.
- Ensure that your hosted environment obtained a "pass" on its ASV scan. If your ISP will not grant permission or cannot pass, change to one who will.
- Remove otherwise secure database servers directly on the Internet by placing them behind firewalls.
- Scan your website specifically for HTTP Response splitting/header injection.
- Verify that the DNS server holding your domains does not allow DNS Zone Transfers.
- Make sure your ASV does not rely on a fully automated process to keep pricing low--new rules mandate that every scan be reviewed by a professional Security Engineer qualified by PCI.
- First turn off SSL v2, because SSL v2 is considered an insecure (weak) protocol. Then, ensure that you are using TLS 1.0 AND that backwards compatibility with SSL v2 is turned off.
- Remove all non-critical uses of all remote access software: pcAnywhere™, VNC, RDP, and even VPN.
- Move all POS systems behind the firewall.
- A specific employee must attest that "proper scoping of the external scan is my company's" responsibility.
About netVigilance
netVigilance is the fastest growing vulnerability detection and assessment company, because it goes Beyond Compliance to detect up to 97% of common network vulnerabilities, far more than any competitor. netVigilance focuses exclusively on solutions for Network Vulnerability Detection and Assessment, including PCI Compliance. It is an active member of the PCI ASV Task Force and the CVSS SIG. For more information, visit www.netvigilance.com.
netVigilance, Beyond Compliance, Total Coverage and Total Vigilance are trademarks of netVigilance. All other trademarks are the properties of their respective owners.
SOURCE netVigilance
Back to top
RELATED LINKS
http://www.netvigilance.com/
Custom Packages
Browse our custom packages or build your own to meet your unique communications needs.
PR Newswire Membership
Fill out a PR Newswire membership form or contact us at (888) 776-0942.
Learn about PR Newswire services
Request more information about PR Newswire products and services or call us at (888) 776-0942.
Featured Video
More in These Categories
Journalists and Bloggers
![]()
Visit PR Newswire for Journalists for releases, photos, ProfNet experts, and customized feeds just for Media.
View and download archived video content distributed by MultiVu on The Digital Center.
Free Investing Newsletter from Investor Uprising!
Learn to navigate the world's financial system and profit from leading companies.
Register for Investor Uprising, the people's investment site, for a free weekly newsletter, information, education and premium research including our latest IU Confidential Report - "All That Glitters: The Ultimate Gold Report".
- Site Preview
-
Close Site Preview
-
View FullScreen

