View Full Version : Patch Mgmt - Vulnerability Scans for Workstations
SimplePCI
06-30-2007, 05:28 AM
Will PCI Auditors look at all the Level 3,4,5 vulnerabilities which may show up on workstations connected to a large distributed global Company network?
SimplePCI
06-30-2007, 09:23 AM
Will PCI Auditors look at all the Level 3,4,5 vulnerabilities which may show up on workstations connected to a large distributed global Company network?
More importantly, since most servers internally are IP-accessible to all workstations, are the vulnerabilities of these workstations in scope?
jbhall56
07-01-2007, 04:34 AM
Any workstations that have access to PCI servers are in scope whether they truly access the PCI servers or not.
This is why the PCI DSS recommends that PCI servers be firewalled away from non-PCI assets. If the PCI servers are firewalled away from the general network with appropriate rules, then controlling and monitoring of traffic and protection of these servers can be accomplished.
vBulletin® v3.7.4, Copyright ©2000-2010, Jelsoft Enterprises Ltd.