CORE IMPACT Pro Penetration Testing Reports:
PCI Vulnerability Validation Report
Testing Vectors: Network Systems
The PCI Vulnerability Validation Report provides results of penetration testing performed with the goal of remaining compliant with the Payment Card Industry (PCI) Data Security Standard, created by the world’s largest credit and debit card issuers to encourage merchants and card processors to establish and maintain stringent IT security controls for any sensitive cardholder data they store. For organizations attempting to comply with PCI DSS, the reports include confirmation that users have performed vulnerability validation and penetration testing, such that required under PCI supplement 11.3 – with use of the product recognized as sufficient in meeting many testing requirements by the PCI Standards Council. Reports include CVSS vulnerability severity scores, adopted by the PCI Council for ranking vulnerabilities identified during required scans and penetration tests.
Targeted Report Results:
- Penetration testing results: proves that required penetration tests are being performed and logged.
- Vulnerability management status: helps you prove that issues found during scanning are being properly addressed.
- Security defense performance: allows you to view and substantiate the required security controls are in place and working.
- Integration with vulnerability scanners: shows how required elements of PCI are working together to lower risks.
Takeaways:
- Extensive lists of vulnerabilities validated and tested with status information regarding their location, availability and related risk.
- Detailed results regarding how an organization is working to meet both the requirements and underlying spirit of the PCI DSS standard.











