Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
CORE IMPACT Pro
Penetration Testing Software
SHARE

CORE IMPACT Pro Penetration Testing Reports: 
PCI Vulnerability Validation Report


Testing Vectors:
Network Systems

The PCI Vulnerability Validation Report provides results of penetration testing performed with the goal of remaining compliant with the Payment Card Industry (PCI) Data Security Standard, created by the world’s largest credit and debit card issuers to encourage merchants and card processors to establish and maintain stringent IT security controls for any sensitive cardholder data they store. For organizations attempting to comply with PCI DSS, the reports include confirmation that users have performed vulnerability validation and penetration testing, such that required under PCI supplement 11.3 – with use of the product recognized as sufficient in meeting many testing requirements by the PCI Standards Council. Reports include CVSS vulnerability severity scores, adopted by the PCI Council for ranking vulnerabilities identified during required scans and penetration tests.

Targeted Report Results:

  • Penetration testing results: proves that required penetration tests are being performed and logged.
  • Vulnerability management status: helps you prove that issues found during scanning are being properly addressed.
  • Security defense performance: allows you to view and substantiate the required security controls are in place and working.
  • Integration with vulnerability scanners: shows how required elements of PCI are working together to lower risks.

Takeaways:

  • Extensive lists of vulnerabilities validated and tested with status information regarding their location, availability and related risk.
  • Detailed results regarding how an organization is working to meet both the requirements and underlying spirit of the PCI DSS standard.
Related Content



Learn more about penetration testing, the approach used by CORE IMPACT security testing software solutions.

Additional Reporting Features

CORE IMPACT Pro reports offer the following additional features for meeting your unique assessment goals:

SCAP Support
In support of the SCAP standard, CORE IMPACT Pro incorporates CVE, CVSS and CPE data into the product's reports and can also export this data in XML format for use in centralized security databases.

Customization
Many CORE IMPACT Pro reports can be tailored to meet the needs of different internal constituencies by providing tailored results for groups including IT management, network administrators, remediation staff, and other IT/security professionals. Additionally, the reports are exportable to other applications for integration with complimentary sets of data.

Aggregation
CORE IMPACT Pro report consolidation capabilities enable customers to create overarching reports of enterprise penetration testing results. Users can import and consolidate results from different penetration tests - conducted at various times using multiple workspaces and consoles - into each of IMPACT Pro’s standard report templates.