DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
PCI Compliance
- robertb24
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 31
- Thank you received: 0
04 Apr 2012 13:13 #71793
by robertb24
Replied by robertb24 on topic Re: PCI Compliance
I agree, but what choice do you have. The bank charges me an additional £50 on my merchant account if I am not compliant. Nice earner for them!
Please Log in or Create an account to join the conversation.
- toph3r
- Offline
- Junior Member
Less
More
- Posts: 27
- Thank you received: 0
16 Apr 2012 13:56 #71909
by toph3r
I've been through two PCI audits, and the firm for whom I worked made extensive use of SNMP. SO, you (and your auditor) are mis-understanding the requirements.
Further, you quote the CVE exploits to which your SNMP daemon is susceptible. Disabling SNMP is not the long-term solution. Patching your SNMP daemon (with updates supplied by your OS / network vendor) is the correct way.
I'm sorry to say this, but it seems a significant amount of clue is missing from the OP.
Replied by toph3r on topic Re: PCI Compliance
I agree, but what choice do you have. The bank charges me an additional £50 on my merchant account if I am not compliant. Nice earner for them!robertb24 wrote:
I've been through two PCI audits, and the firm for whom I worked made extensive use of SNMP. SO, you (and your auditor) are mis-understanding the requirements.
Further, you quote the CVE exploits to which your SNMP daemon is susceptible. Disabling SNMP is not the long-term solution. Patching your SNMP daemon (with updates supplied by your OS / network vendor) is the correct way.
I'm sorry to say this, but it seems a significant amount of clue is missing from the OP.
Please Log in or Create an account to join the conversation.
- toph3r
- Offline
- Junior Member
Less
More
- Posts: 27
- Thank you received: 0
16 Apr 2012 13:57 #71910
by toph3r
Dare I attempt to defend PCI DSS, but in theory PCI is actually a good attempt by the industry to implement ISO27001 standards on firms. This can only be a good thing.
Replied by toph3r on topic Re: PCI Compliance
So true... PCI is the biggest money spinning waste of time I have ever encountered. All leveraged by the banks.drummerjohn wrote:
Dare I attempt to defend PCI DSS, but in theory PCI is actually a good attempt by the industry to implement ISO27001 standards on firms. This can only be a good thing.
Please Log in or Create an account to join the conversation.
- drewy
- Offline
- Junior Member
Less
More
- Posts: 87
- Thank you received: 0
Moderators: Chris, Sami
Copyright © 2024 DrayTek