Preparing For a PCI DSS Audit (Podcast)

Listen to learn how to prepare for a PCI DSS audit.

Updated:  
October 12, 2023

SecurityMetricsPodcast | 11

How to Prepare for a PCI DSS Assessment

A successful PCI DSS assessment requires a fair amount of preparation and scheduling far in advance. These activities may seem like a lot of work, but they are actually the best way to make your assessment less overwhelming, help you control time and cost, and avoid worst-case scenarios.

With thousands of PCI DSS assessment hours between them, SecurityMetrics Principal Analysts George Mateaki (CISSP, CISA, CISM, QSA, PA-QSA) and Jen Stone (MCIS, CISSP, CISA, QSA) sit down to “talk shop” and share stories from the field.

Listen in to learn:

  • How remote assessments work and tips to make them go more smoothly.
  • What you should do a year, 9 months, 6 months, and 3 months before your first assessment. Plus, what to do in between assessments to save time and resources.
  • An overview of the PCI audit timeline–from initial contact to signing of the report on compliance (ROC).

Resources:

Download our Guide to PCI Compliance! - https://www.securitymetrics.com/lp/pci/pci-guide

Download our Guide to HIPAA Compliance! - https://www.securitymetrics.com/lp/hipaa/hipaa-guide

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

How to Prepare for a PCI DSS Assessment Transcript

Hello, and welcome back to the Security Metrics podcast. I'm Jen Stone. I'm a principal security analyst here at Security Metrics, and I have with me a colleague today, George Matayaki. George, will you please introduce yourself for everyone?

Yeah. I would love to. Thank you, Jen. I'm also a security or a principal security analyst, and, I have a background in IT.

Did IT for a number of years, and, then I started to gravitate toward, compliance as I got into security and some SOX things. And, eventually, they allowed me to do PCI stuff. So it was super sweet.

I guess. We'll let you if you know stuff.

I was grateful to, you know, land at Security Metrics, and, I've been here for a little while. I'm coming on just finished six years. I'll I'll make seven years in next March.

And I've just loved doing PCI just just because it's very prescriptive, and, I love working with IT people. So that it's a joy to work with people that that I understand and can relate to and and help them, you know, get secure. And then eventually, I I sign reports that say that, yep. Yep.

We check them out. They're really secure. And so so my background has been largely in infrastructure and, you know, data center stuff, servers, server admin stuff, and eventually landed in compliance. So I've been doing that for a few years, and I love it.

I enjoy it. I love working with IT people.

You have a teaching background as well.

I do. Yeah. So I've been teaching, at various colleges over the years. Started in the late nineties, And I've just I just enjoy teaching, and helping people understand technology. That's fun.

That yeah. And George and I, we get along great. And sometimes we get to go on to audits together, and those are the best times. Just like, if if you're going to go out and do an assessment, you wanna wanna do it with a friend.

So So so full disclosure, Jen is my friend. I and, so I'm just tiny bit biased toward her, but but I will keep everything professional and try to give my best opinion.

Nice things. Right?

You're gonna I will try. Yeah. I will try.

Sometimes I make mistakes, but George never says anything negative about them.

So so, today, we're going to talk together about, assessment basics.

And I think that you're really probably the perfect person to talk to about this. There's a lot of people out there that are doing assessments, and there are a lot of really great assessors out there. And a lot of times what I see is that our customers or or people who who aren't even our customers but who just have questions about assessments, they're kinda nervous about, like, how do we get started? What can we expect?

If you've never been through an assessment, the first one is super intimidating for a lot of people. So let's just kinda talk about that. So, and we can keep it mostly, we'll talk about PCI today, but but just keep in mind, a lot of what we're going to talk about translates to HIPAA assessments or NIST or, yeah, whatever flavor of assessment you have going on, the basics are going to apply. So a lot of times, people when they first start out, when it's their initial assessment, it can be very intimidating for them.

Where do people start? What's what's the first thing that they need to do in order to, successfully complete an assessment? What are the beginning steps?

Yeah. So the timeline that we try to help people follow starts with, just thinking about your what you're trying to be compliant with. Mhmm. And in our discussion today, we're looking, you know, at PCI and and HIPAA and other types of compliance.

So at least a year, we look for you know, we we try to get people to think at least a year ahead, in in terms of, you know, what's what's the path.

The you know, just some overview of of okay. I know I need to be compliant to PCI. You know, what what am I gonna have to do? So at least have the thoughts started a year in advance of everything of of trying to get an assessment.

Sure.

So they're they're thinking that, okay. You know, I I gotta get a PCI assessment. My my bank is telling me I need this. And so so they they, figure out, okay. Let's engage with someone.

Mhmm.

And then our typical timeline that we'd like people to follow is about nine months out, you get with with an assessor that's gonna help you understand your environment and and the things that you might have to do. So initially, it's it's almost like, like, you know, any sort of issue you have. First, you have to recognize you have a problem. So you're so, anyway, a year in advance.

In your a year in advance, you recognize, yes. I need to be compliant. And so then then about nine months in, hopefully, you've engaged with someone, and we have a process that we call our initial gap. And so we work with the customer to help them understand where they are and what they'll need to do to get ready for that assessment. And so we look for nine months in advance. And then then about six months or so, we're hoping that they solidify their policies and procedures.

Right.

For their, you know, for their environment that's gonna comply with with what they're trying to to, certify with or validate for.

And and that that's where you start. You know? And and it is intimidating because, especially for someone that's been self assessing, meaning Yeah. They're they're just signing their own report.

They're checking the boxes and like, yeah. Yeah. We kinda do that. And then they submit it and they're cool.

And then when they're required to have a third party come in, then that's like a shock. Like, holy crap. This stuff is real. You know?

And and and Like, remember when you're a little kid and Yeah.

And your mom's like, go make your bed and clean your room, and you go and do it, and you're like, yeah. It's good. And then they say, now I'm going to come inspect it. It.

I didn't know an inspection was part of this process. And then it's always they always your mom always found something that you just didn't see. That's kinda like having an assessor come is that you think you're doing everything right, but then a third party comes in, that other set of eyes, and goes, guess what you missed? And and it's it's very helpful.

It can not only increase their security stance, but helps them be more compliant with whatever they're trying to to achieve for sure.

Absolutely.

And it it it's always a shock. And, you know, it's not a shock to us. No.

Because that's usually what happens. But when we you know? And we try to ease them into the compliance pain that they're gonna feel.

Yeah. Yeah.

But it so so I one thing I'd really like to emphasize about this whole process is people have to take it seriously.

Mhmm.

You can't look at it as like, oh, these are the hoops they're gonna make me jump so I can take credit cards. It it's not that at all. You know? If we if we break it down into its simplest form, these are the things that people have been breached for. Mhmm. The very bare minimum. You know?

This should PCI should be your floor.

Yep.

You you get your compliance straight with PCI. That's where you start. Mhmm. And then depending on your business, you you, you know, throw more security where you feel is is is appropriate based on your risk. But but PCI should not be the end.

That is not the end.

That is the bare minimum where people are getting breached.

Right.

Every single item in there. That's why they're in the PCI standard because somebody got breached.

Yeah. Yep. So And and it's interesting because, we hear this all the time, especially with new people people who are new to the process. They'll say, well, compliance isn't security.

And I think think that a lot of times the way the reason they're doing that is because they want to say, hey. We are secure and we're doing security right, and we don't care about your compliance, or just sign this because we already know security.

And yet compliance, by and large, was intended to create a more secure stance for organizations or or at least create a a consistent baseline for security Yeah.

To protect specific types of of, information.

Well, the the other, you know, feeling that that I've had personally and and seen other people have is, like, oh, do you think we don't know what we're doing? Yeah. We're IT guys. We know how to take care of our servers.

Yeah. Yeah. Yeah. You do.

But there's some extra things you can do to to that you may not be thinking about Sure.

That that plays into it. And I it the biggest one for me is appropriate staffing. Yes. My heart breaks Uh-huh.

Every time I come across a customer that that just loads some IT dude with all the PCI stuff. Yeah. They there is no way. You know?

The the this has to be something that that when they sleep at night, they're thinking about, you know, do we do everything we need to for PCI? Not because, oh, we're not gonna pass compliance, because they want their place to be secure. Sure. That's it's it's different.

Right? The IT guys, they want their systems up. They want the systems to perform.

That's that's their that's their Functionality is their number one priority.

Yeah.

Yeah. PCI is different. You know, we want to maintain security around data that that could cause you trouble Sure. If it gets breached. So so the priority's a little different. The what you're worried about is a little different. Mhmm.

And so When you because when you have a security focus, security and we hear it over and over again.

Security slows us down. Yeah. You know who else it slows down? The bad guys.

That's right. That's right.

So so understand it. But a lot of businesses don't understand this because computers, technology, the information side is all one thing. It's not they don't have the background to understand that there is a difference between IT and security.

Yes. They go hand in hand. And, yes, they should be implemented together. But the the focus of the individuals that are in charge of each is different. And you want that different focus because it gives you that push pull of functionality with security that's super important to keep the the business from being breached. And from a business perspective, you don't want breaches because that can be really damaging to the the brand.

And with fines and all that, man, you can go out of business if you have a breach.

And it has happened.

Yep.

Yep. So so the other thing that I run into, and this is perhaps more a security thing than PCI, but it it does happen in PCI, is where executives try to bypass the the process. Yeah.

You know?

Because for whatever reason. Oh, I own this company. I'm not doing that. Yeah. You know? And, like, well, who are you to tell me to, you know, make my password longer or not use my personal devices on this piece of network?

I'm the boss. I get to accept that risk.

Yeah. That's not cool.

That's not good.

Yeah. Not good. And so I've seen that in a number of companies, even places where I've worked in the past. Mhmm.

And, you know, you're trying to do the right thing, and then the person with actual data that that could kill your company is the one not following the rules. Yeah. You know? That that, HIPAA.

Yeah. Doctors.

Oh, yeah. It's it's this is really common, especially in some of the the smaller practices where the doctors are wearing a lot of hats, or even where they're just they're the decision makers even if they have someone else doing IT for them, which they should.

The it's it's hard because they want all of the permissions. It's not a status thing. Having the permissions to access everything is not it it's not related to what your status is. It's related to what your job is.

Right? So if the job role requires you to be able to have access to different information, then you should have it. But most CEOs are not going to be required to have access to, credit card data. Just just not the way the companies work.

And so if you look at what is the role and what access to what specific types of data are required, then you can, successfully do a a role based access control. Fancy word. It's RBAC is something that we look at all the time. It's just, does your role align with the access that you have?

And if it doesn't, then you probably need to to fix that for any any type of assessment that you have going on.

Yep. And keep your permission straight.

Yeah.

If you don't have a RBAC RBAC, you know, defined, you're you're kinda just, well, I think that group needs this. Yeah. That they've said they need this. You need to define so, again, with the staffing.

Right? If you don't define who's doing what and you just say, hey, IT guy, I need you to do this from now on Mhmm. And there's not a clear plan and and the load is not balanced, people are gonna leave. You're gonna have turnover.

You know?

Clearly defined roles is huge to security.

Sure.

It doesn't seem like it. Right? Like, what cool technology is that? Uh-huh. Uh-huh. That's just organizing who has access to what.

Yeah. That's all it is. Yep. Exactly. And and it it also allows if you have clearly defined roles, then you don't have a strong personality that's declaring this person should have permission to you know, we don't want Yeah.

We don't want permissions by personality. You want you want permissions by role. And so access, by role also ensures things like, separation of duties. Right?

So see these are the some of the things that when we first come and work with a a company for the very first time, that's what we see is is some basic gotchas are kind of along those lines. Not not enough security staffing. IT is not separated from security staffing. And so if it's your first assessment, you can expect that we're going to see things that are that are just not have not been a concern to to to your organization until then.

Yeah. Well, maybe I could, return to the timeline just a bit. Yeah. So, like, a year out, we want you thinking about engaging somebody.

Mhmm. Think about, okay. If this is PCI, I need some PCI resource to help me get ready. And about nine months is when we like to come in and do, what we refer to as the initial gap process, figuring out, you know, what's gonna happen.

And then six months in, I mentioned, you know, hopefully, policies and procedures are set up, implemented, you know, in PCI. We need an annual review of it. Mhmm. People are signing off on the policy that they're gonna follow it and all that good stuff, that that's occurring six months out from the assessment.

Yeah. And then about three months is when we start talking, travel plans Right. When the assessment date, could happen. And we're hoping that a week in advance that people are providing evidence.

So we have a tool that we use that we collect evidence, and it helps, provide a secure way for us to to upload files and review them and and communicate with the customer. And then then the assessment happens.

Well, you give them, up till a week in advance. You are the nicest I won't even schedule travel if I don't have information uploaded.

Jen is is smart. Very smart. Yeah.

Well, I, you know, I don't wanna travel out there and then well, sometimes I like to travel out twice, but, depends on where they're located.

Well If you're in Singapore, I will come to you every month. Twice every time.

The the the the thing with that, you know, we we want this process to be smooth. It doesn't help us any to to have an, you know, hiccups along the way.

Right.

So the more smooth it can be and and just from an auditor's point of view, you know, when you act like your things are together and things are well established, we gain confidence and we don't dig as deep. Any little weird thing poking out somewhere and we're like, what what's that?

That doesn't We're gonna dig a lot deeper because, remember, we signed these things Yeah.

And our name's on the thing, and we don't want our name on something that's not right.

So that There's a certain number of things that we have to look at, and we do.

Yeah.

And then in looking at those things, if there's anything that stands out to us, we will dig deeper on that particular topic until we are have reached a strong degree of assurance that things are in place.

Yeah.

Right? So so it's it's one of those things where if an organization has centrally managed security things, if they have centrally managed and updated policies and procedures and I know we hate policies and procedures, and not not hate following them. Well, sometimes we do. But but mostly, it's creating them in the first place because it feels like that is a busy work to a lot of the organizations that I talk to. And yet, the policies and procedures are what create those consistencies that make it so that we have to look at fewer things because more things are actually in place when you go and look at them. Right?

That's right. And so a typical assessment, you know, let's say everything's ready. We've got our travel plans ready.

Uh-huh.

The customer has shown evidence that, you know, that that they really are ready. It it's horrible to show up somewhere and there's nothing in place that but they've put up a good, show.

Talked to good game.

Talked to good game.

And there's nothing there.

And we say, okay. Show us evidence of this. And they're like, well, we sent you the the the the document.

Yes, but in real time with my eyes We wanna know that it actually you're actually doing it.

Like, show us. And and usually that's where things break down. It's not to do a gotcha on people. No. It's just that we have to verify Yeah. To to to feel good about signing your report.

Well, and from PCI's perspective, not only are we signing it, but they are also signing it.

Yeah.

Right? So Yeah. So I like PCI because it is collaborative in that way. And the the nice thing about an on-site is we say, alright.

Here's the requirement. Here's what we're expected to do. Now let's sit down together as reasonable humans and look at what you have in place and compare that to what is required. And then together, we both see that if there is a gap or if it's solidly in place.

Yep.

And sometimes in super complex environments, we get to the on-site stage, and and there will be question as to whether certain things have to be in place in in some places or not others, like, multifactor authentication where you have to have that. You can go way down a rabbit hole with MFA depending on are things accessible from outside your network or from inside your network, from from people who are on this subnet or that subnet. But, I mean, that gets pretty technical. I don't wanna dive into that. But there's always room for conversation about, is this really applicable, and is this the way we're doing it accepted by PCI, or do we maybe have to look at us compensating control to allow us to do these things? So the it's never exactly cut and dried in a checklist. It's always some measure of negotiation depending on how complex your organization and your and your systems are.

Yeah.

And, just to give you an idea of what a typical assessment looks like, it usually, you know, a a just a typical merchant trying to be PCI compliant will take a couple days to go through the requirements and will meet with the people that are. Oh, another thing I forgot to mention, logistics.

Yeah.

So before we come on-site, we we wanna set up an agenda, make sure that those people are gonna be available during the times we decided on to come on-site. And then we go on-site, and for the first couple days, we meet with the different groups. They show us evidence. They, you know, show us systems and and and and whatever's there. And then usually on the third day, if everything's gone pretty smooth, we we could possibly do a data center visit or maybe a wrap up meeting of some sort. If things didn't go smooth, we probably use the third day to continue with whatever area didn't go smooth.

Right.

That's typical. Now with with Jen and I, we we do, participate in the large audits, which which can take multiple months. Yeah. Not just like a a week or a few weeks. So some of those are are big, and and they're more complex, but it's the same thing. We're checking, whether or not the different merchants are following, the PCI requirements.

Right.

And sometimes the the fun on sites are, like, retail stores or or or convenience stores or, fast food. Because then you get to go and do a little bit at various different things. And if you like road trips, then it's like, ah, road trip. I'm gonna go check it.

And if you hate road trips, then you don't like those particular audits. But, that's where you go and you say, alright. Is your point of sale system set up the way that your evidence has said? Let's look at your firmware.

Can we look in person and see if your firmware is is correct to what your documentation says it should be? Right? We we do the in person interviews of what kind of training have you had in terms of dealing with, credit card data. And so it it's slightly different for every organization.

Some groups don't have point of sale systems. Some some groups are entirely like service providers, in which case, it's data centers and corporate offices. Right? And and, and then you have to wear, like, a professional shirt and everything.

Well, you know, another thing that's not uncommon is during the assessment, we'll find, another pay flow. You know, payment channel. Yep. And then and then you have to figure out, well, do we have enough time in this audit to include it? Yeah. Or or or if not, you know, you need to talk to sales. So sometimes that sort of thing will come up, and it's not a surprise.

So so, you know, before we're doing the assessment, you wanna do the best you can. I think about three months out, we we're hoping that you're providing, network diagrams and data flow diagrams. Mhmm. And we've discussed with all the people that would possibly know where payment flows are.

And and so, hopefully, you know, we don't discover too much while we're on-site. But one thing to think about that people always forget are are any manual, emergency type procedures Mhmm. That you do. And are you, you know, are you storing paper of any sort to to supplement some emergency procedure?

Those are usually the ones that people forget about. Then you find a cabinet somewhere where there's a bunch of card data.

Yeah.

And then you're like, oh, well, you know, how do you how do you securely shred this and and things like that.

And they say, what? That's just the catering department. That's the way they've always done it. And you say, okay.

Wait. Yeah. But they're in nowhere here have you said catering department. Let's talk about that.

You know? Because Catering? Catering. So so a lot of times we'll go to an organization and they say, alright.

Cards are swiped here. They take this or but catering is like, yeah. We'll take your credit card number, but we won't process it until we actually deliver your order. So that's one of those, like, those types of card flows that they don't even think about.

So as organizations think about what are all of our card flows or in terms of of HIPAA, you know, how does information that you're supposed to protect come into your possession?

All of those data flows, those are hard for anyone to to identify. But, you know, what I find, the groups that really struggle with that is where they say, IT, you're in charge of this assessment, and it's all pushed off on IT. And then you say to IT, what are your data flows? And they go, I don't know. Well, okay. So how does the business take in this whatever sensitive information you're taking in?

Not only do they not know, the how should they be expected to know? Right? They they're not part of the business process side. They just support the system side. Right? So, so in terms of that, who do you think should be involved in an assessment, and at what point do they get involved? You know, we've talked a little bit about pre engagement, the pre on-site, the on-site.

So so who needs to be involved in those various steps?

Yeah.

Absolutely the business. They they should not think that this is just technology stuff. This is absolutely part of the business, key to the business. You know? So typical groups that get involved are accounting. So make sure, you know, money's coming in, money's going out. Who knows about that?

Right.

Accounting people know. You know? IT people, you know, they support it.

Yeah.

They they're the ones that that have to put security on the technology, but the accounting people actually know the flow. Like, where does it go? What bank does it go to? What merchant IDs do we have?

Yeah. Those are the questions that are critical to PCI. You know? We we follow the merchant ID.

That tells us where who has the liability? Who who has to get, you know, all these controls in place? The person that has a merchant ID.

Right.

So that's that's key in in deciding now when it comes to people that you need to talk to, obviously, if you're doing any sort of website, you need the developers.

Mhmm.

So you gotta get, you know, sometimes they're a a a different type of of people.

Developers are hard. Not to be whiny, but, it it can be it can be difficult to, communicate with developers need that information Yeah. Because they're very detached from the whole payment process. What? I gave you a thing that works. Why are you asking me about this?

They're more about functionality.

Exactly. I made this thing work, and and I'm I don't wanna be involved with your I have things to write. Let me go code. Right? And so helping them understand the the critical nature of security in in their job. If they don't already know it, some are great and a hundred percent know that security is part of development.

But there are groups that yeah. Especially in the web development area, and they say, look. All I do is I take this iframe and I put authorize dot net. Wait. What are they called now?

They're called another thing right now. They got bought by someone else.

Sorry.

I don't know. I forgot. I know. Came up in our meeting, so they're no longer out there.

With a c, and I can't remember. Anyway somebody else. So there there's a a payment, gateway that will give you the information. You you tuck it into your, web page that you display, and they take the credit card information and send it off.

It goes from the customer's browser off to to their browser. Right? And so, then organizations say, well, especially the web developers, this has nothing to do with us because it's this widget that we drop in here. Right?

But they don't understand that it it without secure coding and without secure, security tools embedded into those pages, somebody else can go in and, you know, pop that that web server and put malicious code in there and scrape off information and siphon it off without anybody knowing about it.

Sounds like a drive by.

It's kinda like a drive by.

Only He's gonna go pop that server. Yeah. Anyway Sounds sorry?

That sounds very aggressive, Josh.

So, yes. So helping each, individual that could affect the security of whatever information you're protecting, helping them understand how they could affect that security and how you need their help to to to ensure that security makes every assessment go better. But, it's kinda it's the business that whoever says we are going to have this assessment done, you know, you've gotta have that, appropriate level of executive sponsorship on any project.

Mhmm.

And and and an assessment is definitely a project where you want somebody with sufficient, seniority to say this is important, and I'm going to get all the people involved that need to be involved.

Yep. So so developers, if you have a website, as part of your payment channel, your dev folks or the company that does development needs to be involved.

Yeah.

And then your your of course, the people that take care of the servers, your sysadmins, they're a big you know, the patching is big for PCI. Do they have a a formalized process that makes sure that happens and makes sure that if something didn't get patched, how would you know?

Right.

You know, those those types of things.

And then a lot of times, the people who are doing, antivirus well, we have antivirus on everything. Great. And the people who are doing antivirus often are, like, your your help desk people. But you might have somebody who is, considered maybe a a a different level or a different group looking at your ID your intrusion detection, intrusion protection.

Right? So looking at monitoring, logging, and alerting might be slightly different from your antivirus people, and they need to be involved. And then you've got your file integrity monitoring, often part of this group, but not always. Sometimes it's it's more your development people or your data integrity people.

So it kinda depends on how diverse your different groups are that are looking at different types of security in your organization.

It's super important to get them all involved.

Yeah. I I figured I'd just quickly mentioned, I know something that something that we don't really get involved in is is the what's it cost?

Well We have to because it's part of it.

Right? But you know what? People ask me about cost all the time as an assessor, and I I don't know.

I'm not I'm not quoting.

I can tell you hours and then somebody else goes and figures cost.

But, yeah, if especially if you know you probably do know this because you work with our sales teams more than I do. But, yeah, what does it cost to get an assessment? And is it different for, like, penetration testing versus a audit?

Yeah. Absolutely.

So with with the, the audits, they can be as little as fifteen k up to around forty. So that's that's a a a normal range.

Yeah.

When we do the bigger audits, you know, that's that's gonna go up pretty a a lot higher than that.

Large complex organization.

That's definitely not not gonna be your typical audit. That's gonna be a lot. And and, basically, you know, how many merchant IDs are you looking at?

How many reports do you need?

Right.

How many weeks is it gonna take? Sure.

Another tip. Let's let's call this a tip. You you don't wanna just meet with your auditor every week just because that's a nice thing to do. Yeah. Those are what we call billable hours.

Yes.

So that that time gets built to your project. Have a meeting.

Yeah. It's probably better not to.

So just because that's what you do with other people, you know, from a from a tip in in terms of saving money, Don't just do it just because you you it gives you a warm fuzzy or whatever. You know?

So You know what else can can simplify an audit?

Yeah. Is, depending on how many different platforms they have their, information or their systems in, I I worked with an organization that they thought it was going to be a fairly simple audit, but they ended up having, their own, on prem servers. They had two different data centers, and then they they had, and one was one they managed and one that they had hands from the data centers doing it. They were also in Azure and AWS and somewhere in GCP. And I just went, this is this is not going to be simple. Let's let's And so we actually had to go back and and readjust how many hours it's going to take because the less consistent something is, the more hours it's going to take.

Absolutely.

And I know that translates to money.

Yep.

So on the pen test, this is, you know, another area that can be scary for an organization.

The the ones we look at can go from around fifteen to seventy.

These are some that's a range that that often an entity is, going to be paying for their pen test. So it is a bit pricey.

Mhmm.

But just something to keep in mind, it's based on how many days is it gonna take to to appropriately pen test the environment.

And I think that number of days can be related to things like how many roles do you have with different levels of permissions in the application, how many APIs do you have. Yep.

So it's the the application layer pen test as opposed to a network layer pen test is gonna take a lot more time. Network layers are typically less time.

Yep. And so so what you have, you know, with with the net for a typical PCI assessment that we do, we want them looking at the network environment. And as things change, you know, sort of evolve in how applications are are provided, that that takes on a new, a new approach, let's say. Your your traditional approach has, you know, some sort of firewall they're trying to get through, and then you have systems.

And now as things become more virtual, the you know, things are a little different. But but those so you're gonna do a network pen test, and then you're gonna any any application involved in in the payment, system needs to also be, included. Right. And so that that is what we'll be looking at.

And as as a QSA works with you, they will help you understand what piece needs to be tested to satisfy the requirements for, for PCI.

Sure. Sure. It's it's their responsibility to scope their environment, but then the QSA comes in and says yes or no to whether the scope is appropriate. Mhmm.

So there's a kind of a balance there. And, it's important to lean on your QSA to know before they get on-site if the scope is correct. Pen tests take time. So you wanna make sure that that scope is correct far prior to your your on-site.

Yep. So so just like, you know, six months or so or rather nine months, you're working with the QSA to determine your on-site date. That pen test should be a big part of scheduling. So you want that to happen either either a little bit before the assessment or right around the same time.

Three months before.

The three months before would be awesome. Yeah.

Again, I'm I'm a lot meaner than you are, George. But, because if you if you have this if you have the pen test scheduled right when your assessment is and I know that most people don't do this, but I I'm kind of a freak about it.

What if they have a problem and they have all of these things that need remediation? Yeah. And then they run out of time, and then everybody's stressed. And then all of a sudden, you're getting fined by your bank because it's not done when it's supposed to be done. I don't want that to happen to anybody. Right? So planning ahead is, I I might have a little bit of a cybersecurity prepper mentality.

So Well, that is good. The the other thing is, you know, our our slots especially at our company, slots can fill up quick. Yeah. So if you don't schedule your time, you you you end up getting it later and later.

And Yeah. The the later it is, the worse it is for your assessment. Sure. Because you have to have the results of it and the remediation done before the report's signed.

Right?

Because we can't say, oh, yeah. Well, it's great that you have this thing planned for the future. I'm gonna check that off. We we don't get to do future state. Right?

Yep. So so what Jen recommended is is safe. That's the safe approach. Yeah. And you wanna get on the schedule so that, you know, you get it done.

Okay. Now the other thing that comes into play post assessment is we typically look for thirty days. So we want you to have all your so we're gonna do the assessment, and and we try to be an advocate in the sense that, you know, we we point out what you need to do to become compliant, and and we look at it. And and, you know, we we try to help you to to, encourage you, let's say, to get it done so that that we can complete the report.

And and we look at thirty days. So post assessment, we want you to be remediated, done, everything done within thirty days. Yeah. And then your report comes around thirty to forty five days later post assessment.

Yeah. Why does it take a report so long?

Well, the darn the the darn thing's long to begin with.

Take forever to write. There I've had reports that are forty, fifty, sixty hours just in writing time.

And and it's, it takes the time it takes, unfortunately.

So so the the more information the more accurate information Yeah.

That our customers can give us in detail prior to and during the on-site, the quicker that report writing can happen.

It almost sounds like a fine wine.

It just takes the time to take.

That it takes.

That's it.

So yeah. So That's Jen. Same right there.

So post on-site, for sure, we wanna to get that, that remediation done and the re and the reason we need it within thirty days is because, everything that we saw during the on-site, that's gonna go stale. That that Yep.

That's that's for stale.

Yeah.

Yep. So we we push our customers to get that. And, once it goes beyond a certain time, we we will require a revisit.

Yeah.

Because as Jen mentioned, things go stale, and we no longer have the confidence that you're complaining.

Yeah. And that's not just us. This is assessors everywhere. Like, any good assessment company is going to say, we we cannot take information and just let it sit.

We have to take a look at it again. You have to refresh it to make sure that the report is accurate on the most current information. And so that's just a that's just a standard how how you what you need to expect with any organization. Mhmm.

So then, after they get the report and it's all signed and and things are finally we can say, at that point in time, when I sign that report, everything was current. Mhmm. And then what?

It's a magical moment.

It is a magical moment.

The heavens part. The angels sing. No. No. We are we are happy when when people are able to, you know, validate their compliance.

We're able to sign the report, and we feel good about it. Yeah. You know, we we we, you know, we it's just if something's not right, we're not gonna sign it. You know?

That's just not gonna happen. Nope. So, you know, we may like the customer a lot, but that's you have to show compliance so that we feel good signing the thing.

Yeah. It's basically Well, and they're gonna sign it too. So we wanna make sure that whatever we're signing, we're all signing truthfully and accurately, and this is where we're at. It's not helpful to the customer if we say, yeah.

We'll sign it. And then they get a breach. Yeah. That is that's the worst feeling, to to think about that happening.

So, yeah.

But then after that, everything's signed, and then there's, some ongoing sometimes, I don't know if you get get customers like this, but I I I do, and I'm sure that that throughout the industry, you know, you you develop a relationship with people and they then they have questions and they wanna reach out and ask a question.

Yep.

And I I tend to just kinda answer it, but I'm always hopeful that we're gonna to have them the next year so that sales doesn't yell at me for for putting hours towards something. They're like, we don't even we're not even working with them. But but I think I don't know. I feel like it's the right thing to do for for security in general. You just Yeah.

Try and help and reach out and let people know. If you're gonna rearchitect your whole environment big time.

Then you might wanna reach out to your QSA and say, hey. We're planning this entirely different way of doing things. What do I need to do in order to do that? And and sometimes that's another, you know, that might be an an additional cost, but it might be also wrapped in kinda depends on on what your engagement is like. So I don't I don't know the money side. I just want people to be secure.

So so that phase, we kinda refer to as ongoing support post post the the whole process. Right? We so we we try to, provide helpful, hints as because we want you to be compliant the next time we come around. Right?

So little reminders, you know, you know, hopefully so from PCI perspective, there's daily tasks. Mhmm. There are monthly things. There are semiannual.

There's annual stuff. So we're hoping or or quarterly. And and we're hoping that you continue to do these things so there's not that deer in the headlights look when we say, oh, give me your quarterly inspections of, you know, wireless devices or whatever.

Right.

And, Or some of the big things Yeah.

Like TLS. Right? So, for Changes. For a while, we had to tell everybody TLS one point one or above, and and here is your date for that. There was a very specific date that PCI gave.

And then, on an ongoing basis, you know, having to tell them, look. TLS one point one is great. Glad you got there. But guess what?

Your vulnerability scans are going to start failing if you only have one point one in certain circumstances because you need one point two. This is not because we want you to change things, but because, vulnerabilities happen. Vulnerabilities get exploited out in the wild, and then we have to tell people. And so if we have an ongoing relationship with a customer, I try and reach out and say, hey. Just an FYI. I don't know if you've been thinking about this, but, get on this one.

I usually send them, like do you know Douglas Adams and the whole Hitchhiker's Guide to the Galaxy?

I like I like The Hitchhiker's Guide to the Galaxy.

Book that said don't panic. And so I usually send them the don't panic picture. And then I'm like, okay. But don't panic, but kind of a little bit panic. You have to do this thing.

So, you know, we we try to keep up to date with what's going on in the security world. And when we see weird things going on and we think, oh, yeah. My customer uses whatever that product is. Yeah. I better let them know and say, hey. You know, there's this thing.

Yeah.

You need to be aware of. You need to update your systems or patch or Yeah.

You know, just just in case. Because by PCI standards, they're required to know Mhmm.

When things are need patching. But, you know, sometimes, for for whatever reason, you could miss something. Yeah. And, yeah, we we like our customers to to feel secure.

Yeah. Yep. For sure. So, let me I wanna jump ahead. I know I gave you a whole, talking points list, but I kinda wanna jump ahead to one really critical one, which is scoping. Mhmm. And that is, what how do you scope let's so scoping is for different things, but let's let's leave it to PCI for now.

How do you, successfully scope a PCI environment?

I think the number one thing you have to consider is to do it carefully.

Yeah.

I mean I've just You mean you can't just say, we got a server in the corner.

Sometimes we plug it in.

So so, you know, the typical approach is number one, you have to know what you have. Right? So you have to enumerate your payment channels.

Yeah.

And you talk to the people that do it and that could possibly do it. Mhmm. You've got okay. Who takes payments?

How does how do payments come into our organization? Mhmm. How do they you know, what what's the process? And so you have to start with documenting what you have.

Yeah. And then you can determine scope.

Mhmm.

If something, you know, it it it processes, stores, or transmits card data or could affect any of that Yeah. That's part of it.

That's a scope. You know? Exactly.

And and it's easy to say, this doesn't touch card data. It's not in scope. Yeah. But that updates the systems that do touch card data. Yeah.

You know, somebody tries to pivot from that system into your CDE, your card data environment, then you have a problem.

Yeah. And and and one of the ways that I have found that you can get a lot of people engaged that that know if it can affect the security ever or not is is to gamify it a little bit. And you say, alright. We're gonna if we were going to be on the outside looking in and we wanted to to, pop our own boxes Yeah. Drive by.

Gangster gym.

Gangster gym. Exactly.

How would you do it? So we know that these systems have credit card data. And and sometimes, especially every once in a while, you know you get really smart guys that all they wanna do is argue with you. So I'll do this.

Okay. So we know we have this box, and it it takes credit card data. And, this box over here, might communicate with it, but there's no way that you could get credit card data if you were on this box. And then they go, oh, well, I could.

Oh, so well, look. Sometimes you have to do it. And and, using a little bit of social engineering in order to get people to bring their best game to finding out how do we keep things secure. That's part of our job, I think. Yeah. So yeah. Knowing on that cyber kill chain that's a fancy phrase.

So if someone is hacking your systems or or doing negative things, there's different places along the line where you can be aware of that and stop that activity. Yep. That's called the cyber kill chain.

Oh.

And and I know. Super fancy. Right? So, helping other people know what their role is in helping you understand what the cyber kill chain is, That feeds into what is your, scope. Because anything that can potentially affect the security of the system that's in scope is going to be also in scope.

Yep. So so, you know, always remember, logging and alerting, and these are pieces that you're gonna rely on to know whether something's attacking your your card data.

Yeah.

So those systems that impact it and our typical approach is we look at the system and determine, you know, is it appropriate appropriately, secured and controlled?

Right.

And and we have the the twelve areas with, PCI to to apply. Yeah. But a lot of times, people don't wanna go there. They think, no.

No. No. No. That's not in the card data environment. Well, it affects the security. That's that's the Yeah.

It's because more people have to get involved, and you'd have to take more time, and nobody wants to do that.

Understandably.

Okay. So last big topic is this.

Did you know that we're in the middle of pandemic?

Are we talking remote assessment now?

We're talking remote assess. So you and I are very, very fortunate because we live in in Utah where, instances are very low, and we have some some very, we have a lot more flexibility and freedoms in terms of how do we address this particular outbreak than than some places have. But we have we're it's still impacting us a lot Mhmm. Because we don't travel.

So what do you do? You know, on sites, I have always thought, were the most critical way of, ensuring we we got everything during during assessment. Yeah. Now we're doing remote assessments. How what do we do? How do we make it good?

So, you know, a number of, methods have been used. A lot of times, it is, someone holding a a device that's streaming video.

Mhmm.

And so that's about as close as we can get to actually being there Yeah.

When when we aren't able to. So that that's, you know, that's that's the level that we go to. And then and then you just dig a little deeper because you're not actually there to get all the visual and audio cues that you know, in person, there's certain little, it's almost like poker and and and they they have little telltale signs that, you know, they they look fidgety. They look nervous.

Sounds like they are not doing this thing.

Or If in if you're in person, it's a lot easier to say, hey, guys.

You know what you're Yeah. You know where you've got a vulnerability. Tell me what is so we can include it in this report. And they go, okay. Let me tell you. And then you get all of the information.

That's right.

But it's harder when you're on a conference call, when you're a phone call.

It is. It is. I in my opinion so you do the video thing as much as you can. And then anything that that's just a call, you may have additional questions.

Now we have, you know, we we use Zoom and we use, Google Meet and, what's the Microsoft one? Meeting something. Teams? Teams.

Yeah.

So we have all these tools that for certain customers, they work better. And so we use that to to demonstrate or show evidence. Mhmm. And so, you know, we'll, if there if if everything's alright, we'll use recordings of that as evidence that, you know, the the customer showed, evidence that this control is in place.

At the end of the day, I mean, this is just coming from my mind, is I could create evidence that is convincing. Mhmm. So, you know, the system admins have the ability to create just about anything that we're looking for, but we, having had experience in IT and other things, we can usually catch when when somebody's not quite truthful.

If they're making it up.

If they're making it up. You're like, well, could I see something from this date? Or could I see another and you're like and they're like, woah. Uh-uh.

Uh-uh. That's gonna take a moment. Yeah. Yeah. I think, you know, make sure it's in place.

Document it. Show me an iteration because it seems like it's not in place. Yeah. Not not to call somebody a liar straight to their face.

No.

Because that just causes That's just weird, you know?

That's not our purpose. Our purpose is to ensure you have the appropriate control in place, and it's effective.

Yeah.

Right? You could you could have it on paper, but it's not actually happening. Yeah. That's not that's not our purpose.

And we all want to agree, both the assessor and the organization want to agree that things are in place so we can all sign that report together.

Yeah. Yeah. So from my perspective of of thinking, man, I could I could fake that evidence pretty good.

You know, at some point, you're gonna have to trust them. You do all that you can to verify and and, like, you know, do your due diligence being that you can't be there in person. Mhmm. And it's basically the best that you can do if that's video and evidence via Zoom or or Google Hangouts or or other.

You know, we'll try to get more than we would if we're in person just to support the the whatever we're writing. Like, we're saying, yeah. From the evidence that we observed, it looks like this controls in place, and it is effective. Mhmm.

That's the goal. Right? And and that's that's about as good as we can do.

So we in this time of COVID, we do the best we can with those tools Mhmm.

And and we write the report. And when we're able to go on-site again, we're gonna do that because that that is where you really, can tell whether something's in place. I mean, we just do the best we can with the technology we have. Yep. That's about all we can do.

Like, we like to joke about liking some of the trips and and because there's some truth in it. Some of the trips are really great.

Yeah.

But some of them are, like, to Phoenix in August. So I like Phoenix, but not in August.

Are we gonna be talking about locations we don't like?

Or No.

Because that would be rude. I'd sorry. I love people in Phoenix. Back to Singapore anytime of year.

Oh, yeah. Those are those are nice places.

But, you know, people give Jersey a bad rep, but So that's I've had fun there.

You know?

It's had some beautiful There there may be, crime going on.

But Yeah.

You know? And I joke about India because I I go there a couple times a year, and, I love it there. But it does give me dysentery.

No matter what I do, I So you're gas powered on the way in?

Or Absolutely. George. Sorry.

Well, this has been super, fun talking to you. I really appreciate your time coming and talking to me this morning, on the podcast. And and thanks for for joining us all.

Hope to see you again, here at the Security Metrics podcast.

Awesome.

See you, George.

Bye, Jim.

Bye.

Thanks for watching. To watch more episodes of Security Metrics podcast, click on the box on the right. If you prefer to listen to this podcast, it's available on all your favorite podcast platforms. See you on the slopes.