The PCI DSS states that yearly assessments are to be performed by ASVs, while self-assessments can be done quarterly by qualified and experienced professionals. Qualified persons should have multiple years' experience in penetration testing and possess one or more of the following certifications:
- Certified Ethical Hacker (CEH)
- Offensive Security Certified Professional (OSCP)
- CREST penetration testing certifications
- Global Information Assurance (GIAC), for example, GPEN, GWAPT, and GXPN.
The tools used by professionals for the PCI DSS assessment can be commercial or open source, as long as they generate a high level of accuracy. In this book, we have used many tools, some of which not only perform multiple functions, but do so in an automated manner, usually once all IP information has been specified.
In Chapter 6, Vulnerability...