Payment Card Industry Compliance and Assessment Services
PCI DSS Compliance Audits: Conducting formal assessments to verify that organizations meet the Payment Card Industry Data Security Standard (PCI DSS) requirements.
PCI DSS Gap Analysis: Identifying areas of non-compliance and providing recommendations for achieving full PCI DSS compliance.
PCI Penetration Testing: Performing targeted penetration testing on cardholder data environments to ensure they comply with PCI DSS standards.
PCI SAQ Assistance: Assisting organizations in completing the Self-Assessment Questionnaire (SAQ) to evaluate their PCI DSS compliance.
PCI DSS Remediation Services: Offering guidance and support to help organizations resolve non-compliance issues and meet PCI DSS standards.
PCI DSS Readiness Assessments: Evaluating an organization’s readiness for formal PCI DSS audits and identifying areas for improvement.
QSA (Qualified Security Assessor) Services: Providing certified QSA professionals who perform official PCI DSS validation for organizations.
Cardholder Data Environment (CDE) Assessments: Reviewing security controls within cardholder data environments to ensure they align with PCI DSS requirements.
PCI P2PE (Point-to-Point Encryption) Assessment: Evaluating encryption solutions to ensure they meet PCI DSS P2PE compliance standards.
PCI Tokenization Solutions: Implementing and assessing tokenization technologies to protect cardholder data and enhance PCI DSS compliance.These are conducted from the internet or from inside an organisation. Tests will determine if it is possible to gain access to sensitive information such as PII, Finance or Medical data. The scope will be discussed with clines and could including Applications, Databases and Cloud based resources.
Testers will assess whether a user can escalate their privileges and gain usernames and passwords for other business users or access sensitive data. Check will be made to remove data from the corporate environment or whether a user can circumvent existing security controls to grant themselves inbound access to Organisations.