Login Form


Board index » PCI Compliance » PCI for store owners - merchants

All times are UTC - 5 hours




Post new topic Reply to topic  [ 8 posts ] 
Author Message
 Post subject: PCI Compliance Questions-Site Scanning-McAfee, etc.
PostPosted: Wed Feb 17, 2010 10:24 pm 
Offline
CRE Talented
User avatar

Joined: Thu Jan 31, 2008 12:58 am
Posts: 420
Location: Denver, CO
I am working towards getting my website PCI Compliant. I know authorize.net and my merchant bank are both PCI Compliant. Also, I don't store credit cards on my website or office computer and I have a private SSL.
I am using a shared plan with HostGator but am switching to a VPS hosting plan with HostGator.
I have done a lot of research and have posted on here before and it seems a missing piece is I have to have a scan done of my website and also fill out a huge questionaire and then submit it along with my scan results to my merchant bank to become PCI Compliant.
Am I correct about the above?
What this comes back to is site scanning. I have looked at many services including McAfee, Security Metrics, ControlScan, and TrustWave.
Most of my research so far has been with McAfee. They have a service for $319/yr which includes quarterly scans and manual scans as often as I desire. The are no logos with it for my website.
They also offer a full service for $959/year or $1289/2 years for a discount. This full service includes their PCI Scanning but also it includes their McAfee Secure scanning. The scanning is done daily and also with the McAfee Secure scanning you get a McAfee trust logo for your website.
With HostGator's shared plan for free I get the McAfee secure scanning with logo and it includes the PCI scanning but also once I change to VPS hosting I likely will lose this.
I am interested in opinions of the various options for scanning, MCafee, Security Metrics, and ControlScan, and also Trustwave and also if I go with MCafee is their higher plan worth it? They claim I'll see an increase in sales but is that likely to be true? Thank you for your thoughts on the above.


Top
 Profile  
 
 Post subject: Re: PCI Compliance Questions-Site Scanning-McAfee, etc.
PostPosted: Thu Feb 18, 2010 6:13 pm 
Offline
CRE Talented
User avatar

Joined: Sat Apr 19, 2008 3:51 am
Posts: 431
Location: Tennessee
ask them to guarantee in writing a percentage of sales increase within a certain amount of time ( which they will not nor cannot do )

If they say they can then ask if they fail will they continues the scans for free for the life of your website ( they will say no but you can have your money back

( ask would it not be better to just keep the money in my bank to begin with )

_________________
Image
http://www.dragonstailmotorsports.com/


Top
 Profile  
 
 Post subject: Re: PCI Compliance Questions-Site Scanning-McAfee, etc.
PostPosted: Fri Feb 19, 2010 2:37 am 
Offline
CRE Talented
User avatar

Joined: Thu Jan 31, 2008 12:58 am
Posts: 420
Location: Denver, CO
The more I have read up on McAfee's Secure the more I am against it. I had done a live chat on their site and they told me a rep would call me within 10 minutes. He did but I was already out of the office and returned to have 4 phone calls. Phone calls started at 7AM today and they are basically not offering me the PCI Compliance telling me I need the other plan that is $968 approximately, about all the sales, etc. High Pressure sales are a huge turnoff to me, especially when they try to sign me up before I'm able to ask all the questions I want to. I may look at their pci compliance option but I think basic pci scanning is all I need and I likely wil llook at controlscan, security metrics, qualys, or trustwave.


Top
 Profile  
 
 Post subject: Re: PCI Compliance Questions-Site Scanning-McAfee, etc.
PostPosted: Fri Feb 19, 2010 4:56 am 
Offline
CRE Talented
User avatar

Joined: Sat Apr 19, 2008 3:51 am
Posts: 431
Location: Tennessee
One thing you better ask your hosting company is if they are willing to work with your scanning company to assist in getting your site PCI compliant!
I ran into the same thing when I was using CRE Hosting ( Chain Reaction Hosting) one thing was said then I was later told something different.

It was always the scanning companies problem (WINK-WINK) ( Control-scan) even though they used to say "THEY WERE PARTNERS" even they could not make it happen and pass scans on a regular basis.


SO be sure to always save emails and get everything in writing before hand!

_________________
Image
http://www.dragonstailmotorsports.com/


Top
 Profile  
 
 Post subject: Re: PCI Compliance Questions-Site Scanning-McAfee, etc.
PostPosted: Fri Feb 19, 2010 7:01 am 
Offline
CRE Addict
User avatar

Joined: Thu Sep 10, 2009 10:10 pm
Posts: 252
Location: Sheffield, South Yorkshire, United Kingdom
Mark,

Not sure how relevant this would be to you, as we use PayPal Pro and I just noticed this on their site while researching further PCI stuff;

Quote:
PayPal helps
PayPal has partnered with ScanAlert, a Visa and MasterCard-certified PCI vendor, to help our customers comply at no cost for the first year. Enroll online with ScanAlert at: https://www.scanalert.com/SignUp.sa?oc=9673.


ScanAlert is a McAfee service, free for the first year... I've read the T&C's at the bottom of the page and they say the following;

Quote:
Automatic Renewal

Customer agrees that subscription based Services will automatically renew at the end of each subscription period, at the then current list price for the Service, unless Customer sends notice of Customer's request that the Services not renew. Such notice of non-renewal must be sent to McAfee through the e-mail address [email protected] at least thirty (30) days prior to the end of Customer's current subscription period. Notwithstanding the foregoing, if Customer purchased the Services from a McAfee authorized reseller of the Services, the subscription for the Services will not automatically renew at the end of the purchased subscription period, but shall expire and require the purchase of a new subscription period in order for the Services subscription period to be renewed.

Breach

Customer is in breach of this agreement if Customer fail to pay any amount owed to McAfee when due, subject to a 10 day grace period, or Customer fails to comply with these Terms. Unless otherwise stated, fees for Services are due in advance and subject to payment terms in the invoice(s) for the Services, which are incorporated into these Terms by reference. If Customer is in default, McAfee may take any or all of the following actions to remedy the default and protect its interests: (a) declare all unpaid monies immediately due and payable; (b) Terminate Services; (c) terminate the Services; (d) take any other lawful action McAfee may deem appropriate to enforce your obligations under these Terms. Customer agrees to pay costs and reasonable attorney's fees McAfee may incur enforcing its rights under this agreement.


So I'd send them a cancellation letter or something similar around the 340th day and by that time, hopefully there's more competitively full priced PCI scanning services out there in a years time?

You may not use PayPal of course but I just thought I'd let you know what I'd come across, in case it helps.

_________________
Regards,
Rob

Newbie Cre Loader - Running Version: CRE Loaded PCI Pro v6.4.0.a

http://www.shopfullstop.co.uk We Offer It, You Buy It!


Top
 Profile  
 
 Post subject: Re: PCI Compliance Questions-Site Scanning-McAfee, etc.
PostPosted: Sun May 15, 2011 10:27 am 
Offline
CRE Newbie

Joined: Sun Oct 04, 2009 5:11 pm
Posts: 16
GoDaddy offers scans for less than $10 per month and provide a "logo" indicating status of site as well. http://www.godaddy.com/security/website ... x?ci=20677


Top
 Profile  
 
 Post subject: Re: PCI Compliance Questions-Site Scanning-McAfee, etc.
PostPosted: Sat Oct 15, 2011 2:13 pm 
Offline
CRE Legend
User avatar

Joined: Wed Jul 30, 2003 12:00 am
Posts: 1521
SAVE YOUR MONEY.

Scans do nothing to really secure your data, they just waste your time and give you a false sense of security.

CRE Secure will really actually provide you with seamless PCI Compliant security and we now support more gateways than ever.

Also you can get CRE Secure free for 25 trans a month with any 6.5 pro or B2B purchase and the 250 trans a a month is just $12 a month additional.

Try it and you will see it is the best possible solution for PCI Compliance bar none.

_________________
Regards,

Salvatore Iozzia
Founder and Chief Evil Overlord
Loaded Commerce, LLC & The Reactor Works / Hosting
http://loadedcommerce.com | http://thereactorworks.com | http://thereactorhosting.com

JOIN THE LOADED SKYPE CHAT:
http://tinyurl.com/7mlvwot

follow me on TWITTER! http://www.twitter.com/saliozzia


Top
 Profile  
 
 Post subject: Re: PCI Compliance Questions-Site Scanning-McAfee, etc.
PostPosted: Wed Nov 14, 2012 4:47 pm 
Offline
CRE Talented
User avatar

Joined: Tue Nov 30, 2004 1:00 am
Posts: 384
Location: New Smyrna Beach, FL
drm1963 wrote:
One thing you better ask your hosting company is if they are willing to work with your scanning company to assist in getting your site PCI compliant! I ran into the same thing when I was using CRE Hosting ( Chain Reaction Hosting) one thing was said then I was later told something different. It was always the scanning companies problem (WINK-WINK) ( Control-scan) even though they used to say "THEY WERE PARTNERS" even they could not make it happen and pass scans on a regular basis. SO be sure to always save emails and get everything in writing before hand!


We always assist clients with operating system scan violations and remediate as false-positive or dispute because the underlying open source project such as OpenSSH and centOS may have back-ported and patched rather than matched the version the scanner thinks should be present.

We do charge to fix violations found in the CRE cart such as the attack vectors of advanced search, banner manager and others. The best thing to do to ensure a host has completed their assessment is request an "Attestation of Compliance" document.

_________________
Inetbizo Open Source eCommerce Strategy Consulant
========================
CRE, osCommerce E-Commerce Education, Forums, Links


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 8 posts ] 

Board index » PCI Compliance » PCI for store owners - merchants

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
It is currently Sat May 25, 2013 11:35 am
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group