Why Schellman is Able to Perform Both PCI DSS and Penetration Testing Services for Your Organization
Hi, I'm Matt Crane. I'm a leader in the payment security practice here at Schellman.
We're often asked if we're able to do both PCI assessments and penetration testing for the same client. In this video, we'll explain how we're able to provide both and why it's not an independence issue.
First and foremost, I want to cover what the PCI Council says about this. While they don't specifically state that it is or is not an independence issue, if you look at Requirement 11.4 of PCI DSS v4.0, it talks about penetration testing services methodologies. The two main criteria that you have to have as a penetration tester to meet that requirement are:
- You have organizational independence, which means that the individual performing the test cannot be ultimately responsible for securing that system.
- (It goes on to say that organizational independence doesn't mean it has to be an ASV or approved scanning vendor or even a QSA, but so long that that individual doesn't have control over the systems they're testing, it's fine. So, if you have an internal resource that's qualified, you can move forward with them.)
- The organization or the individual conducting the penetration test must be qualified to do so.
- Schellman's penetration testing team, with many of its members holding multiple certifications is, in fact, qualified to do so.
At Schellman, we go a little bit further to make sure we don't have independence issues. Our payment security team—which is ultimately comprised of PCI QSAs—and penetration test teams are separate, and they each have different management structures.
We do that really for a couple of different reasons—primarily because a QSA and a penetration tester have very different skill sets, but also so there's no perceived bias for a QSA who's also doing penetration testing services for the same client.
About Schellman
Schellman is a leading provider of attestation and compliance services. We are the only company in the world that is a CPA firm, a globally licensed PCI Qualified Security Assessor, an ISO Certification Body, HITRUST CSF Assessor, a FedRAMP 3PAO, and most recently, an APEC Accountability Agent. Renowned for expertise tempered by practical experience, Schellman's professionals provide superior client service balanced by steadfast independence. Our approach builds successful, long-term relationships and allows our clients to achieve multiple compliance objectives through a single third-party assessor.