Video

Why Schellman is Able to Perform Both PCI DSS and Penetration Testing Services for Your Organization

Written by Schellman | Sep 11, 2024 4:43:06 PM

Hi, I'm Matt Crane. I'm a leader in the payment security practice here at Schellman.

We're often asked if we're able to do both PCI assessments and penetration testing for the same client. In this video, we'll explain how we're able to provide both and why it's not an independence issue.

First and foremost, I want to cover what the PCI Council says about this. While they don't specifically state that it is or is not an independence issue, if you look at Requirement 11.4 of PCI DSS v4.0, it talks about penetration testing services methodologies. The two main criteria that you have to have as a penetration tester to meet that requirement are:

  • You have organizational independence, which means that the individual performing the test cannot be ultimately responsible for securing that system.
    • (It goes on to say that organizational independence doesn't mean it has to be an ASV or approved scanning vendor or even a QSA, but so long that that individual doesn't have control over the systems they're testing, it's fine. So, if you have an internal resource that's qualified, you can move forward with them.) 
  • The organization or the individual conducting the penetration test must be qualified to do so.
    •  Schellman's penetration testing team, with many of its members holding multiple certifications is, in fact, qualified to do so.
So, from the Council's perspective, it's perfectly fine to have your QSA company performing both the pen test as well as the QSA services for the PCI assessment so long as they meet those two criteria.

At Schellman, we go a little bit further to make sure we don't have independence issues. Our payment security team—which is ultimately comprised of PCI QSAs—and penetration test teams are separate, and they each have different management structures.

We do that really for a couple of different reasonsprimarily because a QSA and a penetration tester have very different skill sets, but also so there's no perceived bias for a QSA who's also doing penetration testing services for the same client.

Now that we've covered why Schellman can do both your pen testing as well as PCI assessments, feel free to reach out to us if you are using us for one of the services but not the other, or if you're looking for a new QSA company or a penetration tester.