Conducting a pentest
To comply with PCI DSS, it is necessary:
To conduct a penetration test according to the requirements of sections 11.4.2-11.4.3, 11.4.6 of the PCI DSS 4.0.1 standard.
Report on internal and external penetration tests
Report on penetration tests for segmentation control
-
98 Good day!
I have certification and significant experience in conducting penetration tests for PCI DSS compliance. I perform the full cycle of work according to the requirements of the PCI DSS 4.0.1 standard (sections 11.4.2-11.4.3, 11.4.6).
Scope of work:
1. Internal penetration test
- Testing from the internal network level
- Checking CDE systems and adjacent segments
… - Identifying vulnerabilities in the internal infrastructure
- Detailed report with all identified issues, CVSS ratings, and recommendations
2. External penetration test
- Testing external entry points (web applications, APIs, VPN)
- Checking external interfaces from the internet
- OWASP Top 10 testing
- Report with Proof of Concept and step-by-step reproduction instructions
3. Penetration test for segmentation control
- Validation of network segmentation effectiveness
- Checking isolation of CDE from non-CDE segments
- Testing firewalls and network ACLs
- Architecture diagram and report on segmentation status
Methodology:
- Use of standardized methodologies (OWASP, PTES, NIST)
- Detailed documentation of all identified vulnerabilities
- Risk assessment considering impact on CDE
- Specific recommendations with remediation priorities
Result:
- 3 complete reports according to PCI DSS requirements
- Executive Summary for management
- Detailed technical documentation for the IT department
- Remediation plan with timelines and priorities
- Consultation during vulnerability remediation
I guarantee quality execution, full compliance with PCI DSS requirements, and support during the audit.
-
981 6 3 Good hour, I can do this, please provide a more detailed specification in private messages, I hope for cooperation.
-
Здравствуйте. А что физически из себя представляет то что надо проверять?
-
Current freelance projects in the category DevOps
Setting up a backup system and optimizing server infrastructureObjective of the work: Ensure reliable data storage for the CRM system and application by implementing an automated backup system, as well as carry out a series of server improvements to enhance the stability, security, and performance of the infrastructure. DevOps, Databases & SQL ∙ 2 days 13 hours back ∙ 23 proposals |
Deployment of a Ruby on Rails project on VPS + Inbound Email RoutingNeed help deploying a platform for automating requests for public information (based on the open-source engine Alaveteli). The project works as a mail router: it generates unique email addresses for each request, sends them to government agencies, and receives responses back to… DevOps, Linux & Unix ∙ 8 days 15 hours back ∙ 11 proposals |
Residential Proxy Infrastructure EngineerWe're building a residential proxy network from scratch — fully owned, no third-party suppliers. We need one exceptional network engineer to build the entire technical foundation. What you'll build: - Android background SDK that routes proxy traffic through user devices… C & C++, DevOps ∙ 10 days 17 hours back ∙ 15 proposals |