3 ms·
The StackExchange post shows some back-and-forth conversation along these lines. The auditor doesn't budge an inch, and gets defensive.
by strommen 10y ago
The StackExchange post shows some back-and-forth conversation along these lines. The auditor doesn't budge an inch, and gets defensive.
- dbg31415 10y agoThere are other service providers. Sorry I didn't read the comments in the StackExchange post. There are other vendors. I think that'd be my next step -- go to my legal team or C-team, explain that answering these questions would put the company in danger, and suggest we consult with another vendor from the approved PCI list. (Sorry I don't know if this is actually the list to go off of -- scans vs. audits, just my point is that there are public lists of approved companies to choose from.) * https://www.pcisecuritystandards.org/assessors_and_solutions/approved_scanning_vendors https://www.pcisecuritystandards.org/assessors_and_solutions... I had a client who just had some random dude telling them he could certify them as PCI Compliant... he was in no way authorized to do that. Was fairly hilarious how it played out; he'd been "certifying them" for years and even went so far as to give them a graphic they could display on their website. There are people who pray on ignorant businesses, but with a little research it's not terribly hard to educate yourself on what's real and what's BS. EDIT: Just read the StackExchange post... Yeah, run. Guy is a nut job, like the random dude who had been advising one of my old clients. That call with him -- around how he wasn't really someone who could certify PCI Compliance -- was one of my favorite calls ever. He basically melted into a rant about, "I know good security, I have never had any of my servers hacked... well only like 2 but those weren't my fault!" Then said he'd get off the phone to do some research... and never called again, didn't even bother sending my client a bill for his services. Wish I had recorded it. BUT... just because there are nut jobs out there, doesn't mean this is something companies should ignore. PCI Compliance is important.