Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

nCircle Automates Quarterly PCI Scan

nCircle announced the nCircle Certified PCI Scan Service version 2.0

SAN FRANCISCO, Calif. -- nCircle, the leading provider of agentless security risk and compliance management solutions, today announced the nCircle Certified PCI Scan Service version 2.0. This version extends the scan service to include automated preparation of the Self-Assessment Questionnaire as well as online submission of the certified quarterly PCI reports for automated retrieval by acquiring financial institutions. The addition of these capabilities to the scan service simplifies compliance administration and enables merchants and service providers of all sizes to demonstrate PCI compliance easily and cost-effectively.

The nCircle Certified PCI Scan Service version 2.0 now includes an online version of the Self-Assessment Questionnaire (SAQ), a required validation tool developed by the PCI Security Standards Council for merchants and service providers to demonstrate PCI compliance. Users can complete the questionnaire online and revisit the document as often as required to ensure accuracy before submitting it for review. In addition, this version also automates the process of filing the SAQ and quarterly PCI reports at the completion of a network scan, through an online portal. The service then automatically notifies the acquiring financial institution when reports are available for secure, convenient retrieval.

These new capabilities, when combined with automated network scanning and a streamlined vulnerability remediation process, simplify administration while reducing the operational costs associated with demonstrating quarterly PCI compliance. In addition to benefiting merchants and service providers, the new version also benefits acquiring financial institutions by enabling them to regularly monitor the compliance status of their merchants.

Additional highlights of the new version include the addition of Common Vulnerability Scoring System (CVSS) base scores as indicated in the National Vulnerability Database to the auto-generated PCI reports. CVSS is an industry standard established to commonly assess the severity of a vulnerability to help prioritize the urgency of response to address it. It solves the problem of multiple, vendor-specific scoring systems and simplifies tracking PCI compliance for merchants, service providers and acquiring financial institutions. The PCI Data Security Standard (DSS) v1.1 requires that as of June 30th, 2007, all Approved Scanning Vendors must be able to deliver certified PCI reports that include CVSS scores.

"The nCircle Certified PCI Scan Service was among the first to pass rigorous testing to become a certified Approved Scan Vendor under the enhanced version 1.1 of the PCI Data Security Standard," said Stefan Petry, Vice President of Product Management, nCircle. "We continue to expand our vision for the service by being among the first to deliver the most advanced, yet simple, and up to date PCI compliance tools in the industry."

nCircle

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11498
PUBLISHED: 2020-04-02
Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to execute arbitrary code in the user's own context, e.g., for user-level persistenc...
CVE-2020-11499
PUBLISHED: 2020-04-02
Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request, as demonstrated by mishandling of the tags and version fields in helperFunctions/mongo_task_conversion.py.
CVE-2020-7628
PUBLISHED: 2020-04-02
install-package through 1.1.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the device function.
CVE-2020-7629
PUBLISHED: 2020-04-02
install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
CVE-2020-7630
PUBLISHED: 2020-04-02
git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.