Scanning for wireless rogue threats….requirements clarified

  • Team Omega
  • November 12, 2012

PCI DSS have updated the requirements as of June 30th of 2012. Now, there are 3 types of required scanning.  

  1. Internal Vulnerability
  2. External IP
  3. Wireless Rogue threat 

Here’s are some tips on the wireless scanning you’d want to pay attention to:

  • Make sure your detection in place is capturing the Mac address of the rogue device as many think their firewall solution covers it
  • Make sure the rogue device Mac addresses are compared to a known list of acceptable addresses 
  • Make sure you have an Incident Response Plan in the event an unauthorized wireless device is detected 

