PCI PTS post-compliance testing is how payment service providers (PSPs) and payment device manufacturers ensure that a device is safe long after The PIN pad, POS terminal, or hardware security module passed a PCI Recognized Laboratory’s review of its firmware architecture, its resistance to physical tampering, and its handling of PINs and keys. That PTS approval is a snapshot. It’s tested against the threats known at the time of evaluation, and it’s typically valid for three years. The device itself often stays in use far longer than that snapshot is valid. In fact we can consider devices to be a static target, they sit for years often processing transactions at thousands of locations while attackers keep working on new techniques. PCI PTS post-compliance testing, as delivered by specialist companies like PCA Cyber Security, is how manufacturers and PSPs, ensure true cybersecurity resilience. What is PCI PTS Post-Compliance Testing? Post-compliance testing is testing of a PTS approved device after it is certified and (often) after it is already deployed. Only a handful companies (like PCA cybersecurity) have the skills and experience to perform this kind which can involve everything from network pen testing to firm engineering – real threats that devices face in the wild. Here’s how post and pre compliance testing differ. - Pre-compliance testing catches problems before a device goes in front of a lab, - post-compliance testing is ongoing payment device testing performed throughout the device’s working life, not a one-time check. We can see the use case for this testing in three steps: - a) Find vulnerabilities that emerge after certification, whether from new attack techniques, firmware updates, or components that were never in scope of the original PTS evaluation - b) Confirm that patches and updates applied after launch haven’t introduced new weaknesses - c) Validate
Post-Compliance Testing for PCI PTS Explained
Read the original article
europeanbusinessreview.com →