Compliance Readiness
Review externally visible website security controls that may be relevant to PCI DSS security requirements.
Websites involved in payment environments may need to meet security requirements established by the Payment Card Industry Data Security Standard (PCI DSS).
WebInspect examines a selection of externally observable website and domain security controls and identifies findings that may be relevant when reviewing your PCI DSS security posture.
This is a readiness assessment and does not certify PCI DSS compliance.
PCI DSS stands for Payment Card Industry Data Security Standard.
It establishes technical and operational security requirements intended to protect payment account data and the systems involved in processing, storing or transmitting it.
The requirements cover many areas of security, including network security, secure configuration, access control, vulnerability management, encryption, monitoring and security testing.
Because PCI DSS applies to more than the public-facing configuration of a website, no simple external website check can determine complete PCI DSS compliance.
Although many PCI DSS requirements require access to internal systems, processes and documentation, some externally visible technical controls can still provide useful security readiness information.
WebInspect can examine areas such as:
WebInspect checks whether HTTPS is available and reviews externally observable TLS configuration.
Secure transmission is particularly important wherever sensitive information could be transmitted over public networks.
Older encryption protocols can present unnecessary security risks.
WebInspect can identify supported TLS versions and highlight obsolete protocol support detected during the inspection.
Certificate validity and expiration are checked to help identify problems with the public HTTPS configuration.
Browser security controls such as HSTS, Content Security Policy and other HTTP response headers can provide additional layers of protection for web applications.
WebInspect reviews these headers and identifies missing or potentially relevant controls.
Publicly accessible configuration files, development artifacts or other unnecessary information exposure can provide useful information to an attacker.
WebInspect includes checks intended to identify certain externally observable exposure indicators.
The inspection can also review domain-level information and email authentication controls such as SPF and DMARC.
These controls do not establish PCI DSS compliance but contribute to understanding the wider external security posture of the domain.
This distinction is important.
WebInspect performs an unauthenticated external inspection. It cannot see internal network architecture, stored cardholder data, user access controls, source code, administrative processes, logging systems or many of the other controls that may fall within PCI DSS scope.
A WebInspect PCI DSS readiness result therefore does not mean that an organization is PCI DSS compliant.
Likewise, a failed readiness check does not automatically establish a PCI DSS violation.
The purpose is to highlight externally observable security findings that may deserve attention when preparing for or maintaining a secure environment.
Security assessments are easier when obvious configuration problems are discovered before a formal review.
An external readiness inspection can help identify areas worth investigating, including outdated TLS support, missing HTTPS protections or publicly exposed configuration information.
Correcting appropriate findings early can improve the overall security posture and make subsequent reviews more productive.
Using a third-party payment provider can significantly change an organization's PCI DSS scope, but it does not automatically mean that the organization's website has no security responsibilities.
The applicable requirements depend on the payment architecture, how customers are redirected or embedded into payment services, and the organization's particular PCI DSS responsibilities.
Organizations should determine their actual PCI DSS scope with their payment provider, acquiring bank or qualified PCI professional where appropriate.
PCI DSS should not be treated purely as a collection of technical tests.
Effective security also depends on maintaining systems, controlling access, managing vulnerabilities, monitoring environments and following appropriate operational procedures.
WebInspect focuses on the portion it can responsibly observe from outside your environment.
Run a WebInspect inspection to identify externally visible security controls and findings that may be relevant to your website's PCI DSS security posture.