The PCI Security Standards Council has released guidance (PDF) to businesses to show them how to use penetration testing to identify network vulnerabilities that could be exploited for malicious activity. [tbusinessnet.com, bankinfosecurity.com, news.google.com]
There is also a discussion thread over on SANS.org Forums.

Leave a comment