
- What is the difference between a Vulnerability Assessment (VA) and a Penetration Test, or is there?
- We just installed a new Firewall and IDS/IPS. Now that this equipment is installed we are pretty secure, right?
- We don't fall under any compliance regulation or standard, and our security was tested when we first installed it. Do we need to keep testing it?
- Our organization really does not have anything to get the attention of a hacker. Could we still be a potential target?
- We've never been hacked before, why worry about it now?
- We do regular testing in-house, why use an outside source?
- I know security should be a high priority, but we have a small IT staff with a limited budget.
- What is a baseline, and how do we get one?
- Is there a way to test new servers before we put them into production?


Payment Card Industry (PCI) Data Security Standard applies to any company that accepts, stores or processes credit cards, which is pretty much anyone in business. Our ASAP Standard and Enterprise versions are designed to address the PCI DSS section 11.3 penetration test requirement. For more information about the PCI standard, and what the requirements are, click on the link below to learn more.