Vulnerability Scan Software

Good Morning,

I am required to install a vulnerability scan software for PCI compliance, we are a small business running Lion on some workstations and Mtn Lion on others. In all we have 14 workstations. Can anyone make a suggestion for good basic scan software That we can use on a monthly basis to keep our PCI compliance people happy?

Thanks

iMac, Mac OS X (10.7.5), Some computers running 10.8.3

Posted on Mar 27, 2013 5:36 AM

Reply
4 replies

Mar 27, 2013 5:40 AM in response to southbayveterinary

If you are looking for software to do virus scans, there are no known viruses in the wild for Mac OS X equipment. However, if required to scan, the best software to use is ClamXAV, available for free download from the Mac App Store.


Do not use software from Norton or McAfee for this as their products have been found to do severe damage to the operating system and are extremely difficult to remove.


Also, do not use MacKeeper as it is malware itself and very destructive.

Mar 27, 2013 7:05 AM in response to southbayveterinary

The simplest solution would be something like the Nessus Suite from Tenable Security...assuming you have someone capable of setting up the scan parameters an running them (ie, someone in your organization who understands both your LOB and security).


At the high-end, you can contract other companies to do this for you.


I can't really offer better suggestions, since I have no idea what Merchant Level you are mandated to meet, your externally facing network footprint, and so on.


Now, I do seem to recall that the guidelines from the PCI consortium require quarterly reporting of vulnerabilities scans of externally facing IP addresses. Why do your PCI Compliance "people" want monthly scans of your internal network?


Anyway, a list of PCI Approved Scanning Vendors is here:

https://www.pcisecuritystandards.org/approved_companies_providers/approved_scann ing_vendors.php (Tenable Network Security is on that list, btw. Not that I'm recommending them one way or another; just want to reassure you that my earlier example was a valid one).

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Vulnerability Scan Software

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.