How does a customer get PCI audited?



I have a client (same one from a previous post) who has some pretty
serious security issues on their network (unsecured .mdb file with
credit card into, etc). I will be fixing the major security holes in
their network, but they still have PCI compliance issues, and I'm
assuming they need to have a quarterly scan done.

They've had this setup for about a year, they knows nothing about PCI
and compliance (myself included, I am not a QSA and still learning about
the compliance procedure).

What are the chances of them getting audited? How does all that work?
Could they potentially fly under the radar for years? I thought there
was something they had to report quarterly to show they're working on
compliance, or something.

I want to be able to tell they company "Listen, here's what could happen
if you get audited, and here's the chances of you getting audited" in
hopes they would take it seriously. I don't want to scare them without
knowing the facts, first I want to know the facts, then I will scare
them. Thanks.
Scott Race
Technology Manager

JD+A NETWORK SERVICES
1264 Hawks Flight Court, Suite 200

El Dorado Hills, CA 95762
P: 916.941.3700 | F: 916.941.3777




Relevant Pages

  • Re: How does a customer get PCI audited?
    ... When your customer is trying to become PCI compliant, make sure that they are tested by a QUALIFIED security company. ... It is very easy to be PCI compliant when you are checked by an automated scanner, but in such cases being compliant means nothing because you're probably still hackable. ... their network, but they still have PCI compliance issues, and I'm ... knowing the facts, first I want to know the facts, then I will scare ...
    (Security-Basics)
  • SecurityFocus Microsoft Newsletter #50
    ... Subject: SecurityFocus Microsoft Newsletter #50 ... Specialist in Microsoft's Security Services Partner Program, ... Network Monitoring for Intrusion Detection ... Relevant URL: ...
    (Focus-Microsoft)
  • << SBS News of the week - Sept 26 >>
    ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: << SBS News of the week - Sept 26 >>
    ... > And he points to the info you need to put the file on the server in the ... > at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... An attacker can exploit these flaws in tandem via specially ...
    (microsoft.public.backoffice.smallbiz2000)
  • << SBS News of the week - Sept 26 >>
    ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
    (microsoft.public.windows.server.sbs)