Skip to content

Should we include intrusion testing as part of the scope of our third party review?

Question: 
We obtain our internet service through our off site bank core processor. Should we include intrusion testing as part of the scope of our third party review?
Answer: 

Performing an intrusion test against your third party processor's equipment is a valid component in periodic network security monitoring. The goal is to assure that their deployed configuration fully meets your written policy. Their policy is immaterial but their configuration controls compliance with your policy.

First published on 10/16/2006

Filed under: 

Search Topics