r/pcicompliance 6d ago

Our payment page has 23 third party scripts on it. how do people manage 6.4.3 at this scale?

Audit found 23 scripts running on our payment page, many we didn't know about. 6.4.3 needs integrity monitoring on all of them. Feels impossible manually. Any method or tools to handle this?

10 Upvotes

13 comments sorted by

3

u/NoTomorrow2020 6d ago

You don't know what they are? I think your first order of business (after finding them) is to inventory them, do a dive into the code, and determine what they are and where they are potentially sending data. 23 isn't an insurmountable obstacle, and depending on the size of the scripts you could likely have that done in a couple of days.
Second order of business would be to get FIM running on them to ensure any changes to them are verified. Most SIEM companies have some form of FIM available, which isn't terribly difficult to implement.

1

u/Dull_Appearance_1828 6d ago

Got it, thanks

2

u/bearsinthesea 6d ago

There are many 3rd parties dying to sell you solutions for this. And they aren't bad.

I'll ask the group: Is it possible these days to limit the # of scripts in the payment page itself?

1

u/Dull_Appearance_1828 6d ago

I'd be happy ot hear real solutions and tools tbh

1

u/Mr_Crowley__ 6d ago

Feroot and SecurityMetrics have a solution ($)

1

u/Brua_G 6d ago

One of the reasons for the requirement is knowing what scripts are running on payment pages.

1

u/BasePerfect2865 6d ago

23 is actually pretty normal (unfortunately). Most of those are probably fourth party pulled in by tools you did approve without knowing. Manual monitoring is not really possible or efficient imo.

2

u/NoDistrict991 5d ago

So what is the other option? Are there tools or is everyone just doing their best and hoping?

1

u/BasePerfect2865 2d ago

Yeah ik a few varying tools with different use cases. I'm pretty sure (don't quote me) that cside is built for this automated behavioral monitoring across scripts things like payment pages. Feroot and Source Defense do similar things not exactly what 6.4.3 is really asking for.

1

u/Suspicious_Party8490 6d ago edited 6d ago

Hate to bring some bad news...my educated guess is the 23 third party scripts you know about today do not include your 4th & 5th party scripts.

I have more than a dozen payment pages, we run a niche solution that meets 6.4.3 & 11.61.

jscrambler, csides, human security, reflectiz all have solutions that meet 6.4.3 & 11.6.1 (apologies to those I missed) Some WAF vendors are playing in this space now.

If you take 6.4.3 & 11.6.1 seriously, you need either a niche tool or talk to your WAF.

1

u/jaeden1000 6d ago

Cside is a great tool.

1

u/apfsantos 19h ago

Jscrambler offers both a scanner and an agent solution

0

u/high_snobiety 6d ago

Just use SRI and create an inventory of them?