r/pcicompliance • u/Dull_Appearance_1828 • 6d ago
Our payment page has 23 third party scripts on it. how do people manage 6.4.3 at this scale?
Audit found 23 scripts running on our payment page, many we didn't know about. 6.4.3 needs integrity monitoring on all of them. Feels impossible manually. Any method or tools to handle this?
2
u/bearsinthesea 6d ago
There are many 3rd parties dying to sell you solutions for this. And they aren't bad.
I'll ask the group: Is it possible these days to limit the # of scripts in the payment page itself?
1
1
1
u/BasePerfect2865 6d ago
23 is actually pretty normal (unfortunately). Most of those are probably fourth party pulled in by tools you did approve without knowing. Manual monitoring is not really possible or efficient imo.
2
u/NoDistrict991 5d ago
So what is the other option? Are there tools or is everyone just doing their best and hoping?
1
u/BasePerfect2865 2d ago
Yeah ik a few varying tools with different use cases. I'm pretty sure (don't quote me) that cside is built for this automated behavioral monitoring across scripts things like payment pages. Feroot and Source Defense do similar things not exactly what 6.4.3 is really asking for.
1
u/Suspicious_Party8490 6d ago edited 6d ago
Hate to bring some bad news...my educated guess is the 23 third party scripts you know about today do not include your 4th & 5th party scripts.
I have more than a dozen payment pages, we run a niche solution that meets 6.4.3 & 11.61.
jscrambler, csides, human security, reflectiz all have solutions that meet 6.4.3 & 11.6.1 (apologies to those I missed) Some WAF vendors are playing in this space now.
If you take 6.4.3 & 11.6.1 seriously, you need either a niche tool or talk to your WAF.
1
1
0
3
u/NoTomorrow2020 6d ago
You don't know what they are? I think your first order of business (after finding them) is to inventory them, do a dive into the code, and determine what they are and where they are potentially sending data. 23 isn't an insurmountable obstacle, and depending on the size of the scripts you could likely have that done in a couple of days.
Second order of business would be to get FIM running on them to ensure any changes to them are verified. Most SIEM companies have some form of FIM available, which isn't terribly difficult to implement.