Home > Ask the Security Experts > Security Management Questions & Answers > What is the best way to comply with PCI DSS requirements 9 and 10?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What is the best way to comply with PCI DSS requirements 9 and 10?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 09 October 2007
Our organization is attempting to deal with requirements 9 and 10 of the Payment Card Industry (PCI) Data Security Standard. Here are a couple questions we have:
  • To satisfy requirement 9.1.1, would a camera outside of the server room that shows everyone who enters the room (with a date/time stamp) be sufficient, or does the camera need to be fixed on the rack containing the specific servers affected by PCI?
  • To satisfy requirements 9 and 10, do server racks need to be equipped with auditable pin or password-based locks?

  • >
    EXPERT RESPONSE
    Before I delve into specifics, I'll relay what I heard from a few PCI auditors to whom I posed these questions. Their answer was a universal "it depends."

    That is the problem with trying to answer a fairly generic question about the PCI DSS. Every auditor has his or her own interpretation of the requirements and, in turn, what suffices for compliance. Thus, I can't answer the question with any level of precision without actually seeing the specific server rooms and understanding the other physical defenses that are in place to protect the servers.

    To be clear, requirement 9 of PCI requires "appropriate facility entry controls to limit and monitor physical access to systems that store, process, or transmit cardholder data." The most important word in that statement is "appropriate" because that is where all the wiggle room is. What's appropriate tends to be in the eyes of the beholder.

    In my opinion, having a camera outside of the server room, which records with an unalterable time stamp who enters and exits the room, and then having sufficiently detailed log records pertaining to changes made on the servers and cardholder data access is enough. But again, that is my opinion.

    It's not really practical to try to put a camera on servers that "fall under PCI." With virtualization continuing to proliferate in data centers around the world, an organization can't really be specific anymore relative to what server is doing which tasks. The applications and data that run on a specific physical enclosure can -- and will -- change frequently.

    That's why requirements 9 and 10 need to be handled with close coordination. You need to be able to pull log records of server changes and data access. Correlating the log files with physical access and video information can provide a pretty good idea about who did what and when.

    Relative to the PIN and/or password-based locks, again the answer depends on each organization's unique situation. Personally, that seems like overkill to me. If I have the servers in a physically secure location and I'm monitoring access to the server room and taking log data from any activity on those servers and the applications that run on the servers, it seems that auditable locks wouldn't add much in terms of meeting PCI requirements.

    If I were your auditor, that would be my position. But I'm not, so do what you can and be able to defend your decisions -- whether that's deploying cameras, locks, or any other controls meant to specifically comply with PCI.

    For more information:

  • In this tip, John Kindervag dispels the five biggest misunderstandings about PCI DSS.
  • Learn what to do if your corporation has missed the PCI DSS deadline.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Security Management
    Is it against HIPAA regulations to permanently store sensitive information?
    Two-tier distributed systems vs. three-tier distributed systems
    How to prevent software piracy
    How do ISO 17799 and SAS 70 differ?
    Has FFIEC made any VoIP-specific mandates?
    What is the best way to administer exams to students via computer?
    Should computer exams be transmitted as PDF files or Word files?
    Is it against HIPAA regulations to display client names?
    Getting started on a career in penetration testing
    Are there security management products that can track compliance objectives?

    PCI Data Security Standard
    PCI Requirement 6.6 has merchants gearing up
    PCI compliance extends to car washes, quick lubes
    PCI council to launch assessor quality assurance program
    The 'security standards dilemma': Network segmentation and PCI Compliance
    NSS Labs to focus research on PCI technologies
    PCI Confusion
    Trio indicted in restaurant data security breach
    PCI portal aims compliance guidance at smaller merchants
    PCI compliance and Web applications: Code review or firewalls?
    How to test the security of personal details submitted to a website

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    PCI DSS (Payment Card Industry Data Security Standard )  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts