Home > Video guide: PCI DSS and the 12 Requirements
PCI Compliance Essentials:
EMAIL THIS

Video guide: PCI DSS and the 12 Requirements

03 Jun 2009 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Diana Kelley and Ed Moyle, co-founders of the consultancy Security Curve, know a thing or two about compliance with the Payment Card Industry Data Security Standard. In this series of instructional videos, Ed and Diana step through each of the 12 PCI compliance requirements, review common questions that they hear when doing assessments, then finally address possible compensating controls that can be used if you cannot meet a given requirement.

Use the links below to jump directly to information on specific PCI compliance requirements:
  • Requirement 1: Firewalls
  • Requirement 2: Defaults
  • Requirement 3: Protect data
  • Requirement 4: Encrypt transmissions
  • Requirement 5: Antivirus
  • Requirement 6: Systems and applications
  • Requirement 7: Restrict access
  • Requirement 8: Unique IDs
  • Requirement 9: Physical access
  • Requirement 10: Auditing
  • Requirement 11: Testing
  • Requirement 12: Policy
  • PCI REQUIREMENT 1: FIREWALLS  

    The requirement calls for "stateful inspection" devices separating the Internet from the cardholder environment. Documentatation is also necessary to ilustrate how the firewalls are deployed and maintained. But do you need a firewall for every store? And what about the use of routers?

    Watch the Requirement 1 video


    PCI REQUIREMENT 2: DEFAULTS  

    To meet PCI Requirement 2, you'll need to learn how to document a secure configuration by removing vendor-enabled passwords and unnecessary services. Security features like encryption for administrative connections will also need to be enabled. Diana Kelley and Ed Moyle review common questions and gotchas, including what to do with hosting providers.

    Watch the Requirement 2 video


    PCI REQUIREMENT 3: PROTECT DATA  

    Simple enough, right? Not necessarily, especially with the infamous sub-requirement 3.4, which explains how to protect stored permanent account numbers. In this section, learn when to use encryption on cardholder data and when to store sensitive authentication data.

    Watch the Requirement 3 video



    PCI REQUIREMENT 4: ENCRYPT TRANSMISSIONS  

    When your permanent account numbers are travelling over the Internet or other public network, that data needs to be encrypted. But what about WEP? Diana Kelley explains why it's usually easier to rely on TLS or IPsec.

    Watch the Requirement 4 video



    PCI REQUIREMENT 5: ANTIVIRUS  

    You probably have this requirement taken care of. It's certainly important to scan for malware and viruses (and don't forget about spyware, too!). But what about antivirus for UNIX and mainframes? What about HIPS or POS systems? In this section, the PCI duo explain what kinds of tools and technologies will help you pass Requirement 5.

    Watch the Requirement 5 video


    PCI REQUIREMENT 6: SYSTEMS AND APPLICATIONS  

    What does it mean exactly to "develop and maintain secure systems and applications?" Make sure that you're developing and testing applications using secure coding techniques. It's also critical to have processes to make sure that systems are secure against vulnerabilities. Also, external Web applications now require external code review OR an application firewall. But which is best?

    Watch the Requirement 6 video


    PCI REQUIREMENT 7: RESTRICT ACCESS  

    This requirement is actually fairly intuitive. The important task is to have documented processes and policies in place that can prove that you've limited who has access to cardholder data. But do you need an automated access control system? Ed Moyle and Diana Kelley point out the main reason why organizations may not meet Requirement 7.

    Watch the Requirement 7 video


    PCI REQUIREMENT 8: UNIQUE IDs  

    In a nutshell, Requirement 8 calls for individual identification for anyone and everyone who has access to cardholder data. In this section, the PCI experts review a common challenge: two-factor authentication for administration.

    Watch the Requirement 8 video


    PCI REQUIREMENT 9: PHYSICAL ACCESS  

    For Requirement 9, basic physical controls are required for the facilities that process cardholder data. Does that mean cameras are required? Are retail locations exempt? Ed Moyle and Diana Kelley review common pitfalls, esepcially when comany cultures are resistant to badges.

    Watch the Requirement 9 video



    PCI REQUIREMENT 10: AUDITING  

    Don't panic. Although the requirement calls for the tracking and monitoring of all access to network resources and card holder data, the main objective is to maintain system logs and have procedures that use and retain them. So does that mean you have to review the logs every day? Or do you need to use a log aggregator or correlation engine? Find out.

    Watch the Requirement 10 video


    PCI REQUIREMENT 11:TESTING  

    PCI Requirement 11 is a popular one, according to Diana Kelley. According to this part of the standard you must conduct quarterly wireless and external scans, as well as annual penetration tests. Diana Kelley explains whether or not file integrity monitoring or Tripwire will help you meet Requirement 11. Also: do you know what happens if you miss a required test?

    Watch the Requirement 11 video


    PCI REQUIREMENT 12: POLICY  

    Last but not least, it's important that you author and maintain a body of policy documentation of how you will address the Data Security Standard requirements. One common question that seems to appear when maintaining a policy that addresses information security: How should new hires be screened? You may have a lot of documentation already, but there's a good chance that you don't have all that you need.

    Watch the Requirement 12 video



    Diana Kelley is a partner with Amherst, N.H.-based consulting firm SecurityCurve. She formerly served as vice president and service director with research firm Burton Group. She has extensive experience creating secure network architectures and business solutions for large corporations and delivering strategic, competitive knowledge to security software vendors.

    Ed Moyle is currently a manager with CTG's information security solutions practice, providing strategy, consulting and solutions to clients worldwide, as well as a founding partner of Security Curve. Ed was previously Vice President and Information Security Officer for Merrill Lynch Investment Managers (MLIM,) where he was responsible for coordinating all aspects of information security within the business unit. Ed is co-author of "Cryptographic Libraries for Developers", and a frequent contributor to the Information Security industry as author, public speaker, and analyst.



    BROWSE BY TAG
    Security Audit, Compliance and Standards,   PCI Data Security Standard,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    PCI Data Security Standard
    Chip and PIN adoption
    Chip and PIN adoption serves lesson for U.S. payment industry
    Heartland CIO is critical of First Data's credit card tokenization plan
    Heartland CIO on end-to-end encryption, credit card tokenization
    Heartland CIO on PCI, E3 project
    Wireless network guidelines for PCI DSS compliance
    Visa probes tokens, encryption for PCI card data protection
    Feds push cybersecurity jobs, PCI DSS changes ahead.
    Voltage, RSA spar over tokenization, data protection
    Experts, vendors search for PCI's holy grail

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    PCI DSS (Payment Card Industry Data Security Standard )  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary




    Search Additional Security Research and Solutions
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts