| Home > Security News > Tough questions on PCI DSS: Private networks, self-assessment and segmentation | |
| Security News: |
|
||
How does PCI apply to merchants whose card transactions are conducted via telephone card readers?
Given the limited scope of the cardholder environment in that case, the number of controls that an enterprise will have to address is also much smaller than might otherwise be the case. For example, controls about network segregation, malware prevention, and so on are likely to be largely inapplicable. If you have any questions about the scope of the cardholder environment, don't forget that an organization's QSA or acquirer can offer guidance on setting the appropriate scope.
Does PCI compliance require that data transmissions over private networks be encrypted? There are a few possible "snags" here that should be taken into account. Be aware of stored records that could contain sensitive authentication data or the PAN. While this type of data doesn't need to be encrypted during transmission, there are different requirements if that data is stored. If the data is being sent across the network, make sure that there aren't devices that could keep this type of data in transaction logs. If our retail organization stores only the last four digits of credit cards at our stores, do we need security measures such as cameras, unique login IDs, etc., to be PCI compliant?
Yes, most likely. Keep in mind that whether the data is stored isn't the only factor. The determination of whether companies need to comply is made based on whether they "store, process or transmit" card information. If card information is being processed or transmitted – even if none of it is stored – that organization still needs to comply. If a corporation needs to comply, it must address all the areas of the standard for the scope of the cardholder environment; this includes all the physical security requirements (e.g. cameras) as well as the technical requirements (IDs). If our retail organization stores only the last four digits of credit cards at our stores, do we need security measures such as cameras, unique login IDs, etc., to be PCI compliant? Is a private network over a public domain between two datacenters PCI compliant? A new version of the PCI self-assessment questionnaire was recently released, and some of the questions specifically mention that the scope is the cardholder data environment, while others do not. For example, question 1.3.9 specifically asks about personal firewall software on any mobile and employee-owned computers with direct access to the Internet that are used to access the organization's network. In this instance, it's not clear if the organization's network is the entire network or just the cardholder data scoped network. How do you treat these types of questions as a QSA? Do you typically limit the scope to the cardholder data environment?
That being said, I hear where you're coming from on 1.3.9. I interpret the scope of this (and some of the other requirements that look like they have universal applicability) in light of the scoping guidance given by the standards council in the audit procedures (it is page five of the "PCI Audit Procedures 1.1.") In there, they're pretty clear that the scope of compliance validation only applies to the cardholder environment, and that segregation of other systems limits the scope provided the segregation is properly applied. Our organization, which is based in Canada, is implementing a mobile POS system. What kind of PCI certification or validation do we need?
Now, if you are authoring the product, my advice to you would be to take a serious look at the PA-DSS (formerly known as the "Payment Application Best Practices" or PABP). In this case, adhering to the requirements and ensuring that your product is ready for compliance to support your clients. Can you clarify the types of data that PCI is intended to cover? Exactly what data must be protected? Does the standard cover personal information like names, addressees, phone numbers, etc., that are not associated with actual card numbers? Our network is not segmented, but the cardholder data environment is separated from the rest of the environment by a firewall. What is the network scope?
If there are questions about whether your particular situation is sufficient to reduce scope, a good guide to answer questions about scoping is on page five of the PCI auditing requirements, which is available on the PCI Security Standards Council website, as well as your QSA and/or acquirer.
For more information: When did the internal audit team option for self-assessment become a viable alternative to a third-party assessment?
As far as the history, the self-assessment provision for Level 1 merchants has been in place since "the beginning" (PCI version 1.0), but it's not all that common in practice. It is provided to give the largest merchants an option for assessment in the event that the scope of the assessment would be prohibitively expensive to the organization. This was a concern among the largest merchants when the standard was introduced. Remember too that the acquirer has to agree; if an organization intends to do this, it should make sure it meets the requirements and gets buy-in from its acquirer. Could you provide detail on how the Verified by Visa program works? Is verification confirmed through tests, auditors, or related means?
The way that Verified by Visa typically works is that a secure channel with the "issuing member" (card issuer) is established between the cardholder's PC and the issuer during the checkout process. This allows the issuer to implement robust authentication of the cardholder prior to allowing the transaction to proceed. For example, the issuer could require that the cardholder authenticate with a biometric or certificate. It could also implement a robust password. All of this can be done in a manner that's relatively non-intrusive to the checkout process. While there are security benefits to using VbV, use of this technology is not required for compliance with PCI.
'); // -->
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||
|
||||||||||