Home > Security Tips > Risk Management Strategies > Guide to passing PCI's five toughest requirements
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

RISK MANAGEMENT STRATEGIES

Guide to passing PCI's five toughest requirements


Craig Norris
09.19.2007
Rating: -5.00- (out of 5)


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


It is well known by now that the major credit card companies have collectively mandated that all members, merchants and service providers storing, processing or transmitting cardholder data must adhere to the Payment Card Industry (PCI)'s "12 commandments" -- the dozen overarching best practices that make up the guideline -- or else risk possible fines and even the termination of credit card processing privileges. In addition, by Sept. 30, 2007, all Level 2 organizations -- merchants processing more than 150,000 Visa or MasterCard transactions each year or merchants that process more than 1 million transactions annually -- must be compliant with these standards. Unfortunately, the path to PCI DSS compliance can be demanding due to the amount of money, time and effort required.

This learning guide will review a few of the more challenging PCI DSS requirements and provide some tips that enterprises can use to achieve PCI DSS compliance.

Review the PCI DSS requirements

For more on the 12 basic requirements of the PCI Data Security Standard, check out our exclusive webcast, PCI Compliance: Best Practices and Common Misconceptions with guest speaker Roger Nebel.
PCI DSS: Where are organizations struggling?
All of the PCI DSS requirements seem to be fairly well defined, unlike those of the Sarbanes-Oxley Act. SOX does not provide any specific direction on how to secure information assets and has been open to varying interpretations by companies and compliance audit firms. Nevertheless, organizations still find it difficult to become PCI DSS compliant. In an interesting study conducted by VeriSign Inc., researchers found that organizations were most likely to be noncompliant with PCI Requirement 3. Seventy-nine percent of the failed assessments did not meet the requirement to protect stored data. According to VeriSign, the top five PCI assessment failings were:

Requirement 3: Protect stored data 79%
Requirement 11: Regularly test security systems and processes 74%
Requirement 8: Assign a unique ID to each person with computer access 71%
Requirement 10: Track/monitor network resources and cardholder data 71%
Requirement 1: Install and maintain a firewall configuration to protect data 66%

The Slaughterhouse-Five: Why are these problem areas?
Regardless of the fact that PCI DSS is definitely comprehensive, the list of requirements allows for 12 potential points of failure; the inability to pass any one means an organization won't be compliant. Additionally, even with the PCI DSS providing specific requirements, it can be interpreted differently by different types of organizations. Let's review the aforementioned PCI requirement failures, analyze why these might cause trouble for some organizations and discuss what measures can be taken to resolve the dilemma.


A GUIDE TO PASSING PCI'S FIVE TOUGHEST REQUIREMENTS

  Requirement 3: Protecting stored data
  Requirement 11: Regularly test security systems and processes
  Requirement 8: Assign a unique ID to users
  Requirement 10: Monitor access to network resources and data
  Requirement 1: Install and maintain a firewall configuration
  Conclusion

ABOUT THE AUTHOR:
Craig Norris, CISSP, CISA, G7799, MCSE, Security+, CAPM, TICSA, is a Regional Engagement Manager at an IT consulting firm in Dallas. He has been involved with information technology and security for over 12 years. He can be contacted via canvip@yahoo.com.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Risk Management Strategies
Easing e-discovery preparation by mapping enterprise data
Database patch denial: How 'critical' are Oracle's CPUs?
Security breach management: Planning and preparation
The ins and outs of database encryption
Failure mode and effects analysis: Process and system risk assessment
Data loss prevention (DLP) tools: The new way to prevent identity theft?
IT GRC: Combining disciplines for better enterprise security
Partner access: Balancing security and availability
Enterprise data management: Analyzing business processes and infrastructure for data protection
Filtering log data: Looking for the needle in the haystack

PCI Data Security Standard
Compliance recycling: Combining compliance efforts to manage PCI DSS
PCI Requirement 6.6 has merchants gearing up
PCI compliance extends to car washes, quick lubes
PCI council to launch assessor quality assurance program
The 'security standards dilemma': Network segmentation and PCI Compliance
NSS Labs to focus research on PCI technologies
PCI Confusion
Trio indicted in restaurant data security breach
PCI portal aims compliance guidance at smaller merchants
PCI compliance and Web applications: Code review or firewalls?

Security Audit
Architect Security and Compliance Programs to Be Complementary
The road to compliance
Hannaford breach illustrates dangerous compliance mentality
Data breach costs soar
IBM to boost security spending, push PCI DSS program
Filtering log data: Looking for the needle in the haystack
Preparing for a network security audit starts with monitoring and remediation
Code Green pitches data protection for SMBs
Dissecting compliance workflow processes
Report: Companies still stumped by PCI DSS

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
PCI DSS (Payment Card Industry Data Security Standard )  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts