PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance
Book information
Description
Identity theft and other confidential information theft have now topped the charts as the #1 cybercrime. In particular, credit card data is preferred by cybercriminals. Is your payment processing secure and compliant? Now in its second edition, PCI Compliance has been revised to follow the new PCI DSS standard 1.2.1. Also new to this edition: Each chapter has how-to guidance to walk you through implementing concepts, and real-world scenarios to help you relate to the information and better grasp how it impacts your data. This book provides the information that you need to understand the current PCI Data Security standards and how to effectively implement security on the network infrastructure in order to be compliant with the credit card industry guidelines and protect sensitive and personally identifiable information.Completely updated to follow the PCI DSS standard 1.2.1Packed with help to develop and implement an effective security strategy to keep infrastructure compliant and secureBoth authors have broad information security backgrounds, including extensive PCI DSS experience Copyright page......Page 1 Foreword......Page 2 Acknowledgments......Page 4 Authors......Page 6 Foreword Contributor......Page 7 1 About PCI and This Book......Page 8 Who Should Read This Book?......Page 10 Organization of the Book......Page 11 Summary......Page 12 2 Introduction to Fraud, ID Theft, and Regulatory Mandates......Page 15 Summary......Page 20 3 Why Is PCI Here?......Page 21 What Is PCI and Who Must Comply?......Page 22 Electronic Card Payment Ecosystem......Page 23 Goal of PCI DSS......Page 24 Compliance Deadlines......Page 27 Compliance and Validation......Page 29 History of PCI DSS......Page 32 PCI Council......Page 34 QSAs......Page 35 Quick Overview of PCI Requirements......Page 37 Changes to PCI DSS......Page 40 PCI DSS and Risk......Page 41 The Case of the Developing Security Program......Page 43 Summary......Page 45 References......Page 46 4 Building and Maintaining a Secure Network......Page 47 Which PCI DSS Requirements Are in This Domain?......Page 48 Establish Firewall Configuration Standards......Page 49 Denying Traffic from Untrusted Networks and Hosts......Page 50 Restricting Connections......Page 51 The Oddball Requirement 11.4......Page 53 Requirement 2: Defaults and Other Security Parameters......Page 55 Develop Configuration Standards......Page 57 Implement Single Purpose Servers......Page 58 Configure System Security Parameters......Page 59 Encrypt Nonconsole Administrative Access......Page 60 What Else Can You Do to Be Secure?......Page 61 Tools and Best Practices......Page 62 System Defaults......Page 63 The Case of the Small, Flat Store Network......Page 64 The Case of the Large, Flat Corporate Network......Page 65 Summary......Page 67 5 Strong Access Controls......Page 68 Principles of Access Control......Page 69 Requirement 7: How Much Access Should a User Have?......Page 71 Requirement 8: Authentication Basics......Page 72 Windows and PCI Compliance......Page 81 POSIX (UNIX/Linux-like Systems) Access Control......Page 94 Cisco and PCI Requirements......Page 96 Requirement 9: Physical Security......Page 98 What Else Can You Do To Be Secure?......Page 102 Random Password for Users......Page 104 Common Mistakes and Pitfalls......Page 105 The Case of the Stolen Database......Page 106 The Case of the Loose Permissions......Page 107 Summary......Page 109 6 Protecting Cardholder Data......Page 110 What Is Data Protection and Why Is It Needed?......Page 111 The Confidentiality, Integrity, Availability Triad......Page 112 PCI Requirement 3: Protect Stored Cardholder Data......Page 113 Requirement 3 Walk-through......Page 115 Encryption Methods for Data at Rest......Page 118 PCI and Key Management......Page 124 PCI Requirement 4 Walk-through......Page 126 Transport Layer Security and Secure Sockets Layer......Page 127 Wireless Transmission......Page 128 Misc Card Transmission Rules......Page 129 Requirement 12 Walk-through......Page 130 How to Become Compliant and Secure......Page 133 Step 3: Identify Where the Data Is Stored......Page 134 Step 6: Develop and Document Policies......Page 135 Common Mistakes and Pitfalls......Page 136 The Case of the Data Killers......Page 138 References......Page 140 7 Using Wireless Networking......Page 141 What Is Wireless Network Security?......Page 142 Where Is Wireless Network Security in PCI DSS?......Page 144 Requirements 1 and 12: Documentation......Page 145 Actual Security of Wireless Devices: Requirements 2, 4, and 9......Page 146 Testing for Unauthorized Wireless: Requirement 11.1......Page 148 Why Do We Need Wireless Network Security?......Page 151 Tools and Best Practices......Page 152 Common Mistakes and Pitfalls......Page 153 The Case of the Untethered Laptop......Page 154 The Case of the Expansion Plan......Page 156 The Case of the Double Secret Wireless Network......Page 157 Summary......Page 158 8 Vulnerability Management......Page 159 Vulnerability Management in PCI......Page 161 Stages of Vulnerability Management Process......Page 163 Requirement 5 Walk-through......Page 168 Requirement 6 Walk-through......Page 169 Web-Application Security and Web Vulnerabilities......Page 174 Requirement 11 Walk-through......Page 183 External Vulnerability Scanning with ASV......Page 185 Considerations when Picking an ASV......Page 186 How ASV Scanning Works......Page 190 PCI DSS Scan Validation Walk-through......Page 193 Operationalizing ASV Scanning......Page 195 What Do You Expect from an ASV?......Page 196 Internal Vulnerability Scanning......Page 198 Common PCI Vulnerability Management Mistakes......Page 200 PCI at a Retail Chain......Page 203 Summary......Page 205 References......Page 206 9 Logging Events and Monitoring the Cardholder Data Environment......Page 207 PCI Requirements Covered......Page 208 Why Logging and Monitoring in PCI DSS?......Page 209 Logging and Monitoring in Depth......Page 210 PCI Relevance of Logs......Page 214 Logging in PCI Requirement 10......Page 216 Monitoring Data and Log Security Issues......Page 220 Logging and Monitoring in PCI – All Other Requirements......Page 223 Tools for Logging in PCI......Page 227 Log Management Tools......Page 233 Intrusion Detection and Prevention......Page 235 Integrity Monitoring......Page 240 Case Study......Page 242 The Case of the Risky Risk-Based Approach......Page 243 The Case of Tweaking to Comply......Page 244 References......Page 245 10 Managing a PCI DSS Project to Achieve Compliance......Page 246 Figuring Out If You Need to Comply......Page 247 Compliance Overlap......Page 248 The Level of Validation......Page 249 What Is the Cost for Noncompliance?......Page 250 Bringing the Key Players to the Table......Page 252 Obtaining Corporate Sponsorship......Page 253 Getting Results Fast......Page 254 Budgeting Time and Resources......Page 255 Establishing Goals and Milestones......Page 256 Having Status Meetings......Page 257 Training Your Compliance Team......Page 258 Setting Up the Corporate Compliance Training Program......Page 259 The Steps......Page 261 PCI SSC New Prioritized Approach......Page 264 Summary......Page 265 Reference......Page 266 11 Don’t Fear the Assessor......Page 267 Remember, Assessors Are There to Help......Page 268 How FAIL == WIN......Page 270 Dealing With Assessors’ Mistakes......Page 271 Planning for Remediation......Page 273 Fun Ways to Use Common Vulnerability Scoring System......Page 275 Planning for Reassessing......Page 277 Summary......Page 278 12 The Art of Compensating Control......Page 279 What Is a Compensating Control?......Page 280 Where Are Compensating Controls in PCI DSS?......Page 281 What a Compensating Control Is Not......Page 282 Funny Controls You Didn’t Design......Page 283 How to Create a Good Compensating Control......Page 285 Summary......Page 289 Security Is a Process, Not an Event......Page 291 Plan for Periodic Review and Training......Page 293 Build and Maintain a Secure Network......Page 295 Protect Cardholder Data......Page 296 Maintain a Vulnerability Management Program......Page 297 Regularly Monitor and Test Networks......Page 299 Maintain an Information Security Policy......Page 301 PCI Self-Assessment......Page 302 The Case of the Compliant Company......Page 303 Summary......Page 304 14 PCI and Other Laws, Mandates, and Frameworks......Page 306 Origins of State Data Breach Notification Laws......Page 307 Commonalities Among State Data Breach Laws......Page 308 How Does It Compare to PCI?......Page 309 PCI and the ISO27000 Series......Page 310 PCI and Sarbanes–Oxley (SOX)......Page 312 Regulation Matrix......Page 314 Summary......Page 315 References......Page 316 15 Myths and Misconceptions of PCI DSS......Page 317 Myth #1 PCI Doesn’t Apply......Page 318 Myth #2 PCI Is Confusing......Page 322 Myth #3 PCI DSS Is Too Onerous......Page 324 Myth #4 Breaches Prove PCI DSS Irrelevant......Page 326 Myth #5 PCI Is All We Need for Security......Page 328 Myth #6 PCI DSS Is Really Easy......Page 331 Myth #7 My Tool Is PCI Compliant......Page 333 Myth #8 PCI Is Toothless......Page 336 The Case of the Cardless Merchant......Page 339 References......Page 340 C......Page 342 F......Page 343 M......Page 344 P......Page 345 T......Page 346 W......Page 347
Similar books
PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance
2023 · PDF
PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance
2012 · PDF
PCI Compliance, Fourth Edition: Understand and Implement Effective PCI Data Security Standard Compliance
2014 · PDF
PCI Compliance, Third Edition: Understand and Implement Effective PCI Data Security Standard Compliance
2012 · EPUB
PCI Compliance, Third Edition: Understand and Implement Effective PCI Data Security Standard Compliance
2012 · PDF
PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance
2010 · PDF
PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance
2010 · PDF
MySQL® Notes for Professionals book
2018 · PDF