PCI Compliance Technical Overview
RM PCI Calendar Dec 2005: Began PCI 15.1 development Feb 2006: Initial PCI Audit Sept 2006: Official 15.1 PCI Release Sept 2006: Validation Report sent to VISA Jan 2007: VISA approves certification
Card Data Compromises n 40% of all compromises involve a restaurant n Top 5 compromises: Full track data retention Default accounts Insecure remote access Non-use of security tools (antivirus, encryption) SQL injection
Terms and Definitions n PCI DSS: Payment Card Industry Data Security Standard n PABP: Payment Application Best Practices n RM is a validated payment application that meets the PCI PABP n So what is “PCI Compliance”? Hint: It’s not simply installing RM 15.1.
The PCI Compliant Site Restaurant must use PCI PABP validated POS application, properly configured, implementing proper procedures, and installed following all site-specific PCI guidelines and rules. That’s 4 areas needing attention: n Use PABP validated applications n Proper configuration n Proper procedures n Follow site guidelines
1. Use PABP validated applications n Use RM 15.1 (final release Sept 2006 or later) n Use certified credit card processing gateways (e.g. Mercury Payment Systems, PC Charge, Datacap)
2. Proper Configuration n Follow ASI PCI configuration guidelines: RM and Reseller PCI Guidance Doc RM and Reseller PCI Guidance Logging, Audit Trail Admin Password Expiration
3. Proper Procedures n Enforcing limited access to RM Server machine. n Internet use from Server machine n Remote access (allowed only during incident) n No ing of card data
4. Site Guidelines n Secure RM Server (credit card server) Physical access Logical access (open ports) Firewalled n Network n Remote Access 2-factor authentication (VPN + PCAnywhere passwords) n And Wireless …
4. Site Guidelines (WiFi) n Enable WPA with key rotation n Change SSID from default n Turn off SSID broadcast n Implement MAC address filtering n Install firewall services between APs and RM Server n Port/Service Restrictions Only: TCP 80, DNS 53, ICMP
Basic Network Internet
Network w/ WiFi Internet
Network w/ WiFi Internet Symbol WS2000
Thank you Questions?