Casestudy

profilesateesh439
Audit2E_Lab09_AW_f216f1508aeaec40fbabceb5e27289e4.pdf

78 LAB #9 | Auditing the System/Application Domain for Compliance Lab #9 - Assessment Worksheet

Auditing the System/Application Domain for Compliance Course Name and Number: _____________________________________________________ Student Name: ________________________________________________________________ Instructor Name: ______________________________________________________________ Lab Due Date: ________________________________________________________________

Overview

In this lab, you learned how to audit the System/Application Domain. You identified common risks, threats, and vulnerabilities found in the System/Application Domain, you aligned the Payment Card Industry Data Security Standard (PCI DSS) standard to the System/Application Domain of security responsibility given that servers perform e-commerce credit card transactions online, you reviewed the PCI DSS standard for the System/Application Domain, and you created a PCI DSS audit for a compliance checklist to identify all elements needed for assessment and compliance with the PCI DSS standard within the System/Application Domain.

Lab Assessment Questions & Answers

1. What are some common risks, threats, and vulnerabilities found in the System/Application Domain that must be mitigated with proper security countermeasures?

2. If your company makes software to accept credit card payments, what standard would you use to

measure and audit your software security?

3. Which three PCI requirements are most relevant to the System/Application Domain?

79

Copyright © 2015 by Jones & Bartlett Learning, LLC, an Ascend Learning Company. All rights reserved. www.jblearning.com Student Lab Manual

4. Your production system is regularly backed up and some of the data is used for testing and developing a new application interface. Is this in compliance with PCI DSS?

5. Why is it a risk to use production data for development?

6. What are some options, according to PCI DSS, to protect external-facing Web applications from known attacks?

7. To perform a PCI DSS compliance audit on your e-commerce Web site, what should you incorporate into Requirement #6, “Develop and Maintain Secure Systems & Applications”?

8. What do you recommend this organization implement for privacy data storage in long-term data storage devices?

9. To perform a PCI DSS compliance audit, what elements must be in your audit checklist that pertain to the System/Application Domain?

10. Performing a vulnerability assessment on PCI DSS production systems, servers, and applications requires what applications and tools?

11. Refer to the PCI DSS Self-Assessment Questionnaire (SAQ) and Attestation of Compliance for All Merchants and all SAQ-Eligible Service Providers v1.2. There are five different SAQ validation types. Which type encompasses merchants who use imprint, standalone terminals, Point of Sale (POS) systems, and store PCI DSS privacy data in databases and storage?

80 LAB #9 | Auditing the System/Application Domain for Compliance

12. As per the SAQ-D and Attestation of Compliance, what are the four major elements a merchant must achieve as part of PCI DSS compliance?

13. Which requirements in PCI DSS SAQ-D apply to vulnerability assessment and vulnerability management for production credit card transaction-processing servers?

14. Which requirements in PCI DSS SAQ-D apply to performing internal and external vulnerability assessment scans and penetration testing on production IT infrastructure and credit card transaction-processing servers?

15. Which requirements in PCI DSS SAQ-D apply to performing file integrity monitoring on critical cardholder servers?

  1. Course Name and Number:
  2. Student Name:
  3. Instructor Name:
  4. Lab Due Date:
  5. Question1:
  6. Question2:
  7. Question3:
  8. Question4:
  9. Question5:
  10. Question6:
  11. Question7:
  12. Question8:
  13. Question9:
  14. Question10:
  15. Question11:
  16. Question12:
  17. Question13:
  18. Question14:
  19. Question15: