1 / 2100%
Carlos Delapaz
ISE510
Unit 2 Assignment 1
PCI DSS and the Seven Domains
1. Identify the touch points between the objectives and requirements of PCI DSS and
oYieldMore’s IT environment.
oBuild and Maintain a Secure Network
oProtect Cardholder Data
oMaintain a Vulnerability Management Program
oImplement Strong Access Control Measures
oRegularly Monitor and Test Networks
oMaintain an Information Security Policy
2. Determine appropriate best practices to implement when taking steps to meet PCI
DSS objectives and requirements.
Install and maintain firewalls.
Protect cardholder data
Develop and maintain secure systems and applications.
Restrict access to cardholder data.
Require users to have unique IDs to access the system
Track and monitor access to networks and cardholder data
Schedule quarterly security scans by an outside vendor
Maintain an information security policy
3. Justify your reasoning for each identified best practice.
Make sure to have a network diagram documenting all connec- tions to
cardholder data
Make sure to have a written policy describing data retention and disposal
policies and procedures. This should include how long data is held, for
what purpose and how often it’s disposed of.
Keep lists of security patches installed on systems and be able to show
they are current with the patches issued by vendors.
Be ready to produce a written policy showing that access to systems is
based on the principle of least privilege and that there are systems in place
for auditing provisioning of user access.
Documentation should be available describing authentication methods.
The requirement states that audit trails be turned on for network systems.
Be able to produce copies of these trails for auditors.
This is a cornerstone of PCI. These vendors, called approved scanning
vendors by the PCI council, conduct vulnerability assessments.
The policy should define responsibilities for employees and contractors.
Also, make sure to have documentation of a security awareness program
and an incident response plan.
4. Prepare a brief report or PowerPoint presentation of your findings for IT
management to review
The requirement is spelled out in section 6.6 of the Payment Card Industry Data Security
Standard (PCI DSS), established by the major credit card companies, including Visa Inc.
and MasterCard Inc., to ensure the privacy of customer information. On June 30, the
recommendation went from best practice to requirement.
What does the mandate mean? It means vendors are swooping in with products that
promise to automate code review and make you PCI compliant. For example, Solidcore
Systems Inc., a change control system provider in Cupertino, Calif., offers an embedded
PCI product for point-of-sale (POS) devices that promises to protect against attacks like
the Hannaford Bros. Co. breach in March.
Research houses are cranking out warnings on the risks of not complying. Typical is a
study from Pleasanton, Calif.-based Javelin Strategy and Research showing that 40% of
consumers change their relationship with a business affected by a security breach. The
study also found that 56% of breach victims wisely prefer a solution that prevents
fraudulent use of their information, over a credit-monitoring system that notifies them
when their information has been stolen.
Of course, security experts are at the ready for comment. The eminently quotable Gartner
Inc. security analyst Avivah Litan has observed (everywhere) that most of the Stamford,
Conn.-based firm’s clients were indeed not ready by June 30. And that most clients are
opting for the application firewall rather than taking on the more onerous job of auditing
their applications for flaws and fixing them.
Students also viewed