1
SNHU
ISE 510 Security Risk Analysis & Plan
2-2 Jones & Bartlett Lecture Presentation and Assignment:
PCI DSS and the Seven Domains
Week 2 HW
30 points
Delapaz Carlos
Due September 1,2019
Submitted on September 15,2019
If late let me know why: resubmission due to wrong file submitted
=====================================
2
1a) Find one control from NIST 800-53 that pertains to this PCI Goal (GOAL 1: Build and
maintain a secure network that is PCI DSS compliant).
Control “SC-7”, also known as “Denial of Service Protection” is a control under the
System and Communications Protection group in NIST 800-53. It basically protects
against and limits the impact, and possible outcome relating to different kinds of denial of
service attacks. Some of the most common types of attacks include SYN Flood, ICMP
Flood, and HTTP Flood. Each of these attacks can block important resources in a
company.
b) How will the security control you selected mitigate risks identified in this goal?
There are numerous ways to mitigate the risks that have been identified within the goal. It
is possible to restrict the internal users, excess bandwidth, excess capacity and detection,
and monitoring systems. While restricting the internal users, the system basically limits
their ability to launch similar attacks against corresponding information systems. While
managing excess bandwidth and capacity it is possible to limit the impact of information
flooding which is caused by DoS attacks. The monitoring and detecting tool must be in
place so that the effects of flooding on information systems can be restricted. This type of
control has been selected so that in case any information system will be PCI DSS
compliant, an individual must be able to access relative resources and information in the
organization network.
2a) Find one control from NIST 800-53 that pertains to this PCI Goal (GOAL 2: Protect
cardholder data).
Control “AC-3(6)”, also known as Access Enforcement, Protection of User and System
Information is a control under Control Enhancement group in NIST 800-53. The role-
based access control (RBAC) is a policy which can restrict the access of the information
system to only the individuals with authorized access. Such access is provided only to
authorized users. It can offer secure cardholder data from being accessed in a malicious
manner.
b) How will the security control you selected mitigate risks identified in this goal?
There are a number of ways to mitigate access control. One such method is assigning
credentials. The individuals who have access to cardholder data should be the only ones
who would be given access. By implementing the access control model, the people with
the authorized credentials can access personal information. Such control relates to the
PCI Goal. The authorized individuals can access secure information such as cardholder
data or other sensitive information.
3a) Find one control from The CIS Critical Security Controls for Effective Cyber Defense that
pertains to this PCI Goal (GOAL 3: Maintain a vulnerability management program).
3
Control CSC 4.1, also known as Continuous Vulnerability Assessment and Remediation
is a control from The CIS Critical Security Controls for Effective Cyber Defense which
relates to the PCI Goal. An implemented and automated vulnerability scanning tool is a
basic necessity to improve security posture. Such tools could be run against all the
systems on any familiar network on a regular basis. It would provide a ranked list relating
to the most dangerous vulnerabilities to each of the system administrators. It would also
allow comparing the overall effectiveness of the system administrators and departments
to reduce the risk that is associated with the vulnerabilities.
b) How will the security control you selected mitigate risks identified in this goal?
The security control that has been selected will mitigate the risks identified in this goal by
intimating the responsible system administrators about the vulnerabilities to the systems.
The automated system would tell them about the vulnerabilities and the best ways to
reduce the risks that arise due to these vulnerabilities.
4a) Find one control from The CIS Critical Security Controls for Effective Cyber Defense that
pertains to this PCI Goal (GOAL 5: Regularly monitor and test networks).
Control CSC 20.1, also known as CSC 20: Penetration Tests and Red Team Exercise is a
control from the CIS Critical Security Controls which is designed for the Effective Cyber
Defense. It relates to the PCI Goal. The conduction of regular penetration tests would
help to identify vulnerabilities as well as possible attack vectors which could be used to
exploit the initiative systems. Such tests can be run on internal and external information
systems. But such a test must be carried out outside the network as it can simulate
external attacks and internal attacks.
b) How will the security control you selected mitigate risks identified in this goal?
The security control that has been selected would mitigate the risks identified in the goal.
This would be possible by allowing the networks to be tested and monitored for unknown
vulnerabilities. It would ensure the network is secure by testing the implemented defense
mechanisms. In case any vulnerability would be found, necessary steps would be taken to
mitigate them.
4
Appendix - PCI DSS 6 Goals from Managing Risk in Information Systems - Maintaining
Compliance (in Classroom)
GOAL 1: Build and maintain a secure network that is PCI DSS compliant
All merchants must protect cardholder information by installing a firewall and a router system.
Install, configure, and maintain a firewall system to maintain control over an organization’s network; use a router device to connect
networks that will make you a PCI compliant merchant.
Next, execute the following steps:
Perform testing when configurations change.
Identify all connections to cardholder information.
Review configuration rules every six months.
Change all default passwords. Default passwords are provided when software is installed; they are discernible and can be easily
discovered by hackers.
GOAL 2: Protect cardholder data
Cardholder data is any personal information about the cardholder that is found on the payment card and can never be saved by a
merchant.
Merchants can only display the maximum of the first six and last four digits of the primary account number.
All information must be encrypted when transmitting data across public networks, such as the Internet, to prevent criminals from
stealing the personal information during the process.
GOAL 3: Maintain a vulnerability management program
Computer viruses make their way onto computers in many ways, but mainly through e-mail and other online activities.
Viruses compromise the security of personal cardholder information on a merchant’s computer, and therefore antivirus software must
be present on all computers associated with the network.
In addition to antivirus software, computers are also susceptible to a breach in the applications and systems installed on the computer.
Merchants must install vendor-provided security patches within a month of their release to avoid exposing cardholder data.
GOAL 4: Implement strong access control measures
As a merchant, you must limit the accessibility of cardholder information.
Install passwords and other security measurements to limit employee’s access to cardholder data.
In order to trace employee’s activities when accessing sensitive information, assign each user an unreadable password used to access
the cardholder data.
Monitor the physical access to cardholder data; do not allow unauthorized persons the opportunity to retrieve the information by
securing printed information as well as digital.
Maintain a visitor log and save the log for at least three months.
GOAL 5: Regularly monitor and test networks
Keep system activity logs that trace all activity; review the log daily for security breaches.
The information stored in the logs is useful in the event of a security breach to trace employee activities and locate the source of the
violation.
Each quarter, use a wireless analyzer to check for wireless access points to prevent unauthorized access.
Also, scan internal and external networks to identify any possible vulnerable areas in the system.
Install software to recognize any modification by unauthorized personnel.
GOAL 6: Maintain an information security policy
Establish a security policy that covers all PCI DSS compliance requirements and includes annual procedures to recognize any security
breaches and day-to-day security policies.
Perform background checks on potential employees and educate new and current employees about the compliance regulations.