2
1a) Find one control from NIST 800-53 that pertains to this PCI Goal (GOAL 1: Build and
maintain a secure network that is PCI DSS compliant).
• Control “SC-7”, also known as “Denial of Service Protection” is a control under the
System and Communications Protection group in NIST 800-53. It basically protects
against and limits the impact, and possible outcome relating to different kinds of
denial of service attacks. Some of the most common types of attacks include SYN
Flood, ICMP Flood, and HTTP Flood. Each of these attacks can block important
resources in a company.
b) How will the security control you selected mitigate risks identified in this goal?
• There are numerous ways to mitigate the risks that have been identified within the
goal. It is possible to restrict the internal users, excess bandwidth, excess capacity
and detection, and monitoring systems. While restricting the internal users, the
system basically limits their ability to launch similar attacks against corresponding
information systems. c While managing excess bandwidth and capacity it is possible
to limit the impact of information flooding which is caused by DoS attacks. The
monitoring and detecting tool must be in place so that the effects of flooding on
information systems can be restricted. This type of control has been selected so that
in case any information system will be PCI DSS compliant, an individual must be
able to access relative resources and information in the organization network.
2a) Find one control from NIST 800-53 that pertains to this PCI Goal (GOAL 2: Protect
cardholder data).
• Control “AC-3(6)”, also known as Access Enforcement, Protection of User and
System Information is a control under Control Enhancement group in NIST 800-53.
The role-based access control (RBAC) is a policy which can restrict the access of
the information system to only the individuals with authorized access. Such access is
provided only to authorized users. It can offer secure cardholder data from being
accessed in a malicious manner.
b) How will the security control you selected mitigate risks identified in this goal?
• There are a number of ways to mitigate access control. One such method is
assigning credentials. The individuals who have access to cardholder data should be
the only ones who would be given access. By implementing the access control
model, the people with the authorized credentials can access personal information. c
Such control relates to the PCI Goal. The authorized individuals can access secure
information such as cardholder data or other sensitive information.
3a) Find one control from The CIS Critical Security Controls for Effective Cyber Defense
that pertains to this PCI Goal (GOAL 3: Maintain a vulnerability management program).
3
• Control CSC 4.1, also known as Continuous Vulnerability Assessment and
Remediation is a control from The CIS Critical Security Controls for Effective
Cyber Defense which relates to the PCI Goal. An implemented and automated
vulnerability scanning tool is a basic necessity to improve security posture. Such
tools could be run against all the systems on any familiar network on a regular
basis. It would provide a ranked list relating to the most dangerous vulnerabilities to
each of the system administrators. It would also allow comparing the overall
effectiveness of the system administrators and departments to reduce the risk that is
associated with the vulnerabilities.
b) How will the security control you selected mitigate risks identified in this goal?
• The security control that has been selected will mitigate the risks identified in this
goal by intimating the responsible system administrators about the vulnerabilities to
the systems. The automated system would tell them about the vulnerabilities and the
best ways to reduce the risks that arise due to these vulnerabilities.
4a) Find one control from The CIS Critical Security Controls for Effective Cyber Defense
that pertains to this PCI Goal (GOAL 5: Regularly monitor and test networks).
• Control CSC 20.1, also known as CSC 20: Penetration Tests and Red Team
Exercise is a control from the CIS Critical Security Controls which is designed for
the Effective Cyber Defense. It relates to the PCI Goal. The conduction of regular
penetration tests would help to identify vulnerabilities as well as possible attack
vectors which could be used to exploit the initiative systems. Such tests can be run
on internal and external information systems. But such a test must be carried out
outside the network as it can simulate external attacks and internal attacks.
b) How will the security control you selected mitigate risks identified in this goal?
• The security control that has been selected would mitigate the risks identified in the
goal. This would be possible by allowing the networks to be tested and monitored
for unknown vulnerabilities. It would ensure the network is secure by testing the
implemented defense mechanisms. In case any vulnerability would be found,
necessary steps would be taken to mitigate them.
4
Appendix - PCI DSS 6 Goals from Managing Risk in Information Systems - Maintaining
Compliance (in Classroom)
GOAL 1: Build and maintain a secure network that is PCI DSS compliant
▪ All merchants must protect cardholder information by installing a firewall and a router system.
▪ Install, configure, and maintain a firewall system to maintain control over an organization’s network; use a router
device to connect networks that will make you a PCI compliant merchant.
▪ Next, execute the following steps:
▪ Perform testing when configurations change.
▪ Identify all connections to cardholder information.
▪ Review configuration rules every six months.
▪ Change all default passwords. Default passwords are provided when software is installed; they are discernible and can
be easily discovered by hackers.
GOAL 2: Protect cardholder data
▪ Cardholder data is any personal information about the cardholder that is found on the payment card and can never be
saved by a merchant.
▪ Merchants can only display the maximum of the first six and last four digits of the primary account number.
▪ All information must be encrypted when transmitting data across public networks, such as the Internet, to prevent
criminals from stealing the personal information during the process.
GOAL 3: Maintain a vulnerability management program
▪ Computer viruses make their way onto computers in many ways, but mainly through e-mail and other online activities.
▪ Viruses compromise the security of personal cardholder information on a merchant’s computer, and therefore antivirus
software must be present on all computers associated with the network.
▪ In addition to antivirus software, computers are also susceptible to a breach in the applications and systems installed
on the computer.
▪ Merchants must install vendor-provided security patches within a month of their release to avoid exposing cardholder
data.
GOAL 4: Implement strong access control measures
▪ As a merchant, you must limit the accessibility of cardholder information.
▪ Install passwords and other security measurements to limit employee’s access to cardholder data.
▪ In order to trace employee’s activities when accessing sensitive information, assign each user an unreadable password
used to access the cardholder data.
▪ Monitor the physical access to cardholder data; do not allow unauthorized persons the opportunity to retrieve the
information by securing printed information as well as digital.
▪ Maintain a visitor log and save the log for at least three months.
GOAL 5: Regularly monitor and test networks
▪ Keep system activity logs that trace all activity; review the log daily for security breaches.
▪ The information stored in the logs is useful in the event of a security breach to trace employee activities and locate
the source of the violation.
▪ Each quarter, use a wireless analyzer to check for wireless access points to prevent unauthorized access.
▪ Also, scan internal and external networks to identify any possible vulnerable areas in the system.
▪ Install software to recognize any modification by unauthorized personnel.
GOAL 6: Maintain an information security policy
▪ Establish a security policy that covers all PCI DSS compliance requirements and includes annual procedures to
recognize any security breaches and day-to-day security policies.
▪ Perform background checks on potential employees and educate new and current employees about the compliance
regulations.