1 / 34100%
Name
Strayer University
Designing PCI DSS Technical Safeguards for an E-commerce Website
CIS 349 – Information Technology Audit and Control
Assignment 3:
Designing PCI DSS Technical Safeguards for an E-commerce Website
Imagine you are an Information Security consultant hired by an e-commerce company that handles
credit card transactions. The company needs to comply with the Payment Card Industry Data Security
Standard (PCI DSS). Write a three to five-page paper in which you:
1. Analyze proper physical access control safeguards for the company's data center or server room,
and provide recommendations for securing cardholder data.
2. Recommend the proper audit controls to be employed to monitor credit card transactions and
access to sensitive data.
3. Suggest three logical access control methods to restrict unauthorized access to cardholder data,
and explain why you suggested each method.
4. Analyze how credit card data is transmitted between the website and the payment gateway and
identify techniques that may be used to provide transmission security safeguards.
Your assignment must follow these formatting requirements:
Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all sides;
citations and references must follow APA or school-specific format. Check with your professor for any
additional instructions.
Include a cover page containing the title of the assignment, the student’s name, the professor’s name,
the course title, and the date. The cover page and the reference page are not included in the required
assignment page length.
The specific course learning outcomes associated with this assignment are:
Describe the role of information systems security (ISS) compliance and its relationship to U.S.
compliance laws.
Use technology and information resources to research issues in security strategy and policy
formation.
Write clearly and concisely about topics related to information technology audit and control
using proper writing mechanics and technical style conventions.
Clickhereto view the grading rubric.
Grading for this assignment will be based on answer quality, logic / organization of the paper, and
language and writing skills, using the following rubric.
Points: 50 Assignment 3: Designing PCI DSS Technical Safeguards for an E-commerce Website
Criteria Unacceptable
Below 60% F
Meets Minimum
Expectations
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplar
90-100%
1. Analyze proper
physical access
control
safeguards and
provide sound
recommendation
s to be employed
in the registrar's
office.
Weight: 21%
Did not submit or
incompletely analyzed
proper physical access
control safeguards and did
not submit or incompletely
provided sound
recommendations to be
employed in the registrar's
office.
Insufficientlyanalyze
d proper physical
access control
safeguards and
insufficientlyprovided
sound
recommendations to
be employed in the
registrar's office.
Partially analyzed
proper physical
access control
safeguards and
partiallyprovided
sound
recommendation
s to be employed
in the registrar's
office.
Satisfactorilyanalyze
d proper physical
access control
safeguards and
satisfactorilyprovided
sound
recommendations to
be employed in the
registrar's office.
Thoroughlyana
proper physica
access control
safeguards an
thoroughlyprov
sound
recommendati
to be employed
the registrar's o
2. Recommend
the proper audit
Students also viewed