Information Security

Activate your FREE membership today  |  Log-in

  • Visit other TechTarget ANZ sites: 
Posted
Feb 22, 2008
 |  By
Patrick Gray

Poor network segmentation biggest threat to PCI compliance

The top mistake made by organisations when implementing the Payment Card Industry Data Security Standard (PCI DSS) is poor network segmentation, according to Verizon Business Security Solutions' principal security architect Michael Nott.

Smaller organisations are often unaware processing transactions on their office networks brings the entire LAN under scope for PCI assessment, he says. "In a lot of cases they don't understand that they should be isolating their production environments from their office network," he told SearchSecurity.com.au. "If you can segment your ... corporate office from your production server ... then PCI only applies to your production environment."

Other common problems include some organisations failing to realise they can't store historical information - such as card numbers - in their databases since the PCI standard came into effect. Access control can also be an issue, Nott says. "They need to have lockdown on production systems and the separation of duties so you can't have one person able to maliciously create a piece of code and roll it up into production without someone reviewing it."

In some circumstances, however, it makes sense for organisations to allow their entire office network to be assessed as in-scope. Those logging in to an in-scope environment from an out-of-scope system must use two factor authentication, Nott says, which might not be practical in some environments, like callcentres. "It really is case by case," he added.


Tripwire_topic_centre_logo

Tripwire helps over 6,000 enterprises worldwide attain compliance, reduce security risks, and increase operational efficiency throughout their IT infrastructure. Tripwire provides policy-based configuration assessment and change auditing capabilities out-of-the-box for virtual and physical infrastructures to quickly achieve and maintain configuration control.

Resource Centres

White Papers

Additional Resources

Contact us: Email blouden@tripwire.com or phone:
+613 9795 9816

TechTarget ANZ sites: SearchCIO.com.au | SearchNetworking.com.au | SearchSecurity.com.au | SearchStorage.com.au | SearchVoIP.com.au

WF Online community sites: ElectricalSolutions | ElectronicsOnline | FoodProcessing | InMotionOnline | LabOnline | ProcessOnline | RadioComms | SafetySolutions | SustainabilityMatters | Voice&Data

Copyright © 2008 Westwick-Farrow Pty Ltd. All rights reserved.
About Us | Contact Us | TechTarget