PCI Compliance. by: David Koston



Similar documents
A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS)

Catapult PCI Compliance

Credit Card Security

PCI PA - DSS. Point BKX Implementation Guide. Version Atos Xenta, Atos Xenteo and Atos Yomani using the Point BKX Payment Core

Josiah Wilkinson Internal Security Assessor. Nationwide

Implementation Guide

PCI DSS Policies Outline. PCI DSS Policies. All Rights Reserved. ecfirst Page 1 of 7

Becoming PCI Compliant

PCI PA - DSS. Point XSA Implementation Guide. Atos Worldline Banksys XENTA SA. Version 1.00

PCI PA - DSS. Point ipos Implementation Guide. Version VeriFone Vx820 using the Point ipos Payment Core

University of Sunderland Business Assurance PCI Security Policy

Enforcing PCI Data Security Standard Compliance

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

paypoint implementation guide

PLACE GROUP UK LONDON STUDENT HOUSING GROUP PAYMENT CARD INDUSTRY DATA SECURITY STANDARD COMPLIANCE STATEMENT PCI DSS (09) VERSION: 2009PCIDSSP4S01

Presented By: Bryan Miller CCIE, CISSP

Please note that in VISA s vernacular this security program for merchants is sometimes called CISP (cardholder information security program).

Visa U.S.A Cardholder Information Security Program (CISP) Payment Application Best Practices

Payment Card Industry (PCI) Compliance. Management Guidelines

Achieving PCI-Compliance through Cyberoam

March

PCI DSS Requirements - Security Controls and Processes

PA-DSS Implementation Guide for. Sage MAS 90 and 200 ERP. Credit Card Processing

Minnesota State Colleges and Universities System Procedures Chapter 5 Administration. Guideline Payment Card Industry Technical Requirements

Project Title slide Project: PCI. Are You At Risk?

PCI Data Security and Classification Standards Summary

Credit Card Processing Overview

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

Standard: PCI Data Security Standard (PCI DSS) Version: 2.0 Date: March Information Supplement: Protecting Telephone-based Payment Card Data

TERMINAL CONTROL MEASURES

Payment Card Industry Data Security Standard PCI-DSS #SA7D, Platform Database, Tuning & Security

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows:

Symposium (FBOS) PCI Compliance. Connecting Great Ideas and Great People. Agenda

CardControl. Credit Card Processing 101. Overview. Contents

Visa Asia Pacific Account Information Security (AIS) Program Payment Application Best Practices (PABP)

Payment Cardholder Data Handling Procedures (required to accept any credit card payments)

74% 96 Action Items. Compliance

Information Technology

Credit Cards and Oracle E-Business Suite Security and PCI Compliance Issues

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance

PCI Data Security Standards

Credit Card Handling Security Standards

COLUMBUS STATE COMMUNITY COLLEGE POLICY AND PROCEDURES MANUAL

PCI Security Compliance

Key Steps to Meeting PCI DSS 2.0 Requirements Using Sensitive Data Discovery and Masking

How To Comply With The Pci Ds.S.A.S

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October cliftonlarsonallen.com CliftonLarsonAllen LLP

How NETGEAR ProSecure UTM Helps Small Businesses Meet PCI Requirements

Qualified Integrators and Resellers (QIR) Implementation Statement

SonicWALL PCI 1.1 Implementation Guide

Top Three POS System Vulnerabilities Identified to Promote Data Security Awareness

Linux VPS with cpanel. Getting Started Guide

Two Approaches to PCI-DSS Compliance

PCI Compliance Security Awareness Program For Marine Corps Community Services Contacts: Paul Watson

Payment Card Industry Compliance

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

How Reflection Software Facilitates PCI DSS Compliance

Payment Card Industry Data Security Standard PCI DSS

General Standards for Payment Card Environments at Miami University

Payment Card Industry (PCI) Data Security Standard. Requirements and Security Assessment Procedures. Version 3.0 November 2013

Payment Card Industry (PCI) Data Security Standard. Requirements and Security Assessment Procedures. Version 3.1 April 2015

Parallels Plesk Panel

GFI White Paper PCI-DSS compliance and GFI Software products

PCI Compliance - A Realistic Approach. Harshul Joshi, CISM, CISA, CISSP Director, Information Technology CBIZ MHM hjoshi@cbiz.com

NETePay 5.0. FDMS Nashville. Installation & Configuration Guide. Part Number:

PCI Training for Retail Jamboree Staff Volunteers. Securing Cardholder Data

Introduction to PCI DSS

SonicWALL PCI 1.1 Self-Assessment Questionnaire

Client Security Risk Assessment Questionnaire

Information Sheet. PCI DSS Overview

Frequently Asked Questions

2.0 PAYMENT CARD INDUSTRY DATA SECURITY STANDARDS (PCI-DSS)

Demystifying the Payment Card Industry - Data Security Standard

COLORADO STATE UNIVERSITY Financial Procedure Statements FPI 6-6

ARE YOU REALLY PCI DSS COMPLIANT? Case Studies of PCI DSS Failure! Jeff Foresman, PCI-QSA, CISSP Partner PONDURANCE

PA-DSS Implementation Guide: Steps to ensure that your POS system is secure

3M SelfCheck Self-Pay Software. Implementation Guide

Payment Card Industry Data Security Standard

Question Name C 1.1 Do all users and administrators have a unique ID and password? Yes

Viterbo University Credit Card Processing & Data Security Procedures and Policy

PCI Data Security Standard Overview and observations from the field. Andrea Del Miglio Practice Manager 28 March 2007

F-SECURE MESSAGING SECURITY GATEWAY

Data Security for the Hospitality

Windows Azure Customer PCI Guide

PA-DSS Implementation Guide. Version Document Owners. Approval Date: January 2012

A Rackspace White Paper Spring 2010

Why Is Compliance with PCI DSS Important?

Payment Card Industry Self-Assessment Questionnaire

SAQ D Compliance. Scott St. Aubin Senior Security Consultant QSA, CISM, CISSP

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

Appendix 1 Payment Card Industry Data Security Standards Program

Using Automated, Detailed Configuration and Change Reporting to Achieve and Maintain PCI Compliance Part 2

Need to be PCI DSS compliant and reduce the risk of fraud?

Preventing. Payment Card Fraud. Is your business protected?

University of Dayton Credit / Debit Card Acceptance Policy September 1, 2009

Parallels Plesk Panel

Implementation Guide for PCI Compliance Microsoft Dynamics RMS

PCI PA-DSS Implementation Guide

Your Compliance Classification Level and What it Means

Transcription:

PCI Compliance by: David Koston

PCI DSS Payment Card Industry Data Security Standard American Express Discover JCB MasterCard VISA

Why? Continue to do business Retain Customers Legal Standards are Coming! Texas' House of Representatives voted 139-0 in favor of a bill that puts PCI requirements into a state law. Under HB 3222 a breached entity will have to reimburse banks and credit unions the cost associated with blocking and reissuing cards if the merchant was not PCI compliant at the time of the compromise. Is your state next?

Disclaimer I'm not a PCI Compliance Assessor or a member of the Payment Card Industry. This information is meant to be used for informational purposes in order to help those with a cpanel server become PCI compliant. No warranty of any kind is provided with this information. This information does not guarantee security or compliance of any kind. Follow the included steps at your own risk.

The Standard https://www.pcisecuritystandards.org/tech/pci_dss.htm Data Storage Information Security Policies Network and Server Security Securing a cpanel / WHM Server

Data Storage What data is stored Data Security

Store What to Store Primary Account Number You can store (must be protected) Cardholder Name Service Code Expiration Date Do Not Store! Full Magnetic Stripe CVC2 / CVV2 / CID PIN / PIN Block

Protect Stored Data On all fronts Physical Protection Electronic Protection All the encryption in the world won't save you if someone can waltz into your server room and access your stored card numbers.

Physical Data Protection Need-to-know disclosures Secure Facility Locks Cameras Cages Visitor Log ID cards Off-site, secure backups!

Electronic Protection - Data Encrypt all traffic and all data Mask PAN when displayed Limit access to servers with secure data Dedicated data storage machines? Drawbridge or stone hut?

Information Security Policy A strong information security policy is important so that all employees are aware of the sensitivity of stored data.

Your Information Security Policy Easily Available Daily Procedures for Staff Clear list of staff with access Who can be trusted? Where can we put data, servers, etc? What software can be on these machines? Workstation vulnerabilities Read-only data, no local storage Audit your policies and procedures frequently

Network and Server Security Denying access Hello, Administrator! Where's that data going? 3 rd Party Application Security Access Control Tracking and Testing

Denying Access Firewalls Block all traffic Explicitly allow necessary traffic Don't forget the workstations! http://www.cpanel.net/security/firewalls.html Services Turn off all unused services

Hello, Administrator! Vendor supplied defaults are bad, mmmkay! Logins and passwords WEP keys Ports URLs

Where's that data going? Simple network setups are easy to keep under wraps Does the data need to leave the subnet, the firewall, the DMZ? What other systems can locate or talk to the data storage system(s)?

3 rd Party Application Security Research, Research, Testing, Testing, Research, Testing, Testing, Testing

Access Control All users must have unique logins Easy vs. Secure Two-factor authentication Is this John Smith? Yes Ok, here's your card number

Tracking and Testing Log access, data transfer, system modifications, etc Who, what, when, where from, where to, worked, and why? This is not a Ronco Showtime TM Rotisserie! Testing, testing, and more testing!

Securing a cpanel / WHM server for PCI DSS Compliance What to do after installation? Lock down open ports Shut off unneeded services Restrict Service Access All traffic over SSL Turn off recursive BIND lookups Turn off mod_userdir Use public key authentication for SSH Other Measures

Securing Lock down open ports Limit open ports to those necessary Example APF configuration: INGRESS (inbound) IG_TCP_CPORTS= 22,25,53,80,443,2083,208 7,2096" IG_UDP_CPORTS="53,465" EGRESS (outbound) EG_TCP_CPORTS="25,37,53,80,113,465,2089" EG_UDP_CPORTS="53,465"

Securing Shut off unneeded services WHM >> Service Configuration >> Service Manager Turn off: Entropychat Interchange Melange Named? MySQL? FTP?

Securing Restrict Service Access WHM >> Security Center >> Host Access Control Restrict access to services such as SSH, FTP, MySQL, etc Deny all traffic and only allow access from specific IP addresses

Securing All traffic over SSL WHM >> SSL/TLS >> Change Server Certificates cpanel / WHM Exim Webmail Courier Apache too! (SSL Manager)

Securing Turn off BIND recursion /etc/named.conf Add the following lines to the options section: Allow-recursion { none ;}; Recursion no; #disables zone transfers Allow-transfer { none ;};

Securing No mod_userdir WHM >> Security Center >> Apache mod_userdir Tweak Enable mod_userdir protection for all users

Securing Public Key Authentication 2 factor authentication require a key and passphrase WHM >> Security >> Manage SSH Keys Create and Authorize your key Disable Password Authentication WHM >> Security Center >> SSH Password Auth Tweak cpanel >> SSH/ Shell Access >> Manage SSH Keys

Securing Public Key Authentication For detailed instructions: http://www.cpanel.net/security/publickeyauth.htm

Securing Other Measures Separate your services Remote MySQL server on local subnet Remote DNS only, no local BIND

Securing Other Measures cpaddons Limit Usage Keep up to date WHM >> Manage cpaddons >> Upgrade all installs that need it Research and contact

Caveats OpenSSL 0.9.7a-43.16 Upgrade to 0.9.8??

Next Steps Contact an assessor ScanAlert www.scanalert.com http://www.scanalert.com/content/webhost/?hostid=4378

Questions?? Ask Away!