![]() |
|
| Payment Card Industry (PCI) |
| How Network-based Access Controls Can Help with Compliance | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
In the wake of several security breaches, the Payment Card Industry, an industry group set up by the major credit card brand companies, has set out to define security requirements for handling credit card data. The group’s Data Security Standard (DSS) version 1.1 specification details the steps any entity that processes, stores, or transmits credit cards must take to protect cardholder data. As with any specification, of course, much is left to interpretation. In the case of the PCI DSS, it’s the Qualified Security Assessors (QSAs) who end up interpreting the specification to see whether a company is compliant with the spec. The spec details only the result of a given security parameter – it does not define how a company must achieve that security. No single process, technology, or system can enable a company to become PCI compliant. Instead, businesses will need to take multiple steps, including deploying security products, to help in this process. Network access controls, in particular those based on identity and role, can play a significant part in helping companies achieve PCI compliance. Network access controls include the ability to authenticate users to a network, track all their activities, learn the user’s role, apply access policies based on that role to govern which resources the user can reach, and detect anomalous behavior on the part of users or applications that might signal an attack. ConSentry Networks has worked with several companies to apply its access control technology to the PCI regulation. The company has been able to help electronic funds processors and other companies achieve compliance in a quick timeframe. The following PCI matrix provides some insight into how ConSentry can be part of an organization’s efforts to meet the PCI requirements. It details the various aspects of the PCI DSS 1.1 specification where ConSentry can deliver concrete tools that achieve the requirement. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||
How ConSentry Addresses PCI Compliance Requirements |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Copyright © 2008, ConSentry Networks. All rights reserved. | 1690 McCandless Drive, Milpitas, CA 95035 | +1 408-956-2100 | 1-866-841-9100 |