pci compliance technical overview 2008. rm pci calendar sept 2006: official 15.1 pci release sept...

14
PCI Compliance Technical Overview 2008

Post on 19-Dec-2015

220 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: PCI Compliance Technical Overview 2008. RM PCI Calendar Sept 2006: Official 15.1 PCI Release Sept 2006: 15.1 certified PCI Compliant Jan 2007: VISA approves

PCI ComplianceTechnical Overview

2008

Page 2: PCI Compliance Technical Overview 2008. RM PCI Calendar Sept 2006: Official 15.1 PCI Release Sept 2006: 15.1 certified PCI Compliant Jan 2007: VISA approves

RM PCI Calendar

Sept 2006: Official 15.1 PCI Release

Sept 2006: 15.1 certified PCI Compliant

Jan 2007: VISA approves certification

May 2007: Official 16.0 PCI Release

Dec 2007: 16.0 certified PCI Compliant

Awaiting VISA certification approval

Page 3: PCI Compliance Technical Overview 2008. RM PCI Calendar Sept 2006: Official 15.1 PCI Release Sept 2006: 15.1 certified PCI Compliant Jan 2007: VISA approves

Terms and Definitions PCI DSS: Payment Card Industry Data

Security Standard PABP: Payment Application Best

Practices RM is a validated payment application

that meets the PCI PABP So what is “PCI Compliance”? Hint: It’s

not simply installing RM 15.1.

Page 4: PCI Compliance Technical Overview 2008. RM PCI Calendar Sept 2006: Official 15.1 PCI Release Sept 2006: 15.1 certified PCI Compliant Jan 2007: VISA approves

The PCI Compliant SiteTo be a fully PCI compliant site, there are 4 areas needing

attention: Use PABP validated applications

Install RM 15.1 or later Proper configuration

RM and Reseller PCI Guidance Doc Proper procedures

Server machine access Remote access

Site guidelines Physical machine access Network / Wireless

Page 9: PCI Compliance Technical Overview 2008. RM PCI Calendar Sept 2006: Official 15.1 PCI Release Sept 2006: 15.1 certified PCI Compliant Jan 2007: VISA approves

What’s a DMZ? DMZ: “De-Militarized Zone” Separate network isolated from RM

network DMZ exposed to internet RM network isolated from internet All enforced through firewall

configuration rules

Page 11: PCI Compliance Technical Overview 2008. RM PCI Calendar Sept 2006: Official 15.1 PCI Release Sept 2006: 15.1 certified PCI Compliant Jan 2007: VISA approves

Setting up DMZ Server RM and Reseller PCI Guidance:

Install NetworkActiv AUTAPF port forwarder as a service

Configure single port forwarding rule Configure OO/RMbrowser/WO Phone

setup to go to DMZ machine and port

Page 12: PCI Compliance Technical Overview 2008. RM PCI Calendar Sept 2006: Official 15.1 PCI Release Sept 2006: 15.1 certified PCI Compliant Jan 2007: VISA approves

Firewall RulesInternet

DMZ10.1.1.*

RM10.1.0.*

Limited to proxy

Page 13: PCI Compliance Technical Overview 2008. RM PCI Calendar Sept 2006: Official 15.1 PCI Release Sept 2006: 15.1 certified PCI Compliant Jan 2007: VISA approves

Setting up the Firewall Symbol WS2000 configuration

Two subnets 1 for RM 1 for DMZ

Firewall Rules Now we’ll show you how…

Page 14: PCI Compliance Technical Overview 2008. RM PCI Calendar Sept 2006: Official 15.1 PCI Release Sept 2006: 15.1 certified PCI Compliant Jan 2007: VISA approves

Questions?