Loaded Commerce Community

Banner


Board index » PCI Compliance » PCI for store owners - merchants

All times are UTC - 5 hours




Post new topic Reply to topic  [ 4 posts ] 
Author Message
 Post subject: PCI DSS - Requirement 1:
PostPosted: Tue Jun 09, 2009 1:58 pm 
Offline
CRE Expert
User avatar

Joined: Wed Jul 30, 2003 12:00 am
Posts: 1411
Requirement 1: Install and maintain a firewall configuration to protect cardholder data

Before you check off #1 on your SAQ, know what your signing. You are actaully attesting that you have done or created a mitigating solution for the following items:

1.1 Establish firewall and router configuration standards that include the following:

1.1.1 A formal process for approving and testing all network connections and changes to the firewall and router configurations

1.1.2 Current network diagram with all connections to cardholder data, including any wireless networks

1.1.3 Requirements for a firewall at each Internet connection and between any demilitarized zone (DMZ) and the internal network zone

1.1.4 Description of groups, roles, and responsibilities for logical management of network components

1.1.5 Documentation and business justification for use of all services, protocols, and ports allowed, including documentation of security features implemented for those protocols considered to be insecure

1.1.6 Requirement to review firewall and router rule sets at least every six months

---------------------------------------

1.2 Build a firewall configuration that restricts connections between untrusted networks and any system components in the cardholder data environment.

1.2.1 Restrict inbound and outbound traffic to that which is necessary for the cardholder data environment.

1.2.2 Secure and synchronize router configuration files.

1.2.3 Install perimeter firewalls between any wireless networks and the cardholder data environment, and configure these firewalls to deny or control (if such traffic is necessary for business purposes) any traffic from the wireless environment into the cardholder data environment.

---------------------------------------

1.3 Prohibit direct public access between the Internet and any system component in the cardholder data environment.

1.3.1 Implement a DMZ to limit inbound and outbound traffic to only protocols that are necessary for the cardholder data environment.

1.3.2 Limit inbound Internet traffic to IP addresses within the DMZ.

1.3.3 Do not allow any direct routes inbound or outbound for traffic between the Internet and the cardholder data environment.

1.3.4 Do not allow internal addresses to pass from the Internet into the DMZ.

1.3.5 Restrict outbound traffic from the cardholder data environment to theInternet such that outbound traffic can only access IP addresses within the DMZ.

1.3.6 Implement stateful inspection, also known as dynamic packet filtering. (That is, only ”established” connections are allowed into the network.)

1.3.7 Place the database in an internal network zone, segregated from the DMZ.

1.3.8 Implement IP masquerading to prevent internal addresses from being translated and revealed on the Internet, using RFC 1918 address space. Use network address translation (NAT) technologies—for example, port address translation (PAT).

---------------------------------------

1.4 Install personal firewall software on any mobile and/or employee-owned computers with direct connectivity to the Internet (for example, laptops used by employees), which are used to access the organization’s network.

---------------------------------------

Lets discuss :)


Top
 Profile  
 
 Post subject: Re: PCI DSS - Requirement 1:
PostPosted: Tue Jun 09, 2009 2:04 pm 
Offline
CRE Expert
User avatar

Joined: Wed Jul 30, 2003 12:00 am
Posts: 1411
With CRE Secure - when used as directed - you can be be PCI Compliant without fulfilling this requirement.

See SAQ-A (yay) versus SAQ-C (oh no!)

https://www.pcisecuritystandards.org/saq/index.shtml

_________________
Regards,

Salvatore Iozzia
Founder and Chief Evil Overlord
Loaded Commerce, LLC & The Reactor Works / Hosting
http://loadedcommerce.com | http://thereactorworks.com | http://thereactorhosting.com

JOIN THE LOADED SKYPE CHAT:
http://tinyurl.com/7mlvwot

follow me on TWITTER! http://www.twitter.com/saliozzia


Top
 Profile  
 
 Post subject: Re: PCI DSS - Requirement 1:
PostPosted: Wed Jul 08, 2009 8:31 pm 
Offline
CRE Talented
User avatar

Joined: Sat Apr 19, 2008 3:51 am
Posts: 431
Location: Tennessee
Would running CRE Secure make a website secure enough to protect any and all customer information including Phone Numbers, address's, email and other customer information even if hosted by Chain Reaction Web?

Are all the servers utilized by Chain reation Web Certified PCI SECURE by Control Scan since they are

Code:
CRE Loaded Announces Strategic Partnership with ControlScan


based on what I always see in my admin side of our B2B 6.4 Cart?

Is using PayPal 100% PCI secure since our sites collect no Credit Card information but it is collected by PayPal off site?

If so why do the not show this code
Code:
$this->pci = true;
which is in CRE Secures payment module but no other which allows it to show this Image instead of this Image

Would this not be considered deceiving to you if you were a customer looking for a payment method and thought by looking at the symbols CRE Secure would appear to be the only PCI Secure method in CRE Loaded to accept Secure credit card Payments?


And then again if this is considered deceiving and is intentional would you not be concerned with a class action lawsuit if this were true and customers found out about it! ( Oh yeah this is purely Hypothetical)

_________________
Image
http://www.dragonstailmotorsports.com/


Last edited by drm1963 on Wed Jul 15, 2009 1:03 am, edited 1 time in total.

Top
 Profile  
 
 Post subject: Re: PCI DSS - Requirement 1:
PostPosted: Wed Jul 15, 2009 1:02 am 
Offline
CRE Talented
User avatar

Joined: Sat Apr 19, 2008 3:51 am
Posts: 431
Location: Tennessee
Funny No one has took the time to address this!

Maybe there is a reason it is getting ignored!!

_________________
Image
http://www.dragonstailmotorsports.com/


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

Board index » PCI Compliance » PCI for store owners - merchants

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
It is currently Thu May 24, 2012 1:45 pm
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group

Login

Forums Latest Activity

Top Listing

1. Cart2Cart - Shopping...
    Category: Shopping Cart Database Conversion Scripts
    
2. Points & Rewards PLUS!...
    Category: Add-Ons
    
3. Configuration Server...
    Category: Fixes
    
4. Credit Card with CCV
    Category: Payment Modules
    
5. CC7333_ATS
    Category: Templates
    
Show more...

© CRE Loaded is a product of Chain Reaction Ecommerce, Inc. Usage & Privacy Policy