Enrico Lorenzi
IT-313
Instructor: Karthik Rajan
3-2 Payment Card Industry Data Security Standard
Fertilizer Plus is a small agricultural company based in Indiana, with their
production facilities in Nebraska and Oklahoma. Typically dealing with processing or
accepting credit card payments. This requires direct compliance with the Payment Card
Industry Data Security Standard (PCI DSS). This report outlines the interactions between
PCI DSS objectives and Fertilizer Plus's IT environment, identifies appropriate best
practices, and provides recommendations for management.
Our recommendations are as follows: we will need to evaluate the current security
infrastructure. In doing this, we are ensuring that workstations, network segmentation,
and firewalls/IDS/IPSs are thoroughly inspected. For employee workstations, software
upgrades will be required to replace any device that is running Windows 7 with the
current OS (Operating System). Then, isolation will be needed to isolate the cardholder
data from other networks by utilizing a demilitarized zone (DMZ). Lastly, we will then
implement advanced firewalls and intrusion detection/prevention systems. Data
protection will also need to be addressed by implementing strong encryption for both data
at rest and in transit. We will also need to implement access controls that facilitate role-
based access controls by utilizing the least privilege and multi-factor authentication for
sensitive data access. Additionally, we will need to implement unique IDs and enforce
IT-313
Instructor: Karthik Rajan
3-2 Payment Card Industry Data Security Standard
Fertilizer Plus is a small agricultural company based in Indiana, with their
production facilities in Nebraska and Oklahoma. Typically dealing with processing or
accepting credit card payments. This requires direct compliance with the Payment Card
Industry Data Security Standard (PCI DSS). This report outlines the interactions between
PCI DSS objectives and Fertilizer Plus's IT environment, identifies appropriate best
practices, and provides recommendations for management.
Our recommendations are as follows: we will need to evaluate the current security
infrastructure. In doing this, we are ensuring that workstations, network segmentation,
and firewalls/IDS/IPSs are thoroughly inspected. For employee workstations, software
upgrades will be required to replace any device that is running Windows 7 with the
current OS (Operating System). Then, isolation will be needed to isolate the cardholder
data from other networks by utilizing a demilitarized zone (DMZ). Lastly, we will then
implement advanced firewalls and intrusion detection/prevention systems. Data
protection will also need to be addressed by implementing strong encryption for both data
at rest and in transit. We will also need to implement access controls that facilitate role-
based access controls by utilizing the least privilege and multi-factor authentication for
sensitive data access. Additionally, we will need to implement unique IDs and enforce