PCI ISA Training
Scoping Review
Systems Providing Security Services
Systems supplying protection offerings as required via PCI DSS, or that can be contributing to
how an entity meets PCI DSS requirements may additionally consist of:
-Authentication servers (e.G. LDAP)
-Time management (e.G. NTP) servers
-Patch deployment servers
-Audit log storage and correlation servers
-Anti-virus control servers
-Routers and firewalls filtering network traffic
-Systems acting cryptographic and/or key management features
-Systems controlling and/or monitoring physical get right of entry to
PCI DSS scope includes:
-People
-Processes
-Technology
Scoping: People
Examples of roles that can be protected in scope of assessment:
-Cashiers and sales clerks
-Back-workplace clerks
-Call center operators
-Systems and network directors
-IT help personnel
-Application developers
-Key custodians
-Human assets
-Information safety officials
-Physical safety officers
-Customer aid
-Accounting/finance employees
,-Supervisors/managers for each place
-Senior management and executives
Scoping: Processes
Examples of strategies associated with price processing:
-Regular payment processing channels
-Payment cancellations and chargebacks
-Back-up and fail-over processes
-Reconciliation, periodic reporting
-Distribution and garage of paper reviews and different bodily media
-Legacy procedures and records shops
-Onboarding methods for brand spanking new employees
Examples of helping processes:
-Authorizations and approvals for gadget get admission to
-Firewall review processes
-Change management
-Scheduling of protection patch deployments
-System constructing and configuration
-Identifying and escorting traffic
-Performing log evaluations
-Processes for reporting potential protection incidents
-Security policy updates
Scoping: Technology
Examples of types of technology:
-Servers, applications, networks, devices
-Physical protection structures
-Logical safety structures
-Payment terminals and point of sale structures
-Electronic communications
-Backups and disaster recovery "warm" websites
-Telecommunications: POTS vs. VoIP
-Management systems
-Remote get entry to systems
Sampling
Sampling is an option for assessors to facilitate the evaluation method.
- Sampling is NOT used to put into effect PCI DSS necessities or to select
, requirements to be assessed
Principles of sampling:
- Sample ought to be consultant of the complete population
- Consider business facilities and device additives
- Samples of gadget additives need to encompass all combinations
- Samples have to be large enough to offer guarantee that controls are implemented as
predicted
- Assessor's sampling methodology documented in ROC
Planning for the Assessment
Pre-evaluation planning can also encompass:
-List of interviewees, gadget components, documentation, centers
-Ensure assessor is acquainted with technologies covered in assessment
-If sampling, verify sample choice and size is representative of the whole populace
-Identify the jobs and the people within each function to be interviewed as a part of the
assessment
Sampling Scenario
What to do not forget?
-What are the distinctive OS/database combinations at each facility?
-Is every OS/database mixture used for the identical purpose?
-Is each OS/database aggregate configured the same way?
-If they're configured the equal manner, how is this demonstrated?
-Do the unique locations comply with one single set of operational and safety processes, or do
they each have their own?
-If they comply with the identical strategies, how is this demonstrated?
-Which facilities/components were reviewed inside the preceding assessment?
Sampling isn't just about technology
Assessment Time and Duration
Allow enough time to carry out the assessment
-Size and complexity of surroundings
-Number of people, techniques and device components to be reviewed
-Travel time to centers being reviewed
Reassessment
Scoping Review
Systems Providing Security Services
Systems supplying protection offerings as required via PCI DSS, or that can be contributing to
how an entity meets PCI DSS requirements may additionally consist of:
-Authentication servers (e.G. LDAP)
-Time management (e.G. NTP) servers
-Patch deployment servers
-Audit log storage and correlation servers
-Anti-virus control servers
-Routers and firewalls filtering network traffic
-Systems acting cryptographic and/or key management features
-Systems controlling and/or monitoring physical get right of entry to
PCI DSS scope includes:
-People
-Processes
-Technology
Scoping: People
Examples of roles that can be protected in scope of assessment:
-Cashiers and sales clerks
-Back-workplace clerks
-Call center operators
-Systems and network directors
-IT help personnel
-Application developers
-Key custodians
-Human assets
-Information safety officials
-Physical safety officers
-Customer aid
-Accounting/finance employees
,-Supervisors/managers for each place
-Senior management and executives
Scoping: Processes
Examples of strategies associated with price processing:
-Regular payment processing channels
-Payment cancellations and chargebacks
-Back-up and fail-over processes
-Reconciliation, periodic reporting
-Distribution and garage of paper reviews and different bodily media
-Legacy procedures and records shops
-Onboarding methods for brand spanking new employees
Examples of helping processes:
-Authorizations and approvals for gadget get admission to
-Firewall review processes
-Change management
-Scheduling of protection patch deployments
-System constructing and configuration
-Identifying and escorting traffic
-Performing log evaluations
-Processes for reporting potential protection incidents
-Security policy updates
Scoping: Technology
Examples of types of technology:
-Servers, applications, networks, devices
-Physical protection structures
-Logical safety structures
-Payment terminals and point of sale structures
-Electronic communications
-Backups and disaster recovery "warm" websites
-Telecommunications: POTS vs. VoIP
-Management systems
-Remote get entry to systems
Sampling
Sampling is an option for assessors to facilitate the evaluation method.
- Sampling is NOT used to put into effect PCI DSS necessities or to select
, requirements to be assessed
Principles of sampling:
- Sample ought to be consultant of the complete population
- Consider business facilities and device additives
- Samples of gadget additives need to encompass all combinations
- Samples have to be large enough to offer guarantee that controls are implemented as
predicted
- Assessor's sampling methodology documented in ROC
Planning for the Assessment
Pre-evaluation planning can also encompass:
-List of interviewees, gadget components, documentation, centers
-Ensure assessor is acquainted with technologies covered in assessment
-If sampling, verify sample choice and size is representative of the whole populace
-Identify the jobs and the people within each function to be interviewed as a part of the
assessment
Sampling Scenario
What to do not forget?
-What are the distinctive OS/database combinations at each facility?
-Is every OS/database mixture used for the identical purpose?
-Is each OS/database aggregate configured the same way?
-If they're configured the equal manner, how is this demonstrated?
-Do the unique locations comply with one single set of operational and safety processes, or do
they each have their own?
-If they comply with the identical strategies, how is this demonstrated?
-Which facilities/components were reviewed inside the preceding assessment?
Sampling isn't just about technology
Assessment Time and Duration
Allow enough time to carry out the assessment
-Size and complexity of surroundings
-Number of people, techniques and device components to be reviewed
-Travel time to centers being reviewed
Reassessment