For PCI Compliance, simply having this remote administrative applications open to an unsecured network such as the Internet violates the PCI regulations. If you're allowing remote administration from the Internet, you'll want to configure a remote client VPN - usually done with your firewall or even Internet router. With this configuration, you can configure your firewall to not allow remote access from the Internet - which immediately brings you into compliance.
For users that do need to access internal resources from a remote system, they would connect to the VPN and then use whatever application (RDP, VNC, etc) to access the internal server.
Hope this helps...
Mike
Main Topics
Browse All Topics





by: richrumblePosted on 2009-10-21 at 13:40:55ID: 25628150
If you mean from a VPN/Remote access perspective... Neither without 2-factor authentication.
ndards.org /security_ standards/ download.h tml?id=pci _dss_v1-2. pdf
If you mean for general lan remote administration, then RDP is the clear chioce as VNC passwords are limited to 8 characters and the protocol is not encrypted by default and is mostly compressed instead of encrypted.
https://www.pcisecuritysta
Is your question is pertaining for 2.2.3, or 2.3? I have a feeling you meant 8.3 though.
-rich