Solved

PCI Compliance Proxy server requirement 1.3

Posted on 2009-06-29
9
1,416 Views
Last Modified: 2013-11-15
We are attempting to become PCI compliant.

I am looking for some guidanve and experience for requirement 1.3.

1.3 - 'Prohibit direct public access between the internet and any system component in the card holder data environmenty.

We have PCs on the CCD network that wish to access the internet.

For this indirect access is a a firewall running NAT and Stateful packet filtering  sufficient to meet the above requirement. or

Do we require to create a DMZ and place a proxy server in there to manage connections to the internet.

What is acceptable to a QSA.
Many thanks
0
Comment
Question by:dbhsupport
  • 3
  • 2
9 Comments
 

Author Comment

by:dbhsupport
ID: 24743166
whackamod

sorry for that, not sure how it ended up in documentum, my mistake.

Its more networking compliance standards, nothing to do with web development, thanks for your help can you tell me how to change it.
0
 
LVL 29

Accepted Solution

by:
coreybryant earned 500 total points
ID: 24774899
Your first solution is good and the second solution using the proxy server would be better.
Most companies (ASV) will provide you a free report - you might consider having a licensed ASV do this to see if this is acceptable.  However, with you being Level 1, I would consider using the proxy server, along with a WebThreat service to help prevent any unauthorized access (maybe like BlueCoat).
0
 

Author Comment

by:dbhsupport
ID: 24783588
Hi Corey,

Sorry if I was misunderstood, we are level 4 not 1, self assessment with fairly limited kit at each site ( AD server , some PCs and a CCD holding application on a seperate server ).

That is great news if the firewall alone is sufficient, we are planning using the Sonicwall - with IPS service on. Because the upheaval of creating a DMZ and then having something to put in it?? would stretch our IT resource.

The interpretation of what is indirect access, is quite varied. I appreciate DMZ - proxy better, but looking to secure in as cost effective a manner as possible.
Have you seen an ASV approved setup with this config?

Many thanks


0
 
LVL 29

Assisted Solution

by:coreybryant
coreybryant earned 500 total points
ID: 24827862
They might approve the set-up, most will give you a free report.  It matters more on what the ASV can get through (if they can get through) to your closed system.  
You might also take a look at the self-assessment questionnaire (completed annually) to help you as well.
If you are in the United States - you have a number of options available to you.  Personally, I would stay away from First Data (and its agents).  They will charge you an annual PCI compliance fee even if you use another company to help you with PCI compliancy.  They say it can be waived, but this is after they charge you and usually they only refer a portion of the fee already accessed.  
0
 

Author Closing Comment

by:dbhsupport
ID: 31597847
not really what i was after
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

JavaScript has plenty of pieces of code people often just copy/paste from somewhere but never quite fully understand. Self-Executing functions are just one good example that I'll try to demystify here.
SSL stands for “Secure Sockets Layer” and an SSL certificate is a critical component to keeping your website safe, secured, and compliant. Any ecommerce website must have an SSL certificate to ensure the safe handling of sensitive information like…
The viewer will learn how to create and use a small PHP class to apply a watermark to an image. This video shows the viewer the setup for the PHP watermark as well as important coding language. Continue to Part 2 to learn the core code used in creat…
This tutorial will teach you the core code needed to finalize the addition of a watermark to your image. The viewer will use a small PHP class to learn and create a watermark.

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

24 Experts available now in Live!

Get 1:1 Help Now