We help IT Professionals succeed at work.

Check out our new AWS podcast with Certified Expert, Phil Phillips! Listen to "How to Execute a Seamless AWS Migration" on EE or on your favorite podcast platform. Listen Now

x

PCI Compliance Proxy server requirement 1.3

Medium Priority
1,948 Views
Last Modified: 2013-11-15
We are attempting to become PCI compliant.

I am looking for some guidanve and experience for requirement 1.3.

1.3 - 'Prohibit direct public access between the internet and any system component in the card holder data environmenty.

We have PCs on the CCD network that wish to access the internet.

For this indirect access is a a firewall running NAT and Stateful packet filtering  sufficient to meet the above requirement. or

Do we require to create a DMZ and place a proxy server in there to manage connections to the internet.

What is acceptable to a QSA.
Many thanks
Comment
Watch Question

Author

Commented:
whackamod

sorry for that, not sure how it ended up in documentum, my mistake.

Its more networking compliance standards, nothing to do with web development, thanks for your help can you tell me how to change it.
Unlock this solution and get a sample of our free trial.
(No credit card required)
UNLOCK SOLUTION

Author

Commented:
Hi Corey,

Sorry if I was misunderstood, we are level 4 not 1, self assessment with fairly limited kit at each site ( AD server , some PCs and a CCD holding application on a seperate server ).

That is great news if the firewall alone is sufficient, we are planning using the Sonicwall - with IPS service on. Because the upheaval of creating a DMZ and then having something to put in it?? would stretch our IT resource.

The interpretation of what is indirect access, is quite varied. I appreciate DMZ - proxy better, but looking to secure in as cost effective a manner as possible.
Have you seen an ASV approved setup with this config?

Many thanks


Unlock this solution and get a sample of our free trial.
(No credit card required)
UNLOCK SOLUTION

Author

Commented:
not really what i was after
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a sample view!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.