Solved

PCI and Small Business Server

Posted on 2012-03-16
1
324 Views
Last Modified: 2012-05-09
I am working with a customer needing to complete form D of PCI's SAQ.

Question 2.2.1 says is there only one primary function per server? It gives the example, are web servers, database servers and DNS servers all on separate servers.

Does this mean that a SBS would not be PCI compliant as it hosts DHCP, DNS, AD, File Server, SharePoint and Exchange all on one box?

How deep does this go? Take Exchange for instance. Exchange has a mailbox db server, a web front end and its back end.. does all this need to be separated too?
0
Comment
Question by:Schuyler Dorsey
1 Comment
 
LVL 62

Accepted Solution

by:
btan earned 500 total points
ID: 37732906
Do not really see that it need to be one service one physical machine as this can be complicated in virtual environment. The idea is ti isolate and segregate service oneinside so as thisto bescope down the ideadss involvement and segregate which can be lesser prone to copecracks due to cracksmany services running in same box. Sometimes it needis not reallycost effective and efficient to split up inherent web services...but we can harden and lockdown those ports etc. Some info on sbs  meeting pci dss

 http://social.technet.microsoft.com/wiki/contents/articles/853.adjustments-for-pci-dss-scan.aspx
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now