PCI Compliance

I need to setup a Cisco ASA 5505 for PCI compliance in a very small retail business. They have 4 I/P credit card readers. My question is, would it be compliant to segment the card readers on a separate 8 port switch and assign that to a DMZ? If so, what security level, 50 or something else?
I am open to any ideas presented.
Dennis PillowAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

JohnBusiness Consultant (Owner)Commented:
You get compliance certification through the bank or financial institution responsible for the card (or cards). You have to follow their certification procedures. You cannot do it yourself.
Dennis PillowAuthor Commented:
Interesting, I was told that I was responsible for the setup.
JohnBusiness Consultant (Owner)Commented:
You would have to follow the compliance steps (that is maybe what was meant when you were told), but the requirements are specific and established by the financial institution. They are responsible for final certification . The time to certify is often measure in months.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
The 7 Worst Nightmares of a Sysadmin

Fear not! To defend your business’ IT systems we’re going to shine a light on the seven most sinister terrors that haunt sysadmins. That way you can be sure there’s nothing in your stack waiting to go bump in the night.

Dennis PillowAuthor Commented:
In understand completely now. This is becoming a very confusing side of retail business. It seems that I have been thrown into this whether I want to or not. I do support my customers fully.
JohnBusiness Consultant (Owner)Commented:
Thanks for the update and I was happy to help.
Dennis PillowAuthor Commented:
Your welcome. I know where to get great advice to help with some of the simplest issues.
JohnBusiness Consultant (Owner)Commented:
Here is a decent starting point for you. It has a good overview and supporting links.

https://www.pcisecuritystandards.org/security_standards/
Dennis PillowAuthor Commented:
Thank you John.
JohnBusiness Consultant (Owner)Commented:
You are most welcome and I am glad I could help.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Network Security

From novice to tech pro — start learning today.