7 ms·
You’re absolutely right! Full disk encryption (FDE) does indeed fall short of PCI 4.0 requirements because it transparently decrypts data for anything running o
by motymichaely 2y ago
You’re absolutely right! Full disk encryption (FDE) does indeed fall short of PCI 4.0 requirements because it transparently decrypts data for anything running on the OS or accessed by the user, which isn't sufficient for finer-grained control.
PCI 4.0 demands more granular encryption authorization models, where data is either encrypted at the file or column level, or access to plain data is restricted to more specific roles than just the OS user account. This is to reduce the risk of unauthorized access.
There are a few dev-centric data protection solutions that address these requirements seamlessly. These solutions allow you to store and encrypt any type of data with simple APIs while transparently managing keys, rotation, and granular access controls.
I am currently evaluating Piiano Vault (https://www.piiano.com/pii-data-privacy-vault https://www.piiano.com/pii-data-privacy-vault) as one such solution for a new product that I am currently working on that would require a PCI compliant zero-data solution. Seems like its delivery model is very flexible - it can be fully self-hosted or consumed as a managed SaaS, providing robust data protection tailored to my specific needs.
Will update with my findings!