5 ms·
How serious is that certification? Is it a bureaucracy certification with some vintage requirements or is it something that keeps adapting to the changes in the
by pothibo 12y ago
How serious is that certification? Is it a bureaucracy certification with some vintage requirements or is it something that keeps adapting to the changes in the technology environment?
- falcolas 12y agoPCI is a voluntary certification which is more or less toothless. You can pass a PCI, and still be terribly vulnerable in a myriad of ways. Also, PCI certification of the environment doesn't make you, the end user, PCI certified.
- grandalf 12y ago> PCI is a voluntary certification which is more or less toothless. You can pass a PCI, and still be terribly vulnerable in a myriad of ways. Less so with PCI DSS 3.0 SAQ A-EP, which probably results in e-commerce sites using Cloudflare failing that SAQ.
- haswell 12y agoAbsolutely correct. I worked at one of the "big 4" fully PCI compliant/validated credit card companies for years, and while I do not feel comfortable getting into specifics, it shocked me how many potential vulnerabilities I observed over the years. Many emails to INFOSEC were written.
- adrr 12y agoPCI is always done on scope. What part of system the PANs are touching. So your CDN is just one part of where PANs can pass through and next is the system that sends it out to the network. And if you store the PAN, then the DB. Also is not voluntary, your merchant account will enforce it. PCI is all self assessment till you hit level 1, then you have to bring an auditor in and they'll go over all your systems that handle the PANs and ensure they are PCI compliant. Its not an easy task. PCI 3.0 is coming out with helps deal with target like breaches which ensures compliance continuity, so its no longer a point of time like the past.
- cesther 12y agoPCI DSS is not voluntary if you transmit, store or process credit cards. It is enforced through contract, typically for a merchant through their relationship with their bank, for service providers via the contract with the merchant.
- lambersley 12y agoIts quite important. Any business that processes or stores credit card transactions for AMEX, Visa and Discover cards automatically fall under the jurisdiction of PCI, whether the business wants to or not. PCI has the authority to levy huge fine against businesses for failure to maintain its Data Security Standards. Small eComm businesses can easily falter at the financial pressures. I've seen major businesses elect to simply pay the fines as implementing PCI DSS can be quite costly in large, legacy environments.
- michaelmior 12y agoI don't think the OP was questioning the practical need to be PCI-compliant. I think the question was as to how useful PCI actually is at protecting users. (i.e. does it actually prescribe best practices or is it just smoke and mirrors)
- adrr 12y agoIts pretty decent. It has requirements on logging including kernel level logging. The ASV tests are pretty through in terms of testing for known vulnerabilities. I failed my first ASV test because my allowed ciphers where vulnerable to the BEAST attack.
- peterwwillis 12y agoIt does change over time and get updated every year, but it's always been kind of a joke. You're basically filling out a form that says "I'm pretty sure i'm secure", you get port scanned, somebody comes to your business to verify you didn't make the whole thing up [if you are Level 1], and you eventually get some official stamps of approval. Amazingly it can cost up to a half million dollars to go through the whole process for Level 1. Quite the tidy industry.
- freehunter 12y agoIt can be a joke, but it's a good way to get senior leadership onboard with new security technologies. "It helps with PCI" and the check is signed.
- smackfu 12y agoIt ensure you are doing bare minimum best practices, like not sharing user ids and using encryption. It's sad that any company dealing with credit card data could fail, but not surprising.
- ef4 12y ago> Is it a bureaucracy certification with some vintage requirements or is it something that keeps adapting to the changes in the technology environment? That's not really an "or" question. It is a bureaucracy-oriented standard that focuses mostly on whether you have the right policies in place in all the right topic areas. But it also adapts reasonably well to changing technology -- because it actually has relatively little to say about specific technologies.
- deleted 12y ago[deleted]
- tzs 12y agoIt changes. For instance, earlier versions were written under the assumption that if you were doing your own credit card processing it was on dedicated physical servers you owned or leased, and that these servers were either in a facility exclusively for your use or if they were in a shared data center they were in locked cage that you had exclusive access to. It was not possible to meet the requirements if you were doing your processing on Amazon ECS or similar services. There was even some question over whether or not you could meet PCI requirements using your own virtualization. If two things are supposed to be on separate networks, but those two networks are actually virtual networks between virtual machines running on the same physical host, did that count? Later versions took into account virtualization. It became possible to do credit card processing and storage on ECS and similar services if they had the appropriate PCI certification. (Note: you still have to have your own certification. The certification of places like Amazon and CloudFlare just means that it is possible to use them in your credit card processing architecture and still get certified).
- lsh123 12y agoIt depends on how you approach it. You can pass the certification just with checkboxes/paperwork or you actually try to understand the reasoning behind requirements to make things better.
- adrr 12y agoPCI level 1 is more than checkboxes. Its an independent auditor coming in to confirm compliance.
- lsh123 12y agoBeen there, done that. Still a lot of checkboxes. The auditor will not likely to really understand the details of your setup. E.g. you can install firewall with all ports open, then document this setup, justified business reasons. And then it is technically enough to complete section 1. Of course it would not anything extra to your security.
- 0xdeadbeefbabe 12y ago> Is it a bureaucracy certification with some vintage requirements Yes, but vintage in computer security could be as little as 1 year ago. > is it something that keeps adapting to the changes in the technology environment? Somewhat, but threats to its own existence take a higher priority. Don't expect PCI flunkies to get excited about bitcoin, for example, or even stripe.