7 ms·
Encrypting backups makes a lot of sense. Is encrypting an active db a requirement in some enterprise environments?
by nahname 12y ago
Encrypting backups makes a lot of sense. Is encrypting an active db a requirement in some enterprise environments?
- ceejayoz 12y agoPCI compliance requires that, IIRC.
- michaelmior 12y agoBeen a while since I've had to deal with PCI, but I don't think encryption is required.
- Spooky23 12y agoIt is now. From https://www.pcisecuritystandards.org/documents/PCI_DSS_v3.pdf https://www.pcisecuritystandards.org/documents/PCI_DSS_v3.pd... PCI Requirement 3.4: Render PAN unreadable anywhere it is stored (including on portable digital media, backup media, and in logs) by using any of the following approaches: - One-way hashes based on strong cryptography, (hash must be of the entire PAN) - Truncation (hashing cannot be used to replace the truncated segment of PAN) - Index tokens and pads (pads must be securely stored) - Strong cryptography with associated key-management processes and procedures. PCI Requirement 3.5 Document and implement procedures to protect keys used to secure stored cardholder data against disclosure and misuse.
- michaelmior 12y agoPerhaps this is new in v3 since I was working under v2 at the time. It certainly makes sense that the card number must be stored encrypted.
- ceejayoz 12y agohttp://www.csoonline.com/article/2124346/compliance/end-to-end-encryption--the-pci-security-holy-grail.html http://www.csoonline.com/article/2124346/compliance/end-to-e... > Section 3 provides the high-level details around encryption. At a minimum, PCI requires the PAN (primary account number) to be rendered unreadable anywhere it is stored, including portable digital media, backup media and logs.
- randerson 12y agoIt is if you store credit card numbers.
- kolev 12y agoYes, it's 2014 and credit card numbers should not be stored and tokenization is the standard.
- vertex-four 12y agoSomebody's got to store the number eventually.
- kolev 12y agoActually, not really.
- kolev 12y agoThis new feature encrypts the entire database. PCI compliance requires only to encrypt the account number, i.e. the credit card number.
- Hovertruck 12y agoHIPAA requires encryption-at-rest of any personally identifiable information.