PCI DSS FAQ - Payment Card Industry (PCI) Data Security Standard Discussion Forum  

Go Back   PCI DSS FAQ - Payment Card Industry (PCI) Data Security Standard Discussion Forum > Payment Card Industry Data Security Standard Frequently Asked Questions (PCI DSS FAQ) > Protect Cardholder Data > [PCI-DSS] Requirement 4: Encrypt transmission of cardholder data across open, public networks

[PCI-DSS] Requirement 4: Encrypt transmission of cardholder data across open, public networks Sensitive information must be encrypted during transmission over networks that are easy and common for a hacker to intercept, modify, and divert data while in transit.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 03-18-2007, 02:59 AM
admin's Avatar
admin admin is offline
Administrator
 
Join Date: Jul 2002
Posts: 229
Default [PCI-DSS] 4.1 Use strong cryptography and security protocols such as SSL/TLS or IPSEC to safeguard sensitive cardholder data during transmission over open, public networks.

[PCI-DSS] 4.1 Use strong cryptography and security protocols such as SSL/TLS or IPSEC to safeguard sensitive cardholder data during transmission over open, public networks.

Examples of open, public networks that are in scope of the PCI DSS are:
  • The Internet,
  • Wireless technologies,
  • Global System for Mobile communications (GSM), and
  • General Packet Radio Service (GPRS).
4.1.a Verify the use of encryption (for example, SSL/TLS or IPSEC) wherever cardholder data is transmitted or received over open, public networks
  • Verify that strong encryption is used during data transmission
  • For SSL implementations:
    • Verify that the server supports the latest patched versions.
    • Verify that HTTPS appears as a part of the browser Universal Record Locator (URL).
    • Verify that no cardholder data is required when HTTPS does not appear in the URL.
  • Select a sample of transactions as they are received and observe transactions as they occur to verify that cardholder data is encrypted during transit.
  • Verify that only trusted SSL/TLS keys/certificates are
  • Verify that the proper encryption strength is implemented for the encryption methodology in use. (Check vendor recommendations/best practices.)
Reply With Quote
  #2  
Old 07-23-2009, 07:09 AM
supathak supathak is offline
Junior Member
 
Join Date: Jul 2009
Posts: 1
Default

Is there any possible Compensating Control for Requirement#4?
Reply With Quote
  #3  
Old 04-27-2010, 02:09 AM
gdimitrov gdimitrov is offline
Junior Member
 
Join Date: Apr 2010
Posts: 3
Default

Should the transmission of cardholder data in the local network be encrypted? Example DB<->application and application1<->application2.

Of course all applications and the DB are isolated with firewall from the internet. There is only limited access to the servers for some administrators over secure connection, and of course there is a web interface to the application server from Internet (through some kind of transparent proxy). The DB servers are not accessible from Internet directly.

Thank you.
Reply With Quote
  #4  
Old 05-03-2010, 08:38 AM
Roger Nebel Roger Nebel is offline
Moderator
 
Join Date: Mar 2007
Posts: 43
Default Encrypting local network traffic

The current standard does not specifically require encryption of local area network traffic containing sensitive card holder data. Right now only public network traffic (i.e., the Internet) and stored data must be encrypted. However, if you look at the last few compromises they have mostly been based on local area network sniffing of unencrypted traffic. Yes, malware was allowed in and, yes, data was allowed out - both of which are banned by PCI. In my opinion encrypting local area network traffic which includes sensitive card holder data should be a requirement.
Reply With Quote
Reply

Bookmarks
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
[PA-DSS] 12.1 If the payment application sends, or facilitates sending, cardholder data over public networks, the payment application must support use of strong cryptography and security protocols such as secure sockets layer (SSL) / transport layer security (TLS) and, internet protocol security (IPSEC) to safeguard sensitive cardholder data during transmission over open, public networks.Examples of open, public networks that are in scope of the PCI DSS are the Internet, WiFi (IEEE 802.11x), global system for mobile communications (GSM), and general packet radio service (GPRS) admin [PA-DSS] 12. Encrypt sensitive traffic over public networks 0 03-18-2007 02:53 AM


All times are GMT -4. The time now is 06:45 AM.


All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest ©1997 - 2010 by PCIDSSFAQ.ORG, except where noted otherwise.
Powered by vBulletin, Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
PCI-DSS Forum  |  PA-DSS Forum