by Ben Rothke and David Mundhenk

A guide to practical PCI compliance

News
Nov 16, 200710 mins

Myriad merchants find themselves at the end of the PCI compliance barrel and are spending significant amounts of time, money and effort in achieving PCI compliance. Advice from companies that have been there can help smooth your path.

One of the biggest mistakes organizations make is jumping into their PCI remediation effort without first understanding their company’s gaps. It’s crucial to realize that every organization has a different maturity level when it comes to technology and compliance. Without first knowing what level you are at, taking a “one size fits all” approach to fixing PCI will spell disaster.

A pre-compliance assessment is imperative and enables you to understand what your PCI compliance effort will entail. The output is a document identifying gaps between your current state and what the PCI DSS (Data Security Standard) requirements necessitate.

Some of the items covered in the pre-compliance assessment include:

— Review of IT infrastructure; PCI-relevant application architecture, policies, procedures and processes; overall network design

— Gap analysis

— Network vulnerability scanning

— Risk analysis

— Mapping business flows to technology flows

Determine your current state by completing the PCI Self-Assessment Questionnaire (SAQ) from the PCI Security Standards Council. The SAQ is divided into six sections focusing on a specific area of security. After completing the SAQ, you will have a good idea of which controls and tools are in are in place.

Cross-Organizational Interaction

PCI requires the whole organization to play nicely together; too many organizations have different IT groups that have developed their own fiefdoms and act in semi-autonomous states. PCI doesn’t support such an approach–it requires different groups to collaborate whether they like it or not.

Success with PCI is dependant on how the numerous groups work together and maintain reasonable expectations. How well this is executed has a direct impact on compliance. The best way to ensure understanding is to set effective ground rules at the beginning of the compliance effort.

Vendor Remediation Support

Your organization has older software and hardware that isn’t PCI-compliant. Similar to preparing for Y2K, getting vendors to ensure their products comply with PCI can be a significant issue. How much of an issue depends on your importance to the vendor and the importance of PCI to the vendor.

If you find that your vendor is not PCI compliant and you need an alternative solution, the PCI Security Vendor Alliance (SVA) is a good resource to check. The SVA assists the payment card industry by providing products and services that enable organizations to achieve compliance with the PCI DSS.

PCI Project Manager

Appointing an internal project manager (PM) assists in PCI efforts. The benefit is that one internal point of contact can own the project and be responsible for ensuring its success. The appointed individual can only be as successful as the support they have been afforded. Without senior management support, the process of acquiring additional money and resources to address assessment findings will take significantly longer and cost more than necessary. Additionally, PCI-imposed changes to IT infrastructure and business process requires the full support of mid-level managers and the in-house expertise of senior and junior technical personnel.

A dedicated PCI PM can take responsibility for identifying and communicating PCI compliance requirements, mapping existing organizational skill sets to required mitigation tasks and tracking tasks as they move toward completion. The PM also schedules regular meetings to assess project progress and provide regular updates to project plans and reports.

Outsourcing PCI Remediation

Achieving PCI compliance may require organizations to restructure not only their IT environment but also significantly retool their business processes. Trying to factor PCI compliance into existing plans and programs may tax existing personnel and budgets; it’s not uncommon for staffing to be optimized to a point where it’s not feasible to accommodate increased workloads. In such cases, it may be worthwhile to consider outsourcing PCI project management and other functions around PCI remediation.

Reducing PCI scope

Reducing the scope of a PCI assessment is often advocated when the recommended changes to the environment have become cost prohibitive or will adversely impact the business or organizational mission.

Some merchants have constructed their POS applications and associated infrastructure with an aggressive eye toward reducing costs at every turn. Often, this infrastructure has evolved to be comingled with non-PCI systems that may have been designed with little or no thought to protecting sensitive information. If there is little or no separation between these systems then PCI requirements will apply to all of the systems within this environment.

Re-architecting such an environment to support PCI-related system hardening requirements–such as monitoring, logging and auditing–may be cost prohibitive. In such instances, it’s reasonable to consider moving the PCI systems into their own dedicated environment and limiting their interaction with non-PCI technology. This helps reduce the number of critical systems to be reshaped into compliance and will enhance security by placing them in a controlled and monitored environment.

The DSS reinforces the concept of segmentation between PCI and non-PCI systems. While it doesn’t specifically mention virtual local areas networks (VLAN) per se, it’s often useful to implement network architecture such that it provides separate, dedicated virtual networks for PCI components. This can be accomplished via a combination of VLANs and network routing that helps to contain and secure PCI systems, and also minimizes their interactions with non-PCI systems.

A good example of this is a business that has multiple locations containing numerous Point of Sale (POS) systems that send the results of its daily transactions back to a server across dedicated private network connections. The DSS requires implementation of intrusion detection systems (IDS) and firewalls to protect cardholder data being stored, processed or transmitted. Effective solutions around this include routing and VLAN configurations that restrict access between the retail store PCI networks. In this scenario there would be no network access allowed between the retail location networks. In addition, PCI systems would be deployed on dedicated VLANs within the retail locations and logically separated via router-based access control lists from non-PCI networks. Firewall-based segmentation and IDS could then be implemented at that single communication aggregation point into the corporate network infrastructure. In this scenario, PCI-based event logging requirements would still apply for all PCI systems at their corporate and retail locations; the costs of implementing the required segmentation, however, would be significantly less.

Remediation project plan

A PCI remediation project plan is needed following a PCI gap or self-assessment. The findings and recommendations can be numerous and overwhelming; it’s important to review and thoroughly understand the implications of the gap assessment results.

Once potential solutions have been identified and agreed upon, the tasks are populated into a Microsoft Project or other appropriate electronic document. The tasks should then be prioritized based on business and organizational objectives; personnel can be assigned various tasks based on subject matter expertise and scheduling availabilities.

Project status meetings

To keep the remediation effort on track, it’s extremely beneficial to have regular project status meetings. The frequency of the meetings is dependent on numerous factors such as compliance deadlines, availability of personnel and resources, change control and maintenance requirements, etc. The PM should schedule and be the moderator of the project status meetings.

Personal productivity can also be impacted by attending unnecessary meetings. Keep the PCI remediation project status meetings on track and conduct the technical discussions on a very high level by reviewing whether a given task has been completed, briefly discussing any possible roadblocks and recording updates to task status with respect to individual efforts.

When detailed discussions become necessary, it’s often valuable to assign a three minute to five minute time limit. If the issues cannot be resolved within that time frame, take those discussions offline to be resolved.

When each meeting is completed, the PM should update the project plan based on detailed notes, task assignments and updated requirements. The project plan should then be disseminated to all those participating in the remediation effort.

Pre-assessments

Performing a pre-assessment prior to the anticipated visit of the PCI Qualified Security Assessor (QSA) is a valuable exercise. It’s also important to have a follow-up meeting after a pre-assessment as this allows the project team to review and discuss the findings and get a head start on remediating items that the QSA might eventually find.

Obtain Compliant ROC and Submit to Appropriate Entities

Following the final PCI assessment and once the all of the relevant PCI assessment items have been fully mitigated, the QSA will then produce the final Report on Compliance (ROC). This report shows that all of the required compliance criteria are “in place” within the given environment. If there are any items not marked “Not In Place,” the report cannot be submitted. The processor, acquiring bank or card brand will reject it.

When to Begin Planning for Next Year’s ROC

Following the initial certification, it’s important to begin planning for the next year’s impending PCI assessment. Achieving initial compliance often requires significant organizational and business process changes, and additional capital investment. It may also require some measurable preplanning to maintain compliance in the face of impending new PCI requirements.

Production applications can rarely be retooled in short order. Merchants with Web-facing e-commerce applications should seriously consider a lead time of six months to nine months to redevelop, fully test and deploy them within the production environment to maintain compliance.

PCI real-world lessons

The ultimate success around PCI depends on how committed management is to it. If management cares, your organization is likely to have had effective security in the first place, and it’s likely you can achieve PCI compliance in the short term. If management doesn’t care or is clueless, your organization’s security is likely already in the hole and PCI failure is inevitable.

Organizations that have had the most success in their PCI efforts have done so by approaching PCI from a risk-driven model. Such an approach enables resources to be prioritized around business risks, which ensures that resources allocated are directly in line with those that contribute to the achievement of corporate objectives.

Such an approach is the cornerstone for an effective PCI compliance program management system. This is a formal system of risk management which can show that the PCI requirements and resulting work have been adequately planned and supervised. Notice that the operative word here is formal. A few IDS sensors rolled-out over the previous weekend don’t display that, nor do security hardware and software systems deployed without proper policies, documentation, administrator training, etc.

Finally, the cruel reality of compliance has shown that there are instances where management, upon notice of the impending audit failure, will respond by firing various people in the security group. In many cases, they may ask the remaining staff to lie to pass the audit. For the individual, this presents the dilemma of truth versus having a job.

If one finds themselves in such a situation, immediately seek legal counsel. According to Louis Brilleman, counsel at Sichenzia Ross Friedman Ference in New York City, a law firm specializing in securities and regulatory matters, “If management asks you or pressures you to sign off on something that is false, they may expose themselves to a charge of intimidation–a criminal offense in most jurisdictions–when coupled with a threat of termination. In such a case, you should seek legal counsel since complying with management’s request will make the person an accomplice that could potentially result in fines and jail sentences.”

Just the basics

Nearly everything in PCI can be considered security 101. It is therefore surprising how people are intimidated by the various PCI requirements. But PCI, like information security, is simply attention to detail and good design, combined with good project management. If you follow those disciplines for your PCI remediation effort, your chances of passing the PCI compliance effort are greatly increased.

Ben Rothke, CISSP, QSA, is a security consultant with BT INS and the author of Computer Security: 20 Things Every Employee Should Know (McGraw-Hill, 2006).

David Mundhenk, CISSP, QSA, is a security consultant with a major professional services firm.