
To ensure critical data can only be accessed by authorised personnel, systems and processes must be in place to limit access based on need to know and according to job responsibilities.
“Need to know” is when access rights are granted to only the least amount of data and privileges needed to perform a job.
7.1 Limit access to system components and cardholder data to only those individuals whose job requires such access. Access limitations must include the following:
7.2 Establish an access control system for systems components with multiple users that restricts access based on a user’s need- to- know, and is set to “deny all” unless specifically allowed. This access control system must include the following:
nuBridges Protect is designed to make it easier for IT to make your operations PCI DSS compliant. Here are just a few examples:
Supports two data protection methods:
The core of the PCI DSS is a group of principles and accompanying requirements, around which the specific elements of the DSS are organised:
Requirement 1: Install and maintain a firewall configuration to protect cardholder data
Requirement 3: Protect stored cardholder data
Requirement 4: Encrypt transmission of cardholder data across open, public networks
Requirement 5: Use and regularly update anti-virus software
Requirement 6: Develop and maintain secure systems and applications
Requirement 8: Assign a unique ID to each person with computer access
Requirement 9: Restrict physical access to cardholder data
Requirement 10: Track and monitor all access to network resources and cardholder data
Requirement 11: Regularly test security systems and processes
Requirement 12: Maintain a policy that addresses information security
Network Access Control Partners
ForeScout’s clientless network access control (NAC) solutions enable customers to gain complete control over network security without disrupting end-user productivity. ForeScout’s CounterACT combines NAC and signature-less intrusion prevention in a single network appliance that interrogates and controls access of every device and seamlessly integrates with any existing IT infrastructure. ForeScout’s NAC is completely transparent and enables enterprises to tailor enforcement to match the level of policy violations, eliminating disruptions during device interrogation.
Evidian Identity and Access Management with dynamic access control and SSO. Evidian software helps you to deploy a global security policy and service level management capability, through identity and access management and service level management software suites
© Copyright Castleforce 2007-2012. Web design by Theme Group