Home > Information Security Tips > Compliance and regulations > Wireless network guidelines for PCI DSS compliance
Security UK Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE AND REGULATIONS

Wireless network guidelines for PCI DSS compliance


Ben Rothke, Contributor
10.13.2009
Rating: --- (out of 5)


Security UK Tips and Expert Advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


In July, the PCI Security Standards Council released its PCI DSS Wireless Guidelines (.pdf), which provide an excellent set of details on how organizations that use or seek to implement 802.11 Wi-Fi networks can ensure they comply with the PCI DSS requirements. While the Payment Card Industry Data Security Standard (DSS) specification provided the base details, many organizations found they needed more specifics on how WLANs affect PCI DSS compliance.

The new document provides guidance and installation suggestions in areas such as how to limit the PCI DSS wireless scope and practical methods for deployment of secure wireless networks in payment environments. But there is a lot more to wireless security than what is written in the 33-page document. In this tip, we'll examine how the new Wi-Fi guidance enables PCI DSS compliance, and some additional best practices enterprises should put in place to not only pass a PCI DSS audit, but also better integrate security into an existing Wi-Fi network.

Do the PCI Wi-Fi guidelines help?
If one takes the guidelines' three chapters and methodically applies them to his or her wireless network, will it then be PCI DSS complaint? Ostensibly, yes. But adhering to the spirit of the mandate -- protecting sensitive electronic payment information, -- can only be ascertained via in-depth analysis of the requirements, and a plan for compliance. Many organizations struggle with the PCI DSS wireless requirements, since the DSS never detailed the security requirements for wireless networks when it was initially released. This is important as there are many new regulatory data protection requirements and standards, of which PCI DSS is one. Beyond the regulations, every organization wants to ensure its data is secure, and its wireless networks remain protected from external attacks. To most effectively design their security architectures, network managers must understand the wireless security features of the networks they are using, as well as their limitations.

Since wireless is often an add-on to an existing enterprise network, Chapter 2 addresses the Cardholder Data Environment (CDE). The PCI CDE is the computer environment wherein cardholder data is transferred, processed or stored, and any networks or devices directly connected to that environment. Organizations that add wireless capabilities to a flat network will find out that their entire network is now likely in scope for PCI DSS compliance.

Even though the PCI DSS is detailed, organizations needed more meticulous details to help them understand how to apply the DSS to their wireless environments. The guide provides that guidance and expands on the practical methods for secure deployment of wireless in payment card transaction environments.

For instance, Chapter 3 details the specific wireless requirements for PCI DSS and general networking. The guidelines note that an entity must comply with the wireless requirements, even if they do not use wireless as part of their CDE. This is needed as the PCI DSS doesn't state how easy it is for someone to establish a rogue wireless access point on a network. When a wireless access point is enabled, it will often have an Ethernet connection tied into some part of the payment network. The wireless access point can then enable an attacker to bridge the connections and gain access to the payment network.

The guide concludes with Chapter 4. It offers applicable requirements for in-scope wireless networks, which details each of the specific requirements. Chapter 4 is the most detailed chapter in the guide and provides the most technical information on the specifics of securing wireless networks. Key points of the chapter include the recommendation to disable all unnecessary applications, ports and protocols, to not advertise organization names in the SSID broadcast, and more.

Beyond the guidelines
The PCI DSS Wireless Guidelines is a valuable document, but the underlying issue is that the recommendations written should have been implemented before any wireless network was deployed. Organizations that are serious about wireless and security should go beyond the guidelines and take the following steps:

  • Architecture -- Ensure the wireless security architecture is centrally controlled, with coordinated access points that are resistant to attack by securely configuring them and ensuring they are patched.
  • Network diagrams -- These are always valuable, but are even more crucial in a PCI environment. Ensure your wireless network diagrams detail the locations of any wireless devices on the network. Once that is done, validate the network diagram using wireless scanning tools. You can use free open source tools such as NetStumbler or Kismet, or more powerful commercial tools such as those offered by Motorola Inc.'s AirDefense unit or AirMagnet Inc.
  • Data mapping -- Many organizations seek to guarantee that no cardholder data goes over wireless. But the only way to verify that is by mapping the data. By documenting how credit card transaction data flows over the network, you can then determine if it is going over the wireless network, which would then be in scope from a PCI perspective.
  • Maintaining compliance -- The hardest aspect is maintaining PCI compliance, as it requires constant vigilance. Ensure you have detailed security and compliance management processes to ensure the wireless networks will remain PCI compliant.

About the author:
Ben Rothke CISSP, PCI QSA, is a Senior Security Consultant with BT Professional Services and the author of Computer Security: 20 Things Every Employee Should Know (McGraw-Hill).


Rate this Tip
To rate tips, you must be a member of SearchSecurity.co.UK.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Compliance and regulations
Encryption basics: How asymmetric and symmetric encryption works
SIEM systems streamline compliance processes, offer security benefits
Tips to achieve PCI compliance
How to choose an external compliance auditor
Using a privacy impact assessment template for DPA compliance
PCI DSS checklist: Mistakes and problem areas to avoid
The elements of a compliance-oriented architecture
PCI DSS requirement: Implement strong access control procedures
How to choose full disk encryption for laptop security, compliance
PCI DSS compliance requirements: Ensuring data integrity

Compliance Regulation and Standard Requirements
PCI DSS requirements still baffling as compliance deadline approaches
Make PCI DSS compliance easier by reducing scope, outsourcing data
Cloud computing compliance: Exploring data security in the cloud
Encryption basics: How asymmetric and symmetric encryption works
SIEM systems streamline compliance processes, offer security benefits
No major PCI DSS revision expected in 2010
PCI QSAs, certifications to get new scrutiny
Tips to achieve PCI compliance
PCI DSS requirements: Get ready for stricter enforcement, fines
Data Protection Act breach could cost companies 500,000 pounds

Wireless Network Security: Setup, Issues and Threats
Configuring a Windows network infrastructure: Wired, wireless security
College learns lessons in choosing the right NAC appliance
GSM cell phone encryption crack may force operators to upgrade
How to keep networks secure when deploying an 802.11n upgrade
Researchers find thousands of flawed embedded devices
SMS attacks against BlackBerry certificate bug possible
Remote phone lock and GPS tracking counter smartphone security risks
Mobile device encryption a must, says Information Commissioner
MMS messaging spoof hack could have global ramifications
Five steps to eliminate rogue wireless access

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Basel II  (SearchSecurityUK.com)
Code of Connection (CoCo)  (SearchSecurityUK.com)
EU Data Protection Directive  (SearchSecurityUK.com)
Financial Services Authority  (SearchSecurityUK.com)
IFRS (International Financial Reporting Standards)  (SearchSecurityUK.com)
UK Identity Cards Act  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



UK Data Security Solutions: Data Privacy, Identity Theft, Data Loss
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts