Contents
What is a PCI log?
Having an audit trail is an important part of the Payment Card Industry Data Security Standard (PCI DSS). Log files contain information about security events, network resources, event logs, system components, and suspicious activity. Protecting cardholder data is one of the key tenants of PCI DSS compliance.
What is PCI in protecting information?
A: The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that ALL companies that accept, process, store or transmit credit card information maintain a secure environment.
Why the PCI DSS is considered either a standard or a framework?
PCI DSS stands for Payment Card Industry Data Security Standard. This compliance framework is an industry-mandated set of standards intended to keep consumers’ card data safe when it is used with merchants and service providers.
Why was logging not required before the PCI DSS?
Prior to the PCI DSS, “logging” (i.e., maintaining a historical account of the people and activity associated with an information network) was not something most organizations regarded as necessary, because they did not consider it to be integral to the protection of cardholder data.
What does PCI mean for a wireless network?
PCI is focused on protecting cardholder data. Therefore, networks and devices that are appropriately segmented from the cardholder data environment (CDE) will not be in scope for the audit.
How is network segmentation related to PCI DSS?
Note that when technologies are used to manage access between systems and networks for purposes of meeting PCI DSS requirements, this is not considered segmentation that reduces PCI DSS scope. While still in scope for PCI DSS, these communications are potentially more secure than uncontrolled communication channels.
What do you need to know about PCI compliance?
The following list of requirements focus on Wi-Fi infrastructure compliance, and do not cover other related systems, such as servers, user database and directory policies, firewall policies, client device hardening, etc., that may or may not be covered by the same engineering group in your organization but wireless networks rely upon.