Hitchhiker’s Guide to PCI DSS 2.0 Scoping (Part 3)
Cardholder Data Discovery Sampling Strategy
June 29, 2012
Views
Editor’s Note: In this post, Steve Levinson outlines sampling strategies for companies establishing their cardholder data discovery processes. This post is the third in a series of four from the “Hitchhiker’s Guide to PCI DSS 2.0 Scoping.” The first post offers a step-by-step methodology, the second post offers a strategy for cardholder data discovery, and the fourth post will provide remediation guidelines for addressing issues with discovered cardholder data.
“Retailers with thousands of in scope POS systems have often asked us if they need to perform cardholder data discovery searches on all of their retail devices (POS systems and store servers). Understandably, it is a daunting task to perform this type of search across so many systems, let alone costs associated with potential licensing costs for discovery tools could become astronomical. Critical Success Factors for Cardholder Data Discovery”
There are many instances where we have worked with retail clients to determine a sampling approach to cardholder data discovery. For those companies who maintain their retail systems on a consistent basis, it is possible to create a sampling methodology to perform cardholder data discovery. Some critical factors to consider for this approach include the following:
Please keep in mind that different QSAs may interpret this PCI requirement differently. Companies to be assessed should collaborate with their QSA prior to or early in their PCI assessment to determine that QSA’s interpretation of sampling for cardholder data scans. It will be up to the merchant to be able to demonstrate a sound approach to their QSA regarding sampling of POS systems for cardholder data.
Have you implemented a sampling methodology to perform cardholder data discovery? If so, how are you determining what entities to scan for cardholder data? What additional strategies have you employed in the event of discovery cardholder data in a sampled environment?
AT&T
Networking Exchange : Topics : Security : Hitchhiker’s Guide to PCI DSS 2.0 Scoping (Part 3)
Hitchhiker’s Guide to PCI DSS 2.0 Scoping (Part 3)
Cardholder Data Discovery Sampling Strategy
By Steve Levinson
Steve Levinson
PCI Practice Director, AT&T
Find me on:
“Retailers with thousands of in scope POS systems have often asked us if they need to perform cardholder data discovery searches on all of their retail devices (POS systems and store servers). Understandably, it is a daunting task to perform this type of search across so many systems, let alone costs associated with potential licensing costs for discovery tools could become astronomical. Critical Success Factors for Cardholder Data Discovery”
There are many instances where we have worked with retail clients to determine a sampling approach to cardholder data discovery. For those companies who maintain their retail systems on a consistent basis, it is possible to create a sampling methodology to perform cardholder data discovery. Some critical factors to consider for this approach include the following:
Please keep in mind that different QSAs may interpret this PCI requirement differently. Companies to be assessed should collaborate with their QSA prior to or early in their PCI assessment to determine that QSA’s interpretation of sampling for cardholder data scans. It will be up to the merchant to be able to demonstrate a sound approach to their QSA regarding sampling of POS systems for cardholder data.
Have you implemented a sampling methodology to perform cardholder data discovery? If so, how are you determining what entities to scan for cardholder data? What additional strategies have you employed in the event of discovery cardholder data in a sampled environment?
You might also be interested in…
Networking Exchange Blog
Get the latest posts delivered right to your inbox. [+]
Receive our daily or monthly email updates and keep current on all the hottest networking trends, perspectives and reports.
Networking Exchange Blog
Thank you for subscribing. Your alerts will be sent to . Be sure to add networkingexchange@attbusiness.com to your safe contact list.
You Might Also Be Interested In...
Networking Exchange Blog
Get the latest posts delivered right to your inbox. [+]
Receive our daily or monthly email updates and keep current on all the hottest networking trends, perspectives and reports.
Networking Exchange Blog
Thank you for subscribing. Your alerts will be sent to . Be sure to add networkingexchange@attbusiness.com to your safe contact list.