 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Regulatory Compliance, Governance and Security &#187; CIS</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/compliance-governance/tag/cis/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/compliance-governance</link>
	<description></description>
	<lastBuildDate>Thu, 10 Mar 2011 15:04:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>PCI DSS Compliance &#124; Understanding Requirement 1</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-understanding-requirement-1/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-understanding-requirement-1/#comments</comments>
		<pubDate>Sun, 17 May 2009 21:36:08 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[CIS]]></category>
		<category><![CDATA[e-commerce]]></category>
		<category><![CDATA[firewalls]]></category>
		<category><![CDATA[internet access]]></category>
		<category><![CDATA[Network Diagrams]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[Requirement 1: Install and maintain a firewall configuration to protect cardholder data]]></category>
		<category><![CDATA[routers]]></category>
		<category><![CDATA[rule sets]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[untrusted networks]]></category>
		<category><![CDATA[wireless networks]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-understanding-requirement-1/</guid>
		<description><![CDATA[PCI DSS Compliance is growing at an astonishing rate for merchants and service providers throughout the country and the globe. Let&#8217;s take some time to distill each of the twelve (12) core Payment Card Industry Data Security Standards (PCI DSS) Requirements. This will be the first in a 12 part series of giving you a [...]]]></description>
				<content:encoded><![CDATA[<p>PCI DSS Compliance is growing at an astonishing rate for merchants and service providers throughout the country and the globe.</p>
<p>Let&#8217;s take some time to distill each of the <strong><a href="http://www.pciassessment.org/12-pci-dss-requirements.php">twelve (12) core Payment Card Industry Data Security Standards</a></strong> (PCI DSS) Requirements. This will be the first in a 12 part series of giving you a better understanding of each of the requirements and the sub-requirements for each. </p>
<p>Build and Maintain a Secure Network<br />
Requirement 1: Install and maintain a firewall configuration to protect cardholder data</p>
<p>As stated by the Payment Card Industry Data Security Standards Requirements: All systems must be protected from unauthorized access from untrusted networks, whether entering the system via the Internet as e-commerce, employees’ Internet access through desktop browsers, employees’ e-mail access, dedicated connection such as business to business connections, via wireless networks, or via other sources. Often, seemingly insignificant paths to and from untrusted networks can provide<br />
unprotected pathways into key systems. Firewalls are a key protection mechanism for any computer network.&#8221;</p>
<p>Okay, fair enough and with that said, as a <strong><a href="http://www.pciassessment.org">Payment Card Industry Qualified Security Assessor</a> </strong>(PCI QSA), here&#8217;s what you need to be aware of for Requirement 1:</p>
<p>1. Have in place an excellent network topology diagram.<br />
2. Make sure you develop the documented policies and procedures that are being called for in Requirement 1<br />
3. When deploying and hardening network devices, (routers, firewalls,etc.), please keep in mind that you need to be documenting this process along with utilizing industry accepted configuration guidelines , such as SANS, NIST, CIS.</p>
<p>This is just a start and by no means all the items for Requirement 1, but being aware of these issues will greatly help you meet the guidelines for PCI DSS Requirement 1.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-understanding-requirement-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
