preview

Evaluation Of Pci Dss Compliance Requirements

Decent Essays

PCI DSS compliance requirements, imposes in a number of areas segregation of duties aiming to protect card holder data. The idea behind this requirement is that, if more people are involved, the less likely that human error will occur and there is less chance to commit fraud or unintentional damage from one person, therefore security will be maintained.
PCI DSS requires to have segregation of duties and separation of development and production environment, aiming to put limitations on accessing card holder data and restrictions on moving data from one environment to other because of risk of exposing card holder data.
PCI DSS provide guidance on creating clear separation of data within the network, cardholder data should be isolated from the rest of the network, which contains less sensitive information. To audit the PCI DSS compliance the following documents can be helpful: network policies and procedures, documentation about network configuration, network devices, and network flow diagrams. There is no complete solution on how organization should configure network and devices to ensure PCI DSS compliance, because every organization has its own business specifics and its own technology, so we say that also segregation of duties is unique for every organization. But we also may conclude that segregation of duties depends heavily on the network configuration and network devices and because of that one of areas of auditing for PCI DSS compliance is also documentation and

Get Access