GUIDE FOR REQUIREMENTS 7, 8, AND 9: IMPLEMENT STRONG ACCESS CONTROL MEASURES

Requirement 7: Restrict access to cardholder data by business need to know

To ensure critical data can only be accessed by authorized personnel, systems and processes must be in place to limit access based on need to know and according to job responsibilities. “Need to know” is when access rights are granted to only the least amount of data and privileges needed to perform a job.

Requirement Guidance
7.1 Limit access to system components and cardholder data to only those individuals whose job requires such access. Access limitations must include the following:
7.1.1 Restriction of access rights to privileged user IDs to least privileges necessary to perform job responsibilities
7.1.2 Assignment of privileges is based on individual personnel's job classification and function
7.1.3 Requirement for an authorization form signed by management that specifies required privileges
7.1.4 Implementation of an automated access control system
The more people who have access to cardholder data, the more risk there is that a user's account will be used maliciously. Limiting access to those with a strong business reason for the access helps your organization prevent mishandling of cardholder data through inexperience or malice. When access rights are granted only to the least amount of data and privileges needed to perform a job, this is a called “need to know,” and when privileges are assigned to individuals based on job classification and function, this is called “role-based access control” or RBAC. Your organization should create a clear policy and processes for data access control based on “need to know” and using “role-based access control,” to define how, and to whom, access is granted.
7.2 Establish a mechanism for system components with multiple users that restricts access based on a user's need to know and is set to “deny all” unless specifically allowed. This access control system must include the following:
Note: “Need to know” is when access rights are granted to only the least amount of data and privileges needed to perform a job.
7.2.1 Coverage of all system components
7.2.2 Assignment of privileges to individuals based on job classification and function
7.2.3 Default “deny-all” setting
Without a mechanism to restrict access based on user's need to know, a user may unknowingly be granted access to cardholder data. Use of an automated access control system or mechanism is essential to manage multiple users. This system should be established in accordance with your organization's access control policy and processes (including “need to know” and “role-based access control”), should manage access to all system components, and should have a default “deny-all” setting to ensure no one is granted access until and unless a rule is established specifically granting such access.

Requirement 8: Assign a unique ID to each person with computer access
Assigning a unique identification (ID) to each person with access ensures that each individual is uniquely accountable for his or her actions. When such accountability is in place, actions taken on critical data and systems are performed by, and can be traced to, known and authorized users.

Requirement Guidance
8.1 Assign all users a unique ID before allowing them to access system components or cardholder data.By ensuring each user is uniquely identified—instead of using one ID for several employees—an organization can maintain individual responsibility for actions and an effective audit trail per employee. This will help speed issue resolution and containment when misuse or malicious intent occurs.
Cyrious facilitates the use of a unique user name for each employee, and the following password guidelines:
1. Must be at least 7 characters.
2. Must contain one uppercase, one lowercase, and one numerical character.
3. Must be changed at least every 90 days.
8.2 In addition to assigning a unique ID, employ at least one of the following methods to authenticate all users:
* Password or passphrase
* Two-factor authentication (for example, token devices, smart cards, biometrics, or public keys)
These authentication items, when used in addition to unique IDs, help protect users' unique IDs from being compromised (since the one attempting the compromise needs to know both the unique ID and the password or other authentication item).
Cyrious facilitates the use of a unique user name for each employee, and the following password guidelines:
1. Must be at least 7 characters.
2. Must contain one uppercase, one lowercase, and one numerical character.
3. Must be changed at least every 90 days.
8.3 Incorporate two-factor authentication for remote access (network-level access originating from outside the network) to the network by employees, administrators, and third parties. Use technologies such as remote authentication and dial-in service (RADIUS); terminal access controller access control system (TACACS) with tokens; or VPN (based on SSL/TLS or IPSEC) with individual certificates.Two-factor authentication requires two forms of authentication for higher-risk accesses, such as those originating from outside your network. For additional security, your organization can also consider using two-factor authentication when accessing networks of higher security from networks of lower security— for example, from corporate desktops (lower security) to production servers/databases with cardholder data (high security).
There is no remote access technology built into the payment application or installed by Cyrious. However, users can and often do use external software (such as Microsoft's Remote Desktop).
8.4 Render all passwords unreadable during transmission and storage on all system components using strong cryptography (defined in PCI DSS and PA-DSS Glossary of Terms, Abbreviations, and Acronyms).Many network devices and applications transmit the user ID and unencrypted password across the network and/or also store the passwords without encryption. A malicious individual can easily intercept the unencrypted or readable user ID and password during transmission using a “sniffer,” or directly access the user IDs and unencrypted passwords in files where they are stored, and use this stolen data to gain unauthorized access.
8.5 Ensure proper user authentication and password management for non-consumer users and administrators on all system components as follows:Since one of the first steps a malicious individual will take to compromise a system is to exploit weak or nonexistent passwords, it is important to implement good processes for user authentication and password management.
8.5.1 Control addition, deletion, and modification of user IDs, credentials, and other identifier objects.To ensure users added to your systems are all valid and recognized users, the addition, deletion, and modification of user IDs should be managed and controlled by a small group with specific authority. The ability to manage these user IDs should be limited to only this small group.
8.5.2 Verify user identity before performing password resets.Many malicious individuals use “social engineering”—for example, calling a help desk and acting as a legitimate user—to have a password changed so they can utilize a user ID. Consider use of a “secret question” that only the proper user can answer to help administrators identify the user prior to resetting passwords. Ensure such questions are secured properly and not shared.
8.5.3 Set first-time passwords to a unique value for each user and change immediately after the first use.If the same password is used for every new user set up, an internal user, former employee, or malicious individual may know or easily discover this password, and use it to gain access to accounts.
8.5.4 Immediately revoke access for any terminated users.If an employee has left the company, and still has access to the network via their user account, unnecessary or malicious access to cardholder data could occur. This access could happen from the former employee or from a malicious user who exploits the older and/or unused account. Consider implementing a process with HR for immediate notification when an employee is terminated so that the user account can be quickly deactivated.
8.5.5 Remove/disable inactive user accounts at least every 90 days.Existence of inactive accounts allows an unauthorized user exploit the unused account to potentially access cardholder data.
8.5.6 Enable accounts used by vendors for remote maintenance only during the time period needed.Allowing vendors (like POS vendors) to have 24/7 access into your network in case they need to support your systems increases the chances of unauthorized access, either from a user in the vendor's environment or from a malicious individual who finds and uses this always-ready external entry point into your network. Please also see 12.3.8 and 12.3.9 for more on this topic.
Updates to Cyrious' software is installed manually. They may be downloaded or delivered on CD/DVD.
8.5.7 Communicate password procedures and policies to all users who have access to cardholder data.Communicating password procedures to all users helps those users understand and abide by the policies, and to be alert for any malicious individuals who may attempt to exploit their passwords to gain access to cardholder data (for example, by calling an employee and asking for their password so the caller can “troubleshoot a problem”).
8.5.8 Do not use group, shared, or generic accounts and passwords.If multiple users share the same account and password, it becomes impossible to assign accountability for, or to have effective logging of, an individual's actions, since a given action could have been performed by anyone in the group that shares the account and password.
8.5.9 Change user passwords at least every 90 days.
8.5.10 Require a minimum password length of at least seven characters
8.5.11 Use passwords containing both numeric and alphabetic characters.
8.5.12 Do not allow an individual to submit a new password that is the same as any of the last four passwords he or she has used.
Strong passwords are the first line of defense into a network since a malicious individual will often first try to find accounts with weak or non-existent passwords. There is more time for a malicious individual to find these weak accounts, and compromise a network under the guise of a valid user ID, if passwords are short, simple to guess, or valid for a long time without a change. Strong passwords can be enforced and maintained per these requirements by enabling the password and account security features that come with your operating system (for example, Windows), networks, databases and other platforms.
8.5.13 Limit repeated access attempts by locking out the user ID after not more than six attempts.Without account-lockout mechanisms in place, an attacker can continually attempt to guess a password through manual or automated tools (for example, password cracking), until they achieve success and gain access to a user's account.
8.5.14 Set the lockout duration to a minimum of 30 minutes or until administrator enables the user ID.If an account is locked out due to someone continually trying to guess a password, controls to delay reactivation of these locked accounts stops the malicious individual from continually guessing the password (they will have to stop for a minimum of 30 minutes until the account is reactivated). Additionally, if reactivation must be requested, the admin or help desk can validate that the account owner is the cause (from typing errors) of the lockout.
8.5.15 If a session has been idle for more than 15 minutes, require the user to re-enter the password to re-activate the terminal.When users walk away from an open machine with access to critical network or cardholder data, that machine may be used by others in the user's absence, resulting in unauthorized account access and/or account misuse.
8.5.16 Authenticate all access to any database containing cardholder data. This includes access by applications, administrators, and all other users.Without user authentication for access to databases and applications, the potential for unauthorized or malicious access increases, and such access cannot be logged since the user has not been authenticated and is therefore not known to the system. Also, database access should be granted through programmatic methods only (for example, through stored procedures), rather than via direct access to the database by end users (except for DBAs, who can have direct access to the database for their administrative duties).

Requirement 9: Restrict physical access to cardholder data
Any physical access to data or systems that house cardholder data provides the opportunity for individuals to access devices or data and to remove systems or hardcopies, and should be appropriately restricted.

Requirement Guidance
9.1 Use appropriate facility entry controls to limit and monitor physical access to systems in the cardholder data environment.Without physical access controls, unauthorized persons could potentially gain access to the building and to sensitive information, and could alter system configurations, introduce vulnerabilities into the network, or destroy or steal equipment.
9.1.1 Use video cameras or other access control mechanisms to monitor individual access to sensitive areas. Review collected data and correlate with other entries. Store for at least three months, unless otherwise restricted by law.
Note: “Sensitive areas” refers to any data center, server room, or any area that houses systems that store cardholder data. This excludes the areas where only point-of-sale terminals are present such as the cashier areas in a retail store.
When investigating physical breaches, these controls can help identify individuals that physically access those areas storing cardholder data.
9.1.2 Restrict physical access to publicly accessible network jacksRestricting access to network jacks will prevent malicious individuals from plugging into readily available network jacks that may allow them access into internal network resources. Consider turning off network jacks while not in use, and reactivating them only while needed. In public areas such as conference rooms, establish private networks to allow vendors and visitors to access Internet only so that they are not on your internal network.
9.1.3 Restrict physical access to wireless access points, gateways, and handheld devices.Without security over access to wireless components and devices, malicious users could use your company's unattended wireless devices to access your network resources, or even connect their own devices to your wireless network, giving them unauthorized access. Consider placing wireless access points and gateways in secure storage areas, such as within locked closets or server rooms. Ensure strong encryption is enabled. Enable automatic device lockout on wireless handheld devices after a long idle period, and set your devices to require a password when powering on.
9.2 Develop procedures to help all personnel easily distinguish between employees and visitors, especially in areas where cardholder data is accessible.
For purposes of this requirement, “employee” refers to full-time and part-time employees, temporary employees and personnel, and contractors and consultants who are “resident” on the entity's site. A “visitor” is defined as a vendor, guest of an employee, service personnel, or anyone who needs to enter the facility for a short duration, usually not more than one day.
Without badge systems and door controls, unauthorized and malicious users can easily gain access to your facility to steal, disable, disrupt, or destroy critical systems and cardholder data. For optimum control, consider implementing badge or card access system in and out of work areas that contain cardholder data.
9.3 Make sure all visitors are handled as follows:Visitor controls are important to reduce the ability of unauthorized and malicious persons to gain access to your facilities (and potentially, to cardholder data).
9.3.1 Authorized before entering areas where cardholder data is processed or maintained.
9.3.2 Given a physical token (for example, a badge or access device) that expires and that identifies the visitors as non-employees.
9.3.3 Asked to surrender the physical token before leaving the facility or at the date of expiration.
Visitor controls are important to ensure visitors only enter areas they are authorized to enter, that they are identifiable as visitors so employees can monitor their activities, and that their access is restricted to just the duration of their legitimate visit.
9.4 Use a visitor log to maintain a physical audit trail of visitor activity. Document the visitor's name, the firm represented, and the employee authorizing physical access on the log. Retain this log for a minimum of three months, unless otherwise restricted by law.A visitor log documenting minimum information on the visitor is easy and inexpensive to maintain and will assist, during a potential data breach investigation, in identifying physical access to a building or room, and potential access to cardholder data. Consider implementing logs at the entry to facilities and especially into zones where cardholder data is present.
9.5 Store media backups in a secure location, preferably in an off-site facility, such as an alternate or back-up site, or a commercial storage facility. Review the location's security at least annually.If stored in a non-secured facility, backups that contain cardholder data may easily be lost, stolen, or copied for malicious intent. For secure storage, consider contracting with a commercial data storage company OR, for a smaller entity, using a safe-deposit box at a bank.
9.6 Physically secure all paper and electronic media that contain cardholder data.Cardholder data is susceptible to unauthorized viewing, copying, or scanning if it is unprotected while it is on portable media, printed out, or left on someone's desk. Consider procedures and processes for protecting cardholder data on media distributed to internal and/or external users. Without such procedures data can be lost or stolen and used for fraudulent purposes
9.7 Maintain strict control over the internal or external distribution of any kind of media that contains cardholder data including the following:
9.7.1 Classify the media so it can be identified as confidentialMedia not identified as confidential may not be treated with the care it requires and may be lost or stolen. Include a media classification process in the procedures recommended in Requirement 9.6 above.
9.7.2 Send the media by secured courier or other delivery method that can be accurately tracked.Media may be lost or stolen if sent via a non-trackable method such as regular postal mail. Use the services of a secure courier to deliver any media that contains cardholder data, so that you can use their tracking systems to maintain inventory and location of shipments.
9.8 Ensure management approves any and all media containing cardholder data that is moved from a secured area (especially when media is distributed to individuals).Cardholder data leaving secure areas without a process approved by management can lead to lost or stolen data. Without a firm process, media locations are not tracked, nor is there a process for where the data goes or how it is protected. Include development of a management-approved process for moving media in the procedures recommended in Requirement 9.6 above.
9.9 Maintain strict control over the storage and accessibility of media that contains cardholder data.Without careful inventory methods and storage controls, stolen or missing media could go unnoticed for an indefinite amount of time. Include development of a process to limit access to media with cardholder data in the procedures recommended above in Requirement 9.6.
9.9.1 Properly maintain inventory logs of all media and conduct media inventories at least annually.If media is not inventoried, stolen or lost media may not be noticed for a long time. Include development of a process for media inventories and secure storage in the procedures recommended above in Requirement 9.6.
9.10 Destroy media containing cardholder data when it is no longer needed for business or legal reasons as follows:
9.10.1 Shred, incinerate, or pulp hardcopy materials so that cardholder data cannot be reconstructed
9.10.2 Render cardholder data on electronic media unrecoverable so that cardholder data cannot be reconstructed.
If steps are not taken to destroy information contained on PC hard disks and CDs, and on paper, disposal of such information may result in compromise and lead to financial or reputation loss. For example, malicious individuals may use a technique known as “dumpster diving,” where they search through trashcans and recycle bins, and use found information to launch an attack. Include development of a process for properly destroying media with cardholder data, including proper storage of such media prior to destruction, in the procedures recommended above in Requirement 9.6.


You could leave a comment if you were logged in.