Wireless Security and PCI Compliance


The Payment Card Industry Security Standards Council (PCI SSC) has published wireless guidelines for PCI DSS, which acknowledge that wireless is a clear and present danger to network security. Though the PCI DSS already included wireless security requirements, this is the first time that the requirements for wireless security have been described unambiguously for all cardholder data environments (CDE).

Regardless of whether or not wireless is deployed in the CDE, all organizations that collect, store or transmit cardholder data must take steps to secure the CDE against wireless threats including unmanaged Rogue APs and unknown wireless devices in the environment and must scan ALL locations.

 
  PCI DSS 1.2 Requirements No Known WLAN AP in CDE Known WLAN AP in CDE
Minimum Scanning Requirements Section 11.1 Conduct wireless scans at least quarterly at all locations
Section 11.4 Monitor wireless intrusion alerts
Section 12.9 Eliminate wireless threats
Secure Wireless Deployment Requirements Section 2.1.1 Change default settings N/A
Section 4.1.1 Use strong encryption and authentication N/A
Section 9.1.3 Restrict physical access N/A
Section 10.5.4 Maintain logs of wireless activity N/A
Section 10.6 Review wireless access logs daily N/A
Section 12.3 Develop and enforce wireless usage policies N/A

SpectraGuard Online PCI Compliance Services

  • PCI Quarterly Scan Service: PCI report delivered monthly
  • PCI Quarterly Scan + Alerts: PCI report delivered monthly plus real-time alerts via email for PCI compliance related wireless threats
  • 24x7 Wireless Monitoring Service: 24x7 monitoring, console access (security dashboard & forensics), real-time alerts via email, and unlimited reports
  • 24x7 Wireless Remediation Service: Monitoring service plus automatic or manual prevention, RF heat maps and location tracking

Know more about SpectraGuard Online

cars