STAGES OF COMPLIANCE
The PCI standard applies to store merchants, banks, service providers and card processors. And that’s not all. PCI extends to all system components connected to cardholder data environments, including network components (firewalls, switches, routers, security appliances, etc.), servers (Web, proxy, database, email, authentication, etc.) and applications, both internal and external. In other words, PCI compliance is a lot of work.
The process of complying with PCI compliance can be viewed in three stages:
- Collection and storage - collecting and securely storing all log data so that it is available for analysis yet tamper-proof and secure.
- Reporting - prove compliance on the spot if audited, and present evidence that controls are in place for protecting data.
- Monitoring and alerting - have systems in place, such as auto-alerting, to help constantly monitor access and usage so that administrators are warned of problems immediately and can rapidly address them. These systems should also extend to the log data itself – there must be proof that log data is being collected and stored.