We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Pci dss question
Options

azadali77
Posts: 18 Forumite


in Techie Stuff
Hi,
I need some help with regards PCI DSS complaince. Bt( who is my broadband provider cant seem to answer this question). Can anyone tell me how I go about solving this problem. how do I check for this? any help would be greatly appreciated
"Are perimeter firewalls installed between all wireless networks and the cardholder data environment, and are these firewalls configured to deny or, if traffic is necessary for business purposes, permit only authorized traffic between the wireless environment and the cardholder data environment?"
and this is the PCI council guidline
"Information
PCI Council Guidelines
The known (or unknown) implementation and exploitation of wireless technology within a network is a common path for malicious individuals to gain access to the network and cardholder data. If a wireless device or network is installed without the entity's knowledge, a malicious individual could easily and "invisibly" enter the network. If firewalls do not restrict access from wireless networks into the CDE, malicious individuals that gain unauthorized access to the wireless network can easily connect to the CDE and compromise account information.
Firewalls must be installed between all wireless networks and the CDE, regardless of the purpose of the environment to which the wireless network is connected. This may include, but is not limited to, corporate networks, retail stores, guest networks, warehouse environments, etc.
PCI Audit Procedures
Examine firewall and router configurations to verify that there are perimeter firewalls installed between all wireless networks and the cardholder data environment.
I need some help with regards PCI DSS complaince. Bt( who is my broadband provider cant seem to answer this question). Can anyone tell me how I go about solving this problem. how do I check for this? any help would be greatly appreciated
"Are perimeter firewalls installed between all wireless networks and the cardholder data environment, and are these firewalls configured to deny or, if traffic is necessary for business purposes, permit only authorized traffic between the wireless environment and the cardholder data environment?"
and this is the PCI council guidline
"Information
PCI Council Guidelines
The known (or unknown) implementation and exploitation of wireless technology within a network is a common path for malicious individuals to gain access to the network and cardholder data. If a wireless device or network is installed without the entity's knowledge, a malicious individual could easily and "invisibly" enter the network. If firewalls do not restrict access from wireless networks into the CDE, malicious individuals that gain unauthorized access to the wireless network can easily connect to the CDE and compromise account information.
Firewalls must be installed between all wireless networks and the CDE, regardless of the purpose of the environment to which the wireless network is connected. This may include, but is not limited to, corporate networks, retail stores, guest networks, warehouse environments, etc.
PCI Audit Procedures
Examine firewall and router configurations to verify that there are perimeter firewalls installed between all wireless networks and the cardholder data environment.
0
Comments
-
I think you'd need to describe your configuration in some detail before anyone could clarify the requirements for you. Basically it's asking what you have between your wireless network and the network where card holder data is stored.0
-
If you're using BT broadband kit, you'll probably fail on that. Because if someone could gain access to your WiFi network, there would be nothing in between stopping them from getting to the area where card data is stored.0
-
I think you might need to consider paying somebody who understands PCI to assess your network and connection to determine if it is compliant. I assume this must be for business use, so it'll be a business expense.0
-
yes it's a restaurant business. I have spoken to an IT specialist and they have quoted £1200. does that seem about right to anyone? I dont know why BT cant provide that service to seperate the networks even if they charged for it0
-
If this is a restaurant, then do you have any need to store cardholder data (the section you quoted mentions this), rather than just processing cards with a terminal when people pay for their meals so you only have the information transiently (or indeed not at all if it's processed through the merchant supplied terminal and goes nowhere near your computer)?
If you are going to be storing card numbers, then you are going to need (at least) internal firewalls to segment your network to comply with the text you quoted.
In my workplace we don't store card numbers, online purchases are made using a form on the merchant's site to accept payment, so our site never sees the card number, and if someone makes a purchase over the phone then the number is typed directly into the online terminal on the merchant's site while they are still on the phone, it is never written down or stored on a computer. Doing it that way makes complying with PCI DSS much less work, because lots of it becomes "not applicable".
If you don't know the answers to any of the questions, then you really need to get professional advice.Proud member of the wokerati, though I don't eat tofu.Home is where my books are.Solar PV 5.2kWp system, SE facing, >1% shading, installed March 2019.Mortgage free July 20230 -
no we dont physically hold any credit card data. But saferpayment say because we are taking the payments via wifi we need to have the networks segregated on the router0
-
-
Yes - find out what the quote is for. You could do this by purchasing a firewall and separate wifi access points for a few hundred quid.0
-
The quote is for hardware £628 and service £500.Just had another quote for £414 plus VAT. When I spoke to both companies they said that BT business hub dont comply with PCI and even BT have said to me that I have to get my own router if I want to comply.
If get a seperate wifi point would i have to get another router?0 -
Yes you will as the BT Hub won't support the level of segregation that you need. That £414 quote looks good - get them to detail and break down the quote and I'm sure we can give you further advice.
Regards0
This discussion has been closed.
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 350.8K Banking & Borrowing
- 253K Reduce Debt & Boost Income
- 453.5K Spending & Discounts
- 243.8K Work, Benefits & Business
- 598.6K Mortgages, Homes & Bills
- 176.8K Life & Family
- 257.1K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards