OVERVIEWCreated in 2004,
PCI-DSS (Payment Card Industry – Data Security Standard) is a global data security standard that applies to any entity that stores, processes, and/or transmits cardholder data. The standard covers both technical and operational system requirements related to any credit card data transaction.
Banks, merchants, online payment processors, service providers... must comply with
PCI-DSS to ensure cardholder-sensitive data security and payment data confidentiality.
For information systems involved in credit card payment processing, the
PCI-DSS Standard specifies 12 requirements grouped into 6 IT control objectives.
How cilasoft can helpExamples of the control objectives and how Cilasoft Security Solutions can help you implement them on the IBM i (AS/400, iSeries, System i) platform are shown below:
| PCI-DSS Requirements | The CILASOFT Answer |
|---|
Build and Maintain a Secure Network:
Install and manage firewall configuration to protect cardholder data.
| CONTROLER More than a firewall, a complete access control solution.
|
Implement Strong Access Control Measures:
Restrict access to cardholder data by business need-to-know.
| CONTROLER Easily allows flexible control over file and record accesses by user or group.
|
Regularly Monitor and Test Networks:
Track and monitor all access to network resources and cardholder data.
| CONTROLER Record who is connected to the IBM i and what they are doing with CONTROLER's extensive logging capabilities. QJRN/400 Use the power of journaling to find out who changed database records or system objects and when. DVM Limit access to information at the field or record level. Block or record access to data according to user-definable rules. |
The Cilasoft Security Software Suite, including QJRN/400, CONTROLER and DVM, is the solution that enables companies to comply with
PCI-DSS efficiently on the IBM i platform.