PCI Requirement 12.3.8 – Automatic Disconnect of Sessions for Remote-Access Technologies After a Specific Period of Inactivity

by Randy Bartels / December 22, 2022

 Automatic Disconnect in Your Usage Policies Remote-access technologies are a constant source of risk for critical resources and cardholder data. This is why PCI Requirement 12.3.8 requires that your usage policies include, “Automatic disconnect of sessions for remote-access technologies after a specific period of inactivity.” In PCI Requirement 8.1.8, we gave you this scenario: A user walks away from an open machine that has access to critical system components…

PCI Requirement 12.3.7 – List of Company-Approved Products

by Randy Bartels / December 22, 2022

 Acceptable Products Your usage policies, as stated in PCI Requirement 12.3.7, should include a list of company-approved products. This list will correlate with your acceptable uses of technology policy to create strong and secure usage policies. The PCI DSS explains that by defining company-approved products, your organization will be better equipped to manage and control gaps in configurations and operational controls, ensuring that a back door is not opened…

PCI Requirement 12.3.6 – Acceptable Network Locations for the Technologies

by Randy Bartels / December 22, 2022

 Acceptable Network Locations Your usage policies, as stated in PCI Requirement 12.3.6, should detail acceptable network locations for the technology at your organization. The PCI DSS explains that by defining acceptable network locations, your organization will be better equipped to manage and control gaps in configurations and operational controls, ensuring that a back door is not opened for attackers. To test compliance with PCI Requirement 12.3.6, an assessor will…

PCI Requirement 12.3.5 – Acceptable Uses of the Technology

by Randy Bartels / December 22, 2022

 Acceptable Use Policies Your usage policies, as stated in PCI Requirement 12.3.5, should detail acceptable uses of the technology at your organization. Acceptable use policies (AUP) normally have users agree to not use the services for illegal purposes, not attempt to harm the security of the technology or system, and to report any suspicious activity. The PCI DSS explains that by defining acceptable uses of the technology, your organization…

PCI Requirement 12.3.4 – A Method to Accurately and Readily Determine Owner, Contact Information, and Purpose

by Randy Bartels / December 16, 2022

 Identification System Your usage policies should have a method for identifying who an asset-owner is. PCI Requirement 12.3.4 specifically details, “A method to accurately and readily determine owner, contact information, and purpose.” This doesn’t mean you need a label on every device defining who the owner is, but you do need to have an identification system. This could be a serial number that traces back to the owner. Without…