Re: PCI-DSS Requirements

Поиск
Список
Период
Сортировка
От Laurenz Albe
Тема Re: PCI-DSS Requirements
Дата
Msg-id 3d512cd00a221216d3ac99b046285b4aa4302033.camel@cybertec.at
обсуждение исходный текст
Ответ на Re: PCI-DSS Requirements  (Inzamam Shafiq <inzamam.shafiq@hotmail.com>)
Список pgsql-general
On Thu, 2022-09-22 at 06:16 +0000, Inzamam Shafiq wrote:
> From: Ron <ronljohnsonjr@gmail.com>
> > > Anyone on PCI-DSS requirements for PostgreSQL DB, need help for some of the points.
> >
> > Can you be more specific?  (Typically. the auditors or the "audit pre-check" team
> > will ask for a bunch of details on how your instance is configured.)
> >
> > The usual questions I get are:
> > - What password hash algorithm is used?
> > - How frequently to passwords expire?
> > - Is SSL used when communicating with applications?
> 
> Actually we are in a starting phase and I have done instance level encryption
> (CYBERTECH TDE Patch) but if someone take dump and restore it on another server
> the data get restored successfully. Also the problem is that the data is in plain text.
> 
> So I want to ask if disk or instance level encryption useful or we should focus on
> column level encryption?
> 
> Also if any error occurred during DML and a plain query will be written into the
> logs which may not be compliant with PCI. How to overcome that?

Yes, data-at-rest encryption is expensive, but of limited effectiveness.

If you store sensitive information about credit cards and their owners,
the best you can do is encrypt sensitive columns in the application, so
that unencrypted data never touch the database. Make sure you don't encrypt
everything, only the sensitive data, so that you can retain some degree of
usability.

A great deal will also rest on your database user management and authentication,
and how well access to the system is logged and controlled.

All that said, there is always a difference between good security and passing
a certification exam...

Yours,
Laurenz Albe



В списке pgsql-general по дате отправления:

Предыдущее
От: YangYuping(杨瑜萍)
Дата:
Сообщение: ECCN for PostgreSQL
Следующее
От: Laurenz Albe
Дата:
Сообщение: Re: ECCN for PostgreSQL