File/Folder encryption - Compliancy with PCI

From: The Poster (nospam_at_nospam_dontyoudare.net)
Date: 09/28/05


Date: Wed, 28 Sep 2005 10:31:33 +0100

G/Day forum,

I'm looking for a File/Folder encryption solution (aside from EFS) for my
Windows 2000 based file server. This is based on one of the requirements of
Visa/MasterCards PCI Data Security Standard - http://snipurl.com/fhzg .

To achieve compliancy with PCI DSS, we need to imply the following controls
on credit card data:

1) to encrypt data at a folder level - that is all of the containing folders
and files
2) to allow for split knowledge of encryption keys and management thereof
3) to allow for strong encryption support (algorithms like 3DES, AES, etc)
4) a mechanism for automating the encryption process on a daily basis - this
is coincide with a backup cycle (no clear text credit card files get backed
up onto tape)

Your thoughts on any products that suit my requirements?

Regards,
Steve.



Relevant Pages

  • Encryptio key hardware solution... help :(
    ... that provides a Secure and Safe environment where these Credit Card ... Now it was proposed we do the 'hardware ... methods to protect and unprotect passed data. ... using a 2-step process the first step will need to read the encryption key ...
    (microsoft.public.sqlserver.security)
  • [PHP] Re: keeping credit card info in session
    ... the strength of the encryption means nothing. ... Anyways, if you're storing the credit card in the database, then ... credit card based on the session id (so you should also store the ... PHP General Mailing List ...
    (php.general)
  • Re: [PHP] Re: keeping credit card info in session
    ... Encryption is a mandatory part of PCI compliance... ... to store the keys somewhere to decrypt the data to use it. ... On Apr 8, 2007, at 4:56 PM, itoctopus wrote: ... Anyways, if you're storing the credit card in the database, then ...
    (php.general)
  • Is In-Browser Encryption Safe?
    ... One of our clients has asked us to add an ordering facility to a web ... protect the credit card number. ... having orders reach the client as email makes sense. ... I have noticed implementations of public-key encryption ...
    (Security-Basics)
  • [PHP] Re: keeping credit card info in session
    ... You have to store the keys somewhere to decrypt the data to use it. ... As we have seen with blu-ray and HD DVD movies, the keys are the weak point that are easily compromised. ... Once you have the decryption key, the strength of the encryption means nothing. ... Anyways, if you're storing the credit card in the database, then why are you ...
    (php.general)