Share this article
Exposure to risk is a significant problem in the world of information security. Here are some pragmatic tips for reducing the risk and shrinking your organisation’s threat surface.
One of the most effective ways to reduce cost, complexity and risk when working towards Payment Card Industry Data Security Standard (PCI DSS) compliance is to shrink down the “scope” of compliance. In essence, this means minimising the systems, networks and processes that handle, store or transmit cardholder data.
Scope reduction isn’t about dodging responsibilities or trying to find loopholes in compliance requirements; it is about understanding what you can and should manage risk for internally, in order to make audits simpler, more streamlined and easy to manage. As anything within scope must meet PCI DSS requirements, the smaller the scope the easier it is to manage your compliance efforts.
So, how do you go about reducing scope responsibly and understanding what can and can’t be considered part of your risk surface? Well, that’s best done with the help of a PCI consultant, of course. But here are some practical strategies to get you started.
By separating cardholder data environments (CDEs) from the rest of your business’s network it is possible to keep systems not involved in the processing of payments to be kept out of scope. This can be implemented by using firewalls, access controls and network monitoring tools to ensure strong segmentation.
By taking steps to partition business operations from CDEs, you can significantly limit the number of systems that require PCI DSS compliance – which saves resource, time and money.
Tokenisation is an important tool in the process of securing sensitive information. Essentially, tokenisation replaces sensitive cardholder data with non-sensitive equivalents that are known as tokens. These tokens can be stored or transmitted without PCI DSS requirements applying in the same way. This is because they carry no intrinsic value.
In using tokenisation for payment data, you can reduce the number of systems that must be secured under PCI DSS.
Using payment gateways and service providers that already hold PCI DSS certification removes the need for your organisation to process or store cardholder data internally. This is a straightforward but popular option for a wide range of businesses that are happy to use a trusted third party solution.
It is important to note, however, that you remain responsible for ensuring that the provider themselves remains compliant.
A common issue found during PCI audits is that businesses retain cardholder data for longer than necessary – sometimes unintentionally. For this reason it is always advisable to perform regular data inventories to identify and eliminate data that can be destroyed.
E2EE – also known as end-to-end encryption – ensures that cardholder data is secured because it is unreadable to threat actors from point of capture through to processing. Any encrypted data that is intercepted during transmission cannot be disseminated and so it protects sensitive information – lowering the risk of a damaging breach and reducing the PCI DSS scope.
Governance, documentation and training
On a practical note, simply following good administration processes is an invaluable part of reducing scope and working towards compliance. This includes:
Like all aspects of security compliance, achieving certification shouldn’t be about a one-off effort or an annual update of business operations. Instead, it is essential that scope is reviewed and assessed on a regular basis to identify potential areas of improvement or any emerging vulnerabilities.
If you’re looking for support with PCI DSS, contact SRM today.