Blog powered by TypePad

« VMware Security Tip of the Day - #6 | Main | VMware Security Tip of the Day - #7 »

March 20, 2007

PCI Standards Tough on Wireless Compliance

PCI DSS is tough on wireless LANs. I suppose wireless LANs have earned this reputation, deservingly so. Too many retailers operate open wireless networks without any encryption or they have used WEP, which can be broken in about 6 minutes of sampling.
PCI DSS requires the following of wireless LANs:
1. Firewall separation of wireless LANs from the wired network
2. If WEP is used, keys must be rotated at least quarterly
3. No default Admin IDs and passwords.
4. SNMP agents can't have community strings of "public"
5. Disable SSID broadcasts
6. Preferably use WPA or WPA2
7. Disable FTP
8. save AP logs
Manually auditing wireless APs is time-consuming. If you are in the middle of wireless audits, www.Wifi-Owl.com is looking for beta testers with Cisco APs to audit and satisfy for requirements 2.1.1,   4.1.1,   10.5.4,  and 11.1

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d834520ea169e200d835259c7469e2

Listed below are links to weblogs that reference PCI Standards Tough on Wireless Compliance:

Comments

This is tough?

:)

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment