Blog powered by TypePad

« VMware Security Tip of the Day - #6 | Main | VMware Security Tip of the Day - #7 »

March 20, 2007

PCI Standards Tough on Wireless Compliance

PCI DSS is tough on wireless LANs. I suppose wireless LANs have earned this reputation, deservingly so. Too many retailers operate open wireless networks without any encryption or they have used WEP, which can be broken in about 6 minutes of sampling.
PCI DSS requires the following of wireless LANs:
1. Firewall separation of wireless LANs from the wired network
2. If WEP is used, keys must be rotated at least quarterly
3. No default Admin IDs and passwords.
4. SNMP agents can't have community strings of "public"
5. Disable SSID broadcasts
6. Preferably use WPA or WPA2
7. Disable FTP
8. save AP logs
Manually auditing wireless APs is time-consuming. If you are in the middle of wireless audits, www.Wifi-Owl.com is looking for beta testers with Cisco APs to audit and satisfy for requirements 2.1.1,   4.1.1,   10.5.4,  and 11.1

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/t/trackback/458164/17070940

Listed below are links to weblogs that reference PCI Standards Tough on Wireless Compliance:

Comments

This is tough?

:)

Post a comment

If you have a TypeKey or TypePad account, please Sign In