Re: File/Folder encryption - Compliancy with PCI

Re: File/Folder encryption - Compliancy with PCI

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Re: File/Folder encryption - Compliancy with PCI Martin 11-24-2005
Posted by =?Utf-8?B?TWFydGlu?= on November 24, 2005, 11:21 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I am an auditor from a Qualified Security Assessor for Visa/MC PCI DSS
Assessments.
I would be interested to discuss further the possible use of EFS in regards
to compliance to PCI.
If interested please provide me with some contact details.

"The Poster" wrote:

> Apparently the credit card companies in question do not approve of EFS (as
> per our Auditors) - pity that because its exactly what I'm looking for.
>
> Regards,
> Steve.
>
> > Just out of curiosity, are you believing that use of EFS cannot
> > acheive one or more of your listed requirements ? (as I did not
> > see one)
> >
> > --
> > Roger Abell
> > Microsoft MVP (Windows Server : Security)
> > MCDBA, MCSE W2k3+W2k+Nt4
> > > G/Day forum,
> > >
> > > I'm looking for a File/Folder encryption solution (aside from EFS) for
> my
> > > Windows 2000 based file server. This is based on one of the requirements
> > > of
> > > Visa/MasterCards PCI Data Security Standard - http://snipurl.com/fhzg .
> > >
> > > To achieve compliancy with PCI DSS, we need to imply the following
> > > controls
> > > on credit card data:
> > >
> > > 1) to encrypt data at a folder level - that is all of the containing
> > > folders
> > > and files
> > > 2) to allow for split knowledge of encryption keys and management
> thereof
> > > 3) to allow for strong encryption support (algorithms like 3DES, AES,
> etc)
> > > 4) a mechanism for automating the encryption process on a daily basis -
> > > this
> > > is coincide with a backup cycle (no clear text credit card files get
> > > backed
> > > up onto tape)
> > >
> > > Your thoughts on any products that suit my requirements?
> > >
> > > Regards,
> > > Steve.
> > >
> > >
> >
> >
>
>
>

Similar ThreadsPosted
File/Folder encryption - Compliancy with PCI September 28, 2005, 5:31 am
Data Encryption Standard (DES) encryption November 15, 2005, 6:26 pm
Encryption July 13, 2005, 5:32 pm
Encryption November 3, 2005, 12:05 pm
Encryption March 30, 2006, 11:36 pm
SSL Encryption May 16, 2007, 10:40 am
MS document encryption June 13, 2005, 12:35 pm
File Encryption February 17, 2006, 2:42 pm
Encryption for Powerpoint? May 19, 2006, 11:32 pm
Email Encryption May 26, 2006, 1:24 pm

The site map in XML format XML site map

Contact Us | Privacy Policy