Implementation Guide Payment Card Industry Data Security Standard
Total Page:16
File Type:pdf, Size:1020Kb
Implementation Guide Payment Card Industry Data Security Standard 1 Table of Contents Introduction .............................................................................................................................................................................. 4 Terminology Used in this Guide .............................................................................................................................................. 5 Table 1: Summary of PCI DSS Requirements ......................................................................................................................... 6 Building and Maintaining a Secure Network ......................................................................................................................... 10 Remote Network Access .................................................................................................................................................... 10 Wireless Networks ............................................................................................................................................................. 11 Using Firewalls .................................................................................................................................................................. 12 Firewalls and Intuit QuickBooks Cash Register Plus ........................................................................................................ 12 Protecting Cardholder Data .................................................................................................................................................... 12 Encrypting Card Information ............................................................................................................................................. 12 If you suspect a security breach ......................................................................................................................................... 13 Transmitting and Sharing of Cardholder Data ................................................................................................................... 13 If your data is requested by Intuit .................................................................................................................................. 13 If you share your data with other parties (such as System Integrators) ......................................................................... 14 Maintaining a Vulnerability Management Program ............................................................................................................... 14 Windows Update ................................................................................................................................................................ 14 Manually Downloading Updates ................................................................................................................................... 14 Antivirus Software ............................................................................................................................................................. 14 Implementing Strong Access Control Measures .................................................................................................................... 14 About System Administrators ............................................................................................................................................ 14 Protecting Your Data with Unique IDs and Passwords ..................................................................................................... 15 What is a complex password? ........................................................................................................................................ 15 Other password recommendations ................................................................................................................................. 16 Creating passwords in Intuit QuickBooks Cash Register Plus ...................................................................................... 16 Creating passwords for employees ................................................................................................................................ 16 Restrict access with security rights ................................................................................................................................ 16 When an employee leaves ............................................................................................................................................. 17 2 Limiting physical access to your data files .................................................................................................................... 17 Monitoring and Testing Your Network .................................................................................................................................. 17 Review Intuit Cash Register Plus log files regularly ......................................................................................................... 17 Intuit QuickBooks Cash Register Plus Audit Log ......................................................................................................... 18 Maintaining an Information Security Policy .......................................................................................................................... 18 Keep Up with Emerging Security Standards ...................................................................................................................... 18 Emergency Preparedness ........................................................................................................................................................ 19 Back up your data file frequently ....................................................................................................................................... 19 Install Uninterruptible Power Supplies (UPS) ................................................................................................................... 19 Keep your business running when disaster strikes ............................................................................................................. 19 Further Information ................................................................................................................................................................ 20 Table 3: Security Web Sites ............................................................................................................................................... 20 How to Contact Us ................................................................................................................................................................. 20 Appendix A: Windows Account Security .............................................................................................................................. 21 Configuring Local User Accounts to be PCI Compliant .................................................................................................... 22 Setting Password Policies .................................................................................................................................................. 22 Setting Account Lockout Policies ...................................................................................................................................... 23 Setting Session Idle Time and Screensaver Options ...................................................................................................... 23 Appendix B: Encryption Key Management .......................................................................................................................... 24 3 Introduction The Payment Card Industry Data Security Standard (PCI DSS) includes requirements for the configuration, operation, and security of payment card transactions in your business. When you, as a retailer, start accepting payment cards you also agree to take the steps necessary to protect your customer’s card data. If you use the QuickBooks POS Merchant Service to authorize and settle credit or debit card transactions in Intuit QuickBooks Cash Register Plus, these standards and this guide apply to you. Adherence to the standards not only is good for your business, as it assures your customers that their transactions are being handled in a secure manner, but also is fiscally important–a security breach could result in significant fines11. When determining the measures that need to be taken for compliance, you need to review your entire system configuration: • Your operating system (Windows) configuration and account controls • Implementation of security software, such as antivirus and firewall applications • Implementation of and access controls to card payment applications (e.g., Intuit QuickBooks Cash Register Plus) • Your policies and procedures for implementing and monitoring all of the above This guide serves to help you implement Intuit QuickBooks Cash Register Plus and your overall system in such a manner to be in compliance with the PCI DSS. Table 1 summarizes the major PCI DSS requirements, what Intuit QuickBooks Cash Register Plus provides you to help meet the requirements, what you are responsible for, and where to get more information on that particular requirement. The remainder of this guide provides recommendations and instructions specific to steps you can take in your use of Intuit QuickBooks Cash Register