Covering PCI and PA DSS)
Total Page:16
File Type:pdf, Size:1020Kb
Monetra® Payment Software Secure Implementation Guide (Covering PCI and PA DSS) Revision: 4.1 Publication date February 20, 2018 Copyright © 2018 Main Street Softworks, Inc. Secure Implementation Guide: (Covering PCI and PA DSS) Main Street Softworks, Inc. Revision: 4.1 Publication date February 20, 2018 Copyright © 2018 Main Street Softworks, Inc. Legal Notice The information contained herein is provided As Is without warranty of any kind, express or implied, including but not limited to, the implied warranties of merchantability and fitness for a particular purpose. There is no warranty that the information or the use thereof does not infringe a patent, trademark, copyright, or trade secret. Main Street Softworks, Inc. shall not be liable for any direct, special, incidental, or consequential damages resulting from the use of any information contained herein, whether resulting from breach of contract, breach of warranty, negligence, or otherwise, even if Main Street has been advised of the possibility of such damages. Main Street reserves the right to make changes to the information contained herein at anytime without notice. No part of this document may be reproduced or transmitted in any form or by any means, electronic or mechanical, for any purpose, without the express written permission of Main Street Softworks, Inc. Table of Contents 1. Revision History .......................................................................................................... 1 2. Monetra Security Validation (PA-DSS) ......................................................................... 2 2.1. Do Not Retain Sensitive Data ............................................................................ 2 2.2. Stored Data Protection ....................................................................................... 4 2.3. Provide Secure Password Features ...................................................................... 7 2.4. Log Application Activity ................................................................................... 8 2.5. Develop Secure Applications .............................................................................. 9 2.6. Protect Wireless Transmissions ......................................................................... 11 2.7. Test for Application Vulnerabilities .................................................................. 12 2.8. Facilitate Secure Network Implementations ....................................................... 13 2.9. Never Store Cardholder Data on the Internet ..................................................... 13 2.10. Facilitate Secure Remote Application Access .................................................. 14 2.11. Encrypt Traffic Over Public Networks ............................................................ 15 2.12. Encrypt All Non-Console Administrative Access ............................................. 15 2.13. Maintain instructional material for customers and integrators ............................ 16 3. Monetra Payment System ............................................................................................ 17 3.1. General Overview ............................................................................................ 17 3.2. Architecture ..................................................................................................... 18 3.3. Application Data and Logging .......................................................................... 19 3.3.1. External Logging .................................................................................. 19 3.3.2. Application Data Storage ....................................................................... 23 3.4. SNMP Monitoring ........................................................................................... 25 3.4.1. SNMP Monetra Architecture .................................................................. 26 3.4.2. SNMP Data Elements ............................................................................ 26 3.4.3. Installing SNMP ................................................................................... 28 3.4.4. Configuring SNMP ............................................................................... 28 3.4.5. Configure Monetra for SNMP ................................................................ 30 3.5. Monetra Virtual User SubSystem ...................................................................... 30 3.5.1. Administrative User(s) ........................................................................... 31 3.5.2. System User(s) ...................................................................................... 31 3.5.3. System SubUser(s) ................................................................................ 31 3.6. Hardware Security Modules (HSM) .................................................................. 32 3.6.1. HSM Monetra Architecture .................................................................... 32 3.6.2. Supported HSM Devices ....................................................................... 33 3.6.3. Monetra HSM Configuration ................................................................. 33 3.7. Network Segmentation via Multi-PORT ............................................................ 38 3.8. Encryption Keys .............................................................................................. 41 3.8.1. Encryption Key Creation from a console ................................................ 42 3.8.2. Encryption Key Creation from the Monetra Manager .............................. 43 3.8.3. Encryption Key Creation (with pass phrase) ........................................... 43 3.8.4. Encryption Key Maintenance ................................................................. 47 3.9. Client Certificates (SSL) .................................................................................. 47 3.9.1. Certificate Authority Setup and Use ....................................................... 48 3.9.2. Restricting SSL Connections with Certificates ........................................ 50 3.9.3. Restricting User Access with Certificates ............................................... 52 3.10. Alternate File System Security ........................................................................ 53 Copyright © 2018 Main Street Softworks, Inc. | Secure Implementation Guide iii Secure Implementation Guide 3.10.1. Encrypted File Systems ....................................................................... 54 A. [SAMPLE] Cryptographic Material Custodian Agreement ........................................... 55 References ...................................................................................................................... 56 Copyright © 2018 Main Street Softworks, Inc. | Secure Implementation Guide iv 1 Revision History Version Date Changes v4.1 2018-02-20 • Added revision history section. v4.0 2015-09-23 • Updated doc to align with PA-DSS v3.1 Copyright © 2018 Main Street Softworks, Inc. | Secure Implementation Guide | CONFIDENTIAL 1 2 Monetra Security Validation (PA-DSS) 2.1. Do Not Retain Sensitive Data .................................................................................... 2 2.2. Stored Data Protection ............................................................................................... 4 2.3. Provide Secure Password Features .............................................................................. 7 2.4. Log Application Activity ........................................................................................... 8 2.5. Develop Secure Applications ...................................................................................... 9 2.6. Protect Wireless Transmissions ................................................................................. 11 2.7. Test for Application Vulnerabilities .......................................................................... 12 2.8. Facilitate Secure Network Implementations ............................................................... 13 2.9. Never Store Cardholder Data on the Internet ............................................................. 13 2.10. Facilitate Secure Remote Application Access .......................................................... 14 2.11. Encrypt Traffic Over Public Networks .................................................................... 15 2.12. Encrypt All Non-Console Administrative Access ..................................................... 15 2.13. Maintain instructional material for customers and integrators .................................... 16 Since its inception, Main Street has incorporated leading edge security practices and technologies directly into all software offerings. The following sections outline the Security Audit used to validate Monetra. They also outline the rolls associated with Monetra users, integrators and resellers when securely implementing Monetra into a PCI compliant production environment, as required by the PA- DSS standard. Version 4.x of this guide (Monetra Secure Implementation) aligns with PCI-DSS and PA-DSS Version(s) 3.1 dated May 2015 and should be used for all new deployments. This document has been updated to include all relevant information for customers deploying Monetra Version 7 up to update 14.8 and Monetra version 8.x.y History Note: The original documentation referenced the Visa PABP document v1.1 as posted on their website date: June 01 2005. Version 1.3 of this guide (Secure Implementation) referenced