Course: IT-313-J1660 Risk Mgmt./Mitigation Sys Des 20EW1
Student's name: Salome Odipo
Name of School: South New Hampshire University
Date: 20th September 2020
Interactions
Fertilizer Plus, a small agricultural company that produces and sells fertilizer products.
The company's senior management has recently decided to accept credit card payments from its
customers, both from store locations and online transactions. PCI DSS is the global data security
standard adopted by the payment card brands for all entities that process, store or transmit
cardholder data and/or sensitive authentication data (Yuliato,2016). The following are some of
the interactions between the objectives of and requirements of PCI DSS and the company:
Since an objectives of PCI DSS is to allow secure card payments to be made, Fertilizer
Plus should build a secure network
Protecting card holder data from breach
Maintaining a vulnerability management program
Implement strong access control measures
Regular monitoring and testing the network
Best Practices
The following are some of the best practices an organization needs to adopt, to effectively
implement and maintain PCI DSS objectives and requirements:
Install and maintain a firewall configuration to protect cardholder data
Do not use vendor-supplied defaults for system passwords and other security
parameters
: Protect stored cardholder data
: Encrypt transmission of cardholder data across open, public networks
Use and regularly update anti-virus software
Develop and maintain secure systems and applications
Restrict access to cardholder data by business need-to-know
:Assign a unique ID to each person with computer access
.: Restrict physical access to cardholder data
: Track and monitor all access to network resources and cardholder data
: Regularly test security systems and processes
Maintain a policy that addresses information security for all pers