• Home
  • Southern New Hampshire University
  • Introduction to Data and Information Management IT204
  • Introduction to Data and Information Management

Introduction to Data and Information Management

Course: IT-313-J1660 Risk Mgmt./Mitigation Sys Des 20EW1 Student's name: Salome Odipo Name of School: South New Hampshire University Date: 20th September 2020 Interactions Fertilizer Plus, a small agricultural company that produces and sells fertilizer products. The company's senior management has recently decided to accept credit card payments from its customers, both from store locations and online transactions. PCI DSS is the global data security standard adopted by the payment card brands for all entities that process, store or transmit cardholder data and/or sensitive authentication data (Yuliato,2016). The following are some of the interactions between the objectives of and requirements of PCI DSS and the company: Since an objectives of PCI DSS is to allow secure card payments to be made, Fertilizer Plus should build a secure network Protecting card holder data from breach Maintaining a vulnerability management program Implement strong access control measures Regular monitoring and testing the network Best Practices The following are some of the best practices an organization needs to adopt, to effectively implement and maintain PCI DSS objectives and requirements: Install and maintain a firewall configuration to protect cardholder data Do not use vendor-supplied defaults for system passwords and other security parameters : Protect stored cardholder data : Encrypt transmission of cardholder data across open, public networks Use and regularly update anti-virus software Develop and maintain secure systems and applications Restrict access to cardholder data by business need-to-know :Assign a unique ID to each person with computer access .: Restrict physical access to cardholder data : Track and monitor all access to network resources and cardholder data : Regularly test security systems and processes Maintain a policy that addresses information security for all pers