secguy
04-27-2007, 10:58 AM
I have a question on how a auditor would look at POS in the following scenario.
All the stores use wireless for scanning inventory.
POS systems run MS. Only use of these systems is store activities. Such as inventory, cash register, sales activity tracking. etc… The stores POS tie into a POS master server that collects all the information. Night the stores communicate back to corp. They pass all the activity for that day. They communicate via dsl over VPN to corp. All data is encrypted. Firewalls at point of entry at each store. The POS do not email or use browsers. USB are locked down. We do have access from corp via VPN to each store system for patches, etc...The router at each store may use DHCP or static to the ISP. My question is would this be considered a private segment even though we have a public facing IP? There is no access from the internet only the VPN. I am trying to figure out if we need to use a vendor to run external scan to all these IP’s. PCI says all external facing addresses must be scanned, but what if we do not have any open services on those devices. I am curious how they do this with a router DHCP off an ISP anyway.
I am also trying to figure out if we need to protect these same way we would a Desktop.
If these systems are only for one app and do not run any normal browsers, mail, etc. Would we be required to run A/V, firewall, hips, etc.?
All the stores use wireless for scanning inventory.
POS systems run MS. Only use of these systems is store activities. Such as inventory, cash register, sales activity tracking. etc… The stores POS tie into a POS master server that collects all the information. Night the stores communicate back to corp. They pass all the activity for that day. They communicate via dsl over VPN to corp. All data is encrypted. Firewalls at point of entry at each store. The POS do not email or use browsers. USB are locked down. We do have access from corp via VPN to each store system for patches, etc...The router at each store may use DHCP or static to the ISP. My question is would this be considered a private segment even though we have a public facing IP? There is no access from the internet only the VPN. I am trying to figure out if we need to use a vendor to run external scan to all these IP’s. PCI says all external facing addresses must be scanned, but what if we do not have any open services on those devices. I am curious how they do this with a router DHCP off an ISP anyway.
I am also trying to figure out if we need to protect these same way we would a Desktop.
If these systems are only for one app and do not run any normal browsers, mail, etc. Would we be required to run A/V, firewall, hips, etc.?