Society of Payment Security Professionals Forum  

Go Back   Society of Payment Security Professionals Forum > Discussion Groups > PA-DSS (PABP)

Reply
 
Thread Tools Display Modes
  #1  
Old 10-12-2009, 11:22 AM
Jeff Carolus Jeff Carolus is offline
Junior Member
 
Join Date: Jun 2009
Location: Sunrise Beach, Missouri
Posts: 5
Default Payment Application Authentication

I have a payment application that is being prepared for Pa-Dss and have many questions, but one specific now.

Are the Pa-Dss requirements in line with the Pci-Dss requirements for password changes, length, re-using paswords, lockouts, etc.. (8.5.9 - 8.5.15) I can see having these strict controls for networks and servers, but in my case there is no "administrative access" to cardholder data allowed by the payment application.

Thanks for any help.
Reply With Quote
  #2  
Old 10-12-2009, 02:34 PM
jbhall56's Avatar
jbhall56 jbhall56 is offline
Senior Member
 
Join Date: Feb 2007
Location: Minneapolis, MN
Posts: 1,277
Default

Yes, the PA-DSS's password management requirements are aligned with the PCI DSS requirements.

That said, they only really apply at the PA-DSS level if the application is managing the authentication process. If you rely on Active Directory, RADIUS or some other outside authentication process, then you are off the hook. However, you need to document in the implementation guide that the outside directory needs to comply with the PCI DSS requirements.
__________________
Jeff Hall, Director, Risk Advisory Services
RSM McGladrey Inc
801 Nicollet Mall, 11th Floor, West Tower
Minneapolis, MN 55402-2526
612 376 9280 - office
612 395 7280 - facsimile
www.mcgladrey.com

The views presented are those of the writer and are not necessarily those of RSM McGladrey Inc
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 05:57 AM.


Copyright (c) The Aegenis Group, Inc.