Society of Payment Security Professionals Forum  

Go Back   Society of Payment Security Professionals Forum > Discussion Groups > PCI DSS Q&A

Reply
 
Thread Tools Display Modes
  #1  
Old 02-05-2009, 07:27 AM
vot_ol vot_ol is offline
Junior Member
 
Join Date: Jan 2009
Posts: 7
Default PCI DSS req.9.2

Hi!

The Bank has the following procedure: all visitors can move inside building only with accompanying person.
The Bank supposes that they don’t need procedures to help all personnel easily distinguish between employees and visitors.

Can QSA-assessor write non-compliance for req 9.2?

Thank you!
Reply With Quote
  #2  
Old 02-05-2009, 10:32 PM
alphonze alphonze is offline
Junior Member
 
Join Date: Feb 2009
Posts: 17
Default

That sounds non-compliant to me. After all, if there is no way to tell the difference between a visitor and a staff-member, then how can anyone be sure whether an unaccompanied person is a legitimate staff-member or an unauthorised visitor?! And if the bank staff do not know *all* the other bank staff, how can they tell if two people are a visitor and his escort, or *two visitors*!?

The intent here seems clear: staff need to be able to identify someone who shouldn't be there, so they can take action if there is an intruder, or an "escaped" visitor.

It's good that the bank has procedures to escort visitors. But those procedures are irrelevant. What is relevant is that when something unusual or abnormal happens, it can be detected.
Reply With Quote
  #3  
Old 02-06-2009, 02:29 AM
neobaby neobaby is offline
Junior Member
 
Join Date: Jan 2009
Posts: 14
Default Different ID Cards

What we have done is provided two different types of ID Cards, one for normal staffs with facility to use as the physical access card ( Magnetic striped ) and for all non employee a different card ( simple plastic ) . This will help to easily distinguish and requires an employee to accompany him .In addition consultants who are in the company for a short period of time, like 1 month are given another access card with a defined expiry period
Reply With Quote
  #4  
Old 02-06-2009, 05:38 AM
jbhall56's Avatar
jbhall56 jbhall56 is offline
Senior Member
 
Join Date: Feb 2007
Location: Minneapolis, MN
Posts: 1,282
Default

Another easy way to comply is to use the name tags you can buy at Office Max or Staples and then use Word to print them up.

On the tag you should print in RED ink the word 'VISITOR' in a bold, somewhat large font. Underneath that, print the visitor's name in BOLD and so that it can be easily read. Underneath their name, have the field of print date so that people can know when the badge was created.
__________________
Jeff Hall, Director, Risk Advisory Services
RSM McGladrey Inc
801 Nicollet Mall, 11th Floor, West Tower
Minneapolis, MN 55402-2526
612 376 9280 - office
612 395 7280 - facsimile
www.mcgladrey.com

The views presented are those of the writer and are not necessarily those of RSM McGladrey Inc
Reply With Quote
  #5  
Old 06-22-2009, 11:10 AM
LJKSoftware LJKSoftware is offline
Senior Member
 
Join Date: Jun 2009
Location: Newton, Massachusetts
Posts: 120
Default Self-expiring ID badges

Quote:
Originally Posted by jbhall56 View Post
On the tag you should print in RED ink the word 'VISITOR' in a bold, somewhat large font. Underneath that, print the visitor's name in BOLD and so that it can be easily read. Underneath their name, have the field of print date so that people can know when the badge was created.
There are printable visitor badges manufactured that expire automatically with the passage of time, to prevent a former visitor from re-using a badge in front of employees who do not read the date carefully.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 02:37 PM.


Copyright (c) The Aegenis Group, Inc.