Society of Payment Security Professionals Forum  

Go Back   Society of Payment Security Professionals Forum > Discussion Groups > PCI DSS Q&A

Reply
 
Thread Tools Display Modes
  #1  
Old 03-18-2009, 03:27 AM
sniper sniper is offline
Junior Member
 
Join Date: Feb 2009
Posts: 3
Default MQ series and PCI Compliance

Has anyone had to address the issue of card data stored by IBM's MQ series? This could particularly be a problem when connectivity is lost and the MQ messages are queued up until connectivity is restored. Ther ecould be tens of thousands of queued messages containing card data!

If that challenge has been met by anyone previously then I would welcome advice on how to remediate it.

Thanks.
Reply With Quote
  #2  
Old 03-18-2009, 04:03 AM
jbhall56's Avatar
jbhall56 jbhall56 is offline
Senior Member
 
Join Date: Feb 2007
Location: Minneapolis, MN
Posts: 1,277
Default

Your MQ issue is no different than any system that batch processes transactions. Key requirements that you need meet include making sure the server(s) in question are properly hardened and secured, access to those servers is extremely limited and the data store is encrypted and only the key custodians and the necessary MQ processes have access to the encryption keys.

If you do all of this as well as meet all of the other relevant PCI requirements, then you should be compliant.
__________________
Jeff Hall, Director, Risk Advisory Services
RSM McGladrey Inc
801 Nicollet Mall, 11th Floor, West Tower
Minneapolis, MN 55402-2526
612 376 9280 - office
612 395 7280 - facsimile
www.mcgladrey.com

The views presented are those of the writer and are not necessarily those of RSM McGladrey Inc
Reply With Quote
  #3  
Old 03-18-2009, 12:04 PM
dbergert dbergert is offline
Member
 
Join Date: Mar 2007
Location: Iowa
Posts: 82
Default

Quote:
Originally Posted by sniper View Post
This could particularly be a problem when connectivity is lost and the MQ messages are queued up until connectivity is restored. There could be tens of thousands of queued messages containing card data!
Note the veribage noted in:
Quote:
Do not store sensitive authentication data after authorization (even if encrypted)
Notice it says after authorization - what your describe, SAF (Store and Forward) from a Payment Host/Switch to the payment endpoints/Networks.

That being said you need to have controls in place to protect the data, monitor the size of the queues, and others as Jeff suggests.
__________________
David Bergert, CISSP, CISA, CPISM/A
www.paymentsystemsblog.com
Reply With Quote
  #4  
Old 05-01-2009, 01:03 PM
derekwh derekwh is offline
Junior Member
 
Join Date: May 2009
Posts: 1
Cool MQ and PCI Compliance

yes - messages that sit on a queue are at risk, but more at risk are in-flight message that can be read, copied, replaced at will due to not implementing the objects and procedures specific to MQ that enable security (MQ is wide open out of the box, and is implemented that way maybe 90% of the time in my experience, with reliance on "network perimeter security" to also protect MQ).

Derek.
IBM Certified WebSphere MQ Specialist.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 05:53 AM.


Copyright (c) The Aegenis Group, Inc.