Click here to get back home

File/Folder encryption - Compliancy with PCI

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
File/Folder encryption - Compliancy with PCI The Poster 09-28-2005
Posted by The Poster on September 28, 2005, 10:31 am
Please log in for more thread options
G/Day forum,

I'm looking for a File/Folder encryption solution (aside from EFS) for my
Windows 2000 based file server. This is based on one of the requirements of
Visa/MasterCards PCI Data Security Standard - http://snipurl.com/fhzg .

To achieve compliancy with PCI DSS, we need to imply the following controls
on credit card data:

1) to encrypt data at a folder level - that is all of the containing folders
and files
2) to allow for split knowledge of encryption keys and management thereof
3) to allow for strong encryption support (algorithms like 3DES, AES, etc)
4) a mechanism for automating the encryption process on a daily basis - this
is coincide with a backup cycle (no clear text credit card files get backed
up onto tape)

Your thoughts on any products that suit my requirements?

Regards,
Steve.




Posted by Roger Abell [MVP] on October 2, 2005, 8:00 am
Please log in for more thread options
Just out of curiosity, are you believing that use of EFS cannot
acheive one or more of your listed requirements ? (as I did not
see one)

--
Roger Abell
Microsoft MVP (Windows Server : Security)
MCDBA, MCSE W2k3+W2k+Nt4
> G/Day forum,
>
> I'm looking for a File/Folder encryption solution (aside from EFS) for my
> Windows 2000 based file server. This is based on one of the requirements
> of
> Visa/MasterCards PCI Data Security Standard - http://snipurl.com/fhzg .
>
> To achieve compliancy with PCI DSS, we need to imply the following
> controls
> on credit card data:
>
> 1) to encrypt data at a folder level - that is all of the containing
> folders
> and files
> 2) to allow for split knowledge of encryption keys and management thereof
> 3) to allow for strong encryption support (algorithms like 3DES, AES, etc)
> 4) a mechanism for automating the encryption process on a daily basis -
> this
> is coincide with a backup cycle (no clear text credit card files get
> backed
> up onto tape)
>
> Your thoughts on any products that suit my requirements?
>
> Regards,
> Steve.
>
>




Posted by The Poster on October 3, 2005, 4:57 pm
Please log in for more thread options
Apparently the credit card companies in question do not approve of EFS (as
per our Auditors) - pity that because its exactly what I'm looking for.

Regards,
Steve.

> Just out of curiosity, are you believing that use of EFS cannot
> acheive one or more of your listed requirements ? (as I did not
> see one)
>
> --
> Roger Abell
> Microsoft MVP (Windows Server : Security)
> MCDBA, MCSE W2k3+W2k+Nt4
> > G/Day forum,
> >
> > I'm looking for a File/Folder encryption solution (aside from EFS) for
my
> > Windows 2000 based file server. This is based on one of the requirements
> > of
> > Visa/MasterCards PCI Data Security Standard - http://snipurl.com/fhzg .
> >
> > To achieve compliancy with PCI DSS, we need to imply the following
> > controls
> > on credit card data:
> >
> > 1) to encrypt data at a folder level - that is all of the containing
> > folders
> > and files
> > 2) to allow for split knowledge of encryption keys and management
thereof
> > 3) to allow for strong encryption support (algorithms like 3DES, AES,
etc)
> > 4) a mechanism for automating the encryption process on a daily basis -
> > this
> > is coincide with a backup cycle (no clear text credit card files get
> > backed
> > up onto tape)
> >
> > Your thoughts on any products that suit my requirements?
> >
> > Regards,
> > Steve.
> >
> >
>
>




Posted by Martin on November 24, 2005, 11:21 am
Please log in for more thread options
I am an auditor from a Qualified Security Assessor for Visa/MC PCI DSS
Assessments.
I would be interested to discuss further the possible use of EFS in regards
to compliance to PCI.
If interested please provide me with some contact details.

"The Poster" wrote:

> Apparently the credit card companies in question do not approve of EFS (as
> per our Auditors) - pity that because its exactly what I'm looking for.
>
> Regards,
> Steve.
>
> > Just out of curiosity, are you believing that use of EFS cannot
> > acheive one or more of your listed requirements ? (as I did not
> > see one)
> >
> > --
> > Roger Abell
> > Microsoft MVP (Windows Server : Security)
> > MCDBA, MCSE W2k3+W2k+Nt4
> > > G/Day forum,
> > >
> > > I'm looking for a File/Folder encryption solution (aside from EFS) for
> my
> > > Windows 2000 based file server. This is based on one of the requirements
> > > of
> > > Visa/MasterCards PCI Data Security Standard - http://snipurl.com/fhzg .
> > >
> > > To achieve compliancy with PCI DSS, we need to imply the following
> > > controls
> > > on credit card data:
> > >
> > > 1) to encrypt data at a folder level - that is all of the containing
> > > folders
> > > and files
> > > 2) to allow for split knowledge of encryption keys and management
> thereof
> > > 3) to allow for strong encryption support (algorithms like 3DES, AES,
> etc)
> > > 4) a mechanism for automating the encryption process on a daily basis -
> > > this
> > > is coincide with a backup cycle (no clear text credit card files get
> > > backed
> > > up onto tape)
> > >
> > > Your thoughts on any products that suit my requirements?
> > >
> > > Regards,
> > > Steve.
> > >
> > >
> >
> >
>
>
>

Similar ThreadsPosted
[Q] Kerberos DES encryption April 20, 2007, 6:11 am
Encryption information request September 20, 2006, 3:52 pm
Outlook encryption plugin October 24, 2006, 2:59 am
Smartcard / NTFS Encryption May 13, 2007, 7:37 pm
Mixed environment - encryption. July 20, 2008, 2:59 pm
Store Passwords Using Reversible Encryption June 15, 2005, 10:44 pm
Replace the VPN's encryption algorithm March 12, 2006, 9:34 am
Shared key for 3des IPSEC encryption September 18, 2006, 6:51 am
BitLocker Data Volume Encryption March 30, 2007, 2:36 pm
Autoenrollment of encryption certs and Outlook configuration June 8, 2005, 10:25 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap