policies:new_cde_component

New CDE Component

Gemporia recognises that payment card information is a valuable asset. Managing security systems and the information they contain is vital to maintain Gemporia’s reputation and the ability to continue trading successfully.

Gemporia considers the security of its cardholder data environment (CDE) and cardholder data to be a crucial element of its business and, to this end, has created a well-defined set of policies, standards and procedures to support secure operations

The aim of this policy document is to lay out how Gemporia will integrate new hardware and software components into the CDE in order to uphold security standards required and desired for this role.

This policy applies to the people, processes and technology that install, either directly or indirectly, new hardware or software within the CDE.

This policy document is designed to be used in conjunction with the appropriate implementation standards as defined by Gemporia in accordance with best practices.

3.1.1 All unnecessary services and protocols shall be disabled

3.1.2 All necessary services and protocols shall be justified and documented

3.1.3 All vendor defaults shall be changed where possible

3.1.4 All common security parameters shall be changed where possible

3.1.5 All non-console administrative access shall be encrypted using strong encryption techniques such as TLS, SSHv2

3.1.6 All web based management shall be carried over HTTPS where possible

3.2.1 All encryption shall be strong and in-line with best practices

3.2.2 All defaults including SNMP community strings shall be changed

3.3.1 The asset shall be recorded on the CDE asset register

3.4 Post installation in CDE

3.4.1 All internal and external vulnerability scans will be re-run if change is significant

3.4.2 All internal and external vulnerability scans will be re-run if a high risk vulnerability is discovered

Date Description
12/08/2015 Original Document Andrew Smith
23/09/2015 Added 3.2 Andrew Smith
08/11/2015 Modified 3.1.5 to remove SSL Andrew Smith
02/12/2015 Added 3.4 and 3.4.1 Andrew Smith
01/11/2016 Changed TGGC to Gemporia Andrew Smith
07/11/2016 Added 3.4.2 Andrew Smith
TypeError: array_filter(): Argument #1 ($array) must be of type array, null given

TypeError: array_filter(): Argument #1 ($array) must be of type array, null given

An unforeseen error has occured. This is most likely a bug somewhere. It might be a problem in the authchained plugin.

More info has been written to the DokuWiki error log.