PCI DSS applies to every organization around the world that processes credit or debit card information. Failing a PCI DSS audit can result in fines, but IT’s responsibilities extend beyond avoiding these penalties. Meeting PCI standards contributes to the security of your business by helping to avoid data breaches and all of their related costs: litigation, customer notification and compensation, damage to the company’s reputation, and diminished share value.
GoAnywhere is a cross-platform managed file transfer (MFT) solution that is designed to help you meet PCI DSS compliance requirements while saving you time and money. It can also eliminate the custom programming and scriptwriting normally required to transfer data, while improving the security and quality of those transfers.
SECURITY SETTINGS AUDIT REPORT
GoAnywhere MFT can analyse more than 60 different security settings to determine compliance with applicable sections of the Payment Card Industry Data Security Standards (PCI DSS). If a security setting does not meet the requirement, the report will indicate the corresponding PCI section and the recommendation on how to correct the security setting.
A Strategic Tool for Compliance and Beyond
GoAnywhere Managed File Transfer helps organizations meet the requirements of PCI DSS by providing a managed, centralised, and auditable solution. The benefits of GoAnywhere for security and compliance include:
Centralized control and management of file transfers
Role-based administration and permissions
Secure connections for the transmission of sensitive data
Encryption of data at rest and in motion
Strong encryption key management with separation of duties
Keeping PCI-related data out of the DMZ
Closed inbound ports into the private network to prevent intrusion
Detailed audit logs for reporting
PCI compliance requirements will continue to evolve, but by implementing robust solutions, forward-thinking IT shops can meet current requirements while laying a strong foundation for future security enhancements.
GoAnywhere Helps You Meet PCI DSS Data Transfer Security Requirements
GoAnywhere directly addresses several of the twelve PCI DSS requirements through features including encryption, role-based security, and audit logs.
Required Standards :
Install and maintain a firewall configuration to protect cardholder data :
IP addresses and ports are customizable in GoAnywhere, allowing flexibility with firewalls. Description fields make it easy to document why connections are used. Combined with GoAnywhere Gateway, full separation of internal data, DMZ, and public networks is simplified.
Do not use vendor-supplied defaults for system passwords and other security parameters :
The GoAnywhere Security Settings Audit report provides a detailed list of all GoAnywhere security defaults, enabled services, and configured security features. Using HTTPS will ensure that all administrative access is encrypted.
Protect stored cardholder data :
With GoAnywhere, your files are protected at rest using strong encryption methods like AES and OpenPGP. It also provides cryptographic key management. Data retention can also be automated.
Encrypt transmission of cardholder data across open public networks :
GoAnywhere protects transmissions over public and private networks using secure protocols including SFTP, FTPS, AS2, AS3, AS4, and HTTPS. TLS 1.1 and 1.2 are fully supported.
Use and regularly update anti-virus software or programs :
GoAnywhere can run on systems with third-party anti-virus solutions. It also supports ICAP integration for external scanning and data loss prevention.
Develop and maintain secure systems and applications :
GoAnywhere supports change control by working in conjunction with test, QA, or development systems, allowing easy promotion of projects from test to production while maintaining separation of duties. Project revisions are recorded, allowing easy rollback of changes.
Restrict access to cardholder data by business need-to-know :
GoAnywhere provides role-based security so each user only has access
to the information they need.
Assign a unique ID to each person with computer access :
GoAnywhere has full individual account management features. It can also integrate with LDAP and external RSA 2-factor authentication to satisfy all account requirements in PCI DSS.
Restrict physical access to cardholder data :
GoAnywhere’s multi-platform and virtual environment flexibility will allow you to run software and store data in your secure location.
Track and monitor all access to network resources and cardholder data :
With detailed audit logs, GoAnywhere makes it easy to monitor all activity on the system. Integration with external logging solutions is built in.