IBM Mainframe Forum Index
 
Log In
 
IBM Mainframe Forum Index Mainframe: Search IBM Mainframe Forum: FAQ Register
 

PCI DSS 1.2 Requirement 3.4 best practice


IBM Mainframe Forums -> All Other Mainframe Topics
Post new topic   Reply to topic
View previous topic :: View next topic  
Author Message
elmerv

New User


Joined: 13 Jul 2006
Posts: 3

PostPosted: Wed Sep 30, 2009 9:08 pm
Reply with quote

Hello,

We are undergoing a review of our controls for PCI compliance. Requirement 3.4 specifies that PAN must be rendered unreadable wherever it is stored. So if the source VSAM dataset contains PANs, does this mean the VSAM dataset needs to be encrypted? Or is RACF enough compensating control to satisfy the PCI requirement? Or is there any other solution?

Thank you.

Bew
Back to top
View user's profile Send private message
Robert Sample

Global Moderator


Joined: 06 Jun 2008
Posts: 8696
Location: Dubuque, Iowa, USA

PostPosted: Wed Sep 30, 2009 9:13 pm
Reply with quote

When we went through the PCI compliance process, it was determined that at a minimum the field had to be encrypted -- RACF access controls is not enough to meet the requirement. Data 21's ZIP-390 product, for one, supports field-level encryption and can be called from COBOL, SAS, PL/I, etc. I believe there are others that do this but I'm most familiar with ZIP-390.
Back to top
View user's profile Send private message
elmerv

New User


Joined: 13 Jul 2006
Posts: 3

PostPosted: Wed Sep 30, 2009 9:25 pm
Reply with quote

Thank you Robert. So we should be looking at encryption, then.
If you would be able to share, were there any performance issues
after implementing encryption?

Thanks.

Bew
Back to top
View user's profile Send private message
Robert Sample

Global Moderator


Joined: 06 Jun 2008
Posts: 8696
Location: Dubuque, Iowa, USA

PostPosted: Wed Sep 30, 2009 9:45 pm
Reply with quote

No, no performance issues showed up since we did only the field, not the entire file.
Back to top
View user's profile Send private message
elmerv

New User


Joined: 13 Jul 2006
Posts: 3

PostPosted: Wed Sep 30, 2009 10:03 pm
Reply with quote

I'll advise them to look into encryption.

Appreciate your input.

Thanks.

Bew
Back to top
View user's profile Send private message
View previous topic :: :: View next topic  
Post new topic   Reply to topic View Bookmarks
All times are GMT + 6 Hours
Forum Index -> All Other Mainframe Topics

 


Similar Topics
Topic Forum Replies
No new posts Urgent requirement for MF (Exp - 4 to... Mainframe Jobs 0
No new posts Need inputs on Space requirement and... IMS DB/DC 0
No new posts SORT requirement COBOL Programming 6
This topic is locked: you cannot edit posts or make replies. Mainframe Developer requirement in Ku... Mainframe Jobs 0
No new posts Cards mainframe developer requirement... Mainframe Jobs 0
Search our Forums:

Back to Top