Policy, Standards, Regulations & Compliance
PCI Validation and Compliance questions/discussion Dec 05 2005 06:27PM
Justin Knox (knox justin gmail com) (1 replies)
Hi all,
I'm the network administrator for a small business. We've been working
for most of this year to re-align ourselves to better meet things like
the PCI. We're coming down to budgeting time, and our interpretation
of a few of these items is leading us towards some very expensive
upgrades and overhauls to our infrastructure. Specifically, we're
looking at Requirement 2.2.1: Implement only one primary function per
server (e.g., web servers, database servers, and DNS should be
implemented on separate servers). Obviously, best practice dictates
this. Frequently, this may not be implemented due to an executive
decision based entirely upon the financial outlay required to do this.

My question is, how are others handling this requirement? Before we
submit our budget proposal(s) to the executives here we want to have
further support for our proposal argument. If you have been validated
or are working towards validation, please let me know how you are
handling this and other requirements.

Thanks,
Justin

--
Justin Knox CCNA, MCP
Network Administrator

[ reply ]
Re: PCI Validation and Compliance questions/discussion Dec 05 2005 08:59PM
Fred Cohen (fred cohen all net) (1 replies)
Re: PCI Validation and Compliance questions/discussion Dec 05 2005 09:22PM
Justin Knox (knox justin gmail com)


 

Privacy Statement
Copyright 2010, SecurityFocus