Saturday, May 11, 2019

PCI Compliance - Physical Security Requirements

Good afternoon all,

I recently started at a very small shop, however, they are required to become "more" PCI compliant. I believe our existing level is ~6% overall... which is incredibly scary.

I'm using this to my advantage to make things suck less... for example, one switching closet does not have a door...or a roof (open concept layout). It is just an open room accessible to staff and the public freely, with a switch connected to our (currently) flat network, with male ends on every cable plugged directly into the switch. They are old and beginning to fall off, so simply moving anything drops multiple connections. Fun times.

With PCI compliance -- I know part of the basics is physical security to the gear. If I were to put a patch panel in, and wall mount both it and the switch -- would I be able to simply put a 4U wallmount rack for the gear and add a door to the room, and be good to go? Or, because there is no ceiling, does that make the door a moot point?

Option #B is forget the door, get a locking cabinet, and be done with it.

Thanks in advance!



No comments:

Post a Comment