Sunday, 7 November 2010

PCI DSS 2.0 Addresses Virtualisation

The Payment Card Industry (PCI) has released version 2.0 of the Data Security Standard (DSS), an update to its 1.2.1 version.

PCI DSS 2.0 focuses on clarity of language for a number of key areas, including virtualisation.

The addition of the virtualisation concept into the standard reflects the importance of this technology and its operational impact within the PCI community, but there are still related security challenges that need to be addressed. Adding virtualisation into the standard is movement in the right direction, but without any real guidance on how to ensure virtualisation compliance, how effective can it be?

The PCI DSS 1.2.1 specification has a requirement that only one primary function per server be implemented, which has led to confusion for those using virtual machines in their environments. It wasn't clear in looking at the 1.2 specification if it permitted two or more virtual machines to run on the same physical server (one of the main reasons behind using virtualisation). The 2.0 specification at least seems to clarify that issue by allowing multiple VMs on the same physical hardware -- that is, as long as each VM is only performing one primary task.

Specifically, requirement 2.2.1 states the following:

Implement only one primary function per server to prevent functions that require different security levels from co-existing on the same server. (For example, web servers, database servers, and DNS should be implemented on separate servers.)

Note: Where virtualisation technologies are in use, implement only one primary function per virtual system component.

Other areas of note are:

If virtualisation is implemented, all components within the virtual environment will need to be identified and considered in scope for the review, including the individual virtual hosts or devices, guest machines, applications, management interfaces, central management consoles, hypervisors, etc. All intra-host communications and data flows must be identified and documented, as well as those between the virtual component and other system components.

The implementation of a virtualised environment must meet the intent of all requirements, such that the virtualised systems can effectively be regarded as separate hardware. For example, there must be a clear segmentation of functions and segregation of networks with different security levels; segmentation should prevent the sharing of production and test/development environments; the virtual configuration must be secured such that vulnerabilities in one function cannot impact the security of other functions; and attached devices, such as USB/serial devices, should not be accessible by all virtual instances.

PCI DSS 2.0 takes effect on Jan. 1, 2011, and represents the first significant update to the standard in over a year. Annual audits that occur after that date will be subject to the new standards. With the wording in the requirements being somewhat vague, and the fact that interpretations can vary from one auditor to the next, you might want to start your planning now to make sure your environment fits within these new guidelines.