27.04.2015 Views

eToken - SafeNet

eToken - SafeNet

eToken - SafeNet

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Achieving PCI DSS Compliance with<br />

Aladdin <strong>eToken</strong> Strong Authentication Solutions<br />

The Payment Card Industry Data Security Standard (PCI DSS) was created by the world’s major credit card companies to protect<br />

customer data. The primary purpose of PCI DSS is the protection of credit card data by reducing fraud and theft. PCI DSS mandates that<br />

any merchants or service providers that handle, transmit, store or process information concerning the major credit cards, or related<br />

card data, are required to meet PCI standards or face penalties and/or severance by the credit card companies.<br />

PCI DSS is a proactive security standard that defines requirements for security management, policies, procedures, network architecture,<br />

software design and other security measures. Aladdin is highly suited to meet and exceed PCI DSS requirements by providing unique<br />

and effective security solutions for merchants and service providers that must meet PCI standards.<br />

Aladdin’s <strong>eToken</strong> solutions help organizations comply with PCI DSS as follows:<br />

Build and maintain a secure network<br />

• Do not use vendor-supplied or default passwords<br />

<strong>eToken</strong> replaces weak passwords with strong, two-factor authentication and<br />

also eliminates the need for risky and costly password maintenance schemes with<br />

<strong>eToken</strong> Single Sign-On.<br />

Protect cardholder data<br />

• Protect stored data<br />

<strong>eToken</strong> ensures that only authorized users are able to access the network and thus access stored data. It also seamlessly integrates<br />

with all third-party disk encryption providers, enhancing security by ensuring that encryption keys are not exposed to untrusted and<br />

vulnerable PC environments.<br />

• Encrypt transmissions of cardholder data across public networks<br />

<strong>eToken</strong> enables email encryption and digital signing, with on-board generation and secure storage of PKI keys and certificates.<br />

Maintain a vulnerability management program<br />

• Develop and maintain secure systems and applications<br />

<strong>eToken</strong><br />

PCI DSS<br />

COMPLIANCE<br />

<strong>eToken</strong> helps organizations apply security controls by ensuring that users are who they say they are, whether within the network or<br />

remotely.<br />

A l a d d i n . c o m / e T o k e n


Implement Strong Access Control Measures<br />

• Restrict access to “need-to-know”<br />

<strong>eToken</strong> provides strong authentication support for role-based access control solutions, ensuring the highest possible level of control over<br />

who is accessing data. The <strong>eToken</strong> Token Management System (TMS) links users, devices, organizational rules, and security applications in a<br />

single automated and fully configurable system, making the implementation of token-based security solutions easily manageable.<br />

• Assign unique IDs to each person with computer access<br />

<strong>eToken</strong> provides a unique ID for users, based on the high security of two-factor authentication: users must not only know their<br />

username and password, but also have possession of their physical <strong>eToken</strong> to gain access.<br />

• Restrict physical access to cardholder data<br />

<strong>eToken</strong> can be shipped with all market-leading RFID coils to deliver both physical and logical access controls in one device.<br />

Regularly monitor and test networks<br />

• Monitor and track all access to network resources and cardholder data<br />

Equipped with auditing and reporting capabilities, the <strong>eToken</strong> Token Management System enables the monitoring and control of data access.<br />

Maintain an Information Security Policy<br />

• Maintain a policy that addresses information security<br />

Aladdin solutions provide strong controls over network access and content security, and eliminate common methods used to bypass<br />

organizational security – allowing organizations to more easily enforce their security policy.<br />

For more information on how Aladdin can help your organization meet the Payment Card Industry Data Security Standard, contact an<br />

Aladdin representative.<br />

© 8/2008 Aladdin Knowledge Systems, Ltd. All rights reserved. Aladdin is a registered trademark and <strong>eToken</strong> is a trademark of Aladdin Knowledge Systems, Ltd. All other names are trademarks or registered trademarks of their respective owners.<br />

For more contact information, visit: www.Aladdin.com/contact<br />

North America: +1-800-562-2543, +1-847-818-3800 • UK: +44-1753-622-266 • Germany: +49-89-89-4221-0 • France: +33-1-41-37-70-30 • Benelux: +31-30-688-0800 • Spain: +34-91-375-99-00<br />

Italy: +39-022-4126712 • Israel: +972-3-978-1111 • China: +86-21-63847800 • India: +91-22-67955943 • Japan: +81-426-607-191 • All other inquiries: +972-3-978-1111

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!