29.06.2015 Views

Minimize the Impact of PCI Section 3 on SAP Applications - Paymetric

Minimize the Impact of PCI Section 3 on SAP Applications - Paymetric

Minimize the Impact of PCI Section 3 on SAP Applications - Paymetric

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

• Segregati<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> card data from applicati<strong>on</strong>s. Unencrypted data never resides<br />

in <strong>SAP</strong> or o<str<strong>on</strong>g>the</str<strong>on</strong>g>r applicati<strong>on</strong>s. <strong>SAP</strong> users never see payment data in clear text<br />

unless <str<strong>on</strong>g>the</str<strong>on</strong>g>y have specific, valid authority.<br />

• Reduced exposure <str<strong>on</strong>g>of</str<strong>on</strong>g> keys. <str<strong>on</strong>g>PCI</str<strong>on</strong>g> requirements 3.5.1 and 3.5.2 mandate that access<br />

to keys is restricted to <str<strong>on</strong>g>the</str<strong>on</strong>g> fewest number <str<strong>on</strong>g>of</str<strong>on</strong>g> custodians and that keys are stored<br />

securely in <str<strong>on</strong>g>the</str<strong>on</strong>g> fewest possible locati<strong>on</strong>s. By centralizing keys <strong>on</strong> a secure server,<br />

an encrypti<strong>on</strong> management server optimally addresses <str<strong>on</strong>g>the</str<strong>on</strong>g>se requirements.<br />

• <str<strong>on</strong>g>Impact</str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> breach limited. With this approach, if an attacker somehow bypasses<br />

both <str<strong>on</strong>g>the</str<strong>on</strong>g> token and encrypti<strong>on</strong>, <str<strong>on</strong>g>the</str<strong>on</strong>g>y will <strong>on</strong>ly have access to <strong>on</strong>e card number.<br />

In c<strong>on</strong>trast, with many encrypti<strong>on</strong> soluti<strong>on</strong>s, if an attacker gains access to <strong>on</strong>e<br />

cryptographic key, <str<strong>on</strong>g>the</str<strong>on</strong>g>y can potentially decrypt thousands or even hundreds<br />

<str<strong>on</strong>g>of</str<strong>on</strong>g> thousands <str<strong>on</strong>g>of</str<strong>on</strong>g> records<br />

If an attacker<br />

somehow<br />

bypasses both<br />

<str<strong>on</strong>g>the</str<strong>on</strong>g> token and<br />

encrypti<strong>on</strong>, <str<strong>on</strong>g>the</str<strong>on</strong>g>y<br />

will have access<br />

to <strong>on</strong>ly <strong>on</strong>e card<br />

number.<br />

Optimized <strong>SAP</strong> Performance and Availability<br />

Through employing an encrypti<strong>on</strong> management server, organizati<strong>on</strong>s can enjoy a range <str<strong>on</strong>g>of</str<strong>on</strong>g><br />

advantages in integrati<strong>on</strong> and performance:<br />

• Improved applicati<strong>on</strong> processing. Tokens can be passed between <strong>SAP</strong> and o<str<strong>on</strong>g>the</str<strong>on</strong>g>r applicati<strong>on</strong>s<br />

without requiring any encrypti<strong>on</strong> or decrypti<strong>on</strong>, thus also providing encrypti<strong>on</strong><br />

“<strong>on</strong>-<str<strong>on</strong>g>the</str<strong>on</strong>g>-wire” at system integrati<strong>on</strong> points. Fur<str<strong>on</strong>g>the</str<strong>on</strong>g>r, <strong>SAP</strong> is freed from having to do resourceintensive<br />

cryptographic processing. This can significantly streamline transacti<strong>on</strong>s across <str<strong>on</strong>g>the</str<strong>on</strong>g><br />

enterprise.<br />

• Optimized applicati<strong>on</strong> availability. Full key rotati<strong>on</strong> can be realized without <strong>SAP</strong> downtime<br />

as this will occur in a separate system entirely.<br />

• Smart tokens. Smart tokens, tokens that feature embedded strings, can be used and can<br />

eliminate <str<strong>on</strong>g>the</str<strong>on</strong>g> need to do frequent decrypti<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> data for reporting and related purposes.<br />

Simplified Administrati<strong>on</strong><br />

Tokenizati<strong>on</strong> significantly eases <str<strong>on</strong>g>the</str<strong>on</strong>g> administrative burden <str<strong>on</strong>g>of</str<strong>on</strong>g><br />

encrypti<strong>on</strong>, <str<strong>on</strong>g>of</str<strong>on</strong>g>fering a range <str<strong>on</strong>g>of</str<strong>on</strong>g> administrative advantages:<br />

• <str<strong>on</strong>g>Minimize</str<strong>on</strong>g>d compliance requirements. By removing<br />

payment data from disparate repositories, <str<strong>on</strong>g>the</str<strong>on</strong>g> cost <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>PCI</str<strong>on</strong>g><br />

is drastically reduced. Instead <str<strong>on</strong>g>of</str<strong>on</strong>g> implementing encrypti<strong>on</strong>,<br />

managing keys, and implementing policies <strong>on</strong> multiple<br />

systems, <strong>on</strong>ly <strong>on</strong>e central server will be <str<strong>on</strong>g>the</str<strong>on</strong>g> focus <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>PCI</str<strong>on</strong>g><br />

encrypti<strong>on</strong> efforts.<br />

Tokens can be passed<br />

between <strong>SAP</strong> and o<str<strong>on</strong>g>the</str<strong>on</strong>g>r applicati<strong>on</strong>s<br />

without requiring any<br />

encrypti<strong>on</strong> or decrypti<strong>on</strong>...<br />

• Streamlined key management. All keys and policies can be managed centrally, as opposed<br />

to having keys in multiple, distributed locati<strong>on</strong>s. This makes such <str<strong>on</strong>g>PCI</str<strong>on</strong>g>-required tasks as key<br />

revocati<strong>on</strong> and rotati<strong>on</strong> much faster and easier.<br />

© 2008 <strong>Paymetric</strong>, Inc. All rights reserved.<br />

.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!