Network Management

Payment Card Industry (PCI) compliance

This article provides information on the Payment Card Industry and SolarWinds compliance.

First published date

10/31/2018 10:34 PM

Last published date

9/20/2022 2:37 PM

Overview

This article provides information on the Payment Card Industry and SolarWinds compliance. 

Product section

Orion Platform

Resolution

The Payment Card Industry Data Security Standard (PCI DSS, sometimes PCI for brevity) is a set of requirements designed to ensure all companies processing, storing, or transmitting credit card information maintain a secure environment.

PCI applies to all organizations or merchants, regardless of size or number of transactions, accepting, transmitting, or storing any cardholder data.

Several SolarWinds® products can help with various areas of the Payment Card Industry (PCI) Data Security Standards (DSS) (© 2019 PCI Security Standards Council, available at www.pcisecuritystandards.org , obtained on November 19, 2019) requirements. The purpose of the PCI DSS is to set a baseline of minimum security for any vendor taking card payments. This is good for the consumer as it (theoretically) institutes best practices to reduce the risk of a security breach potentially exposing their data, making PCI compliant vendors less likely to put you and I at risk for identity theft. Regulations such as PCI DSS can be helpful for IT organizations looking to justify budgets for security and privacy initiatives. However, it also becomes an ongoing cost due to many of the controls being continuous mandates to help you stay out of the headlines.
 

WHAT DOES SOLARWINDS DO FOR PCI DSS COMPLIANCE?

The PCI DSS is broken down into several sections. These sections cover everything from physical security requirements, to secure IT implementation, and general scanning and monitoring. Below are the SolarWinds products able to help users address or assist with the various requirements of PCI DSS:
 

SOLARWINDS PATCH MANAGER

Patch Manager provides integration with native Windows patching technology (WSUS/SCCM) and provides built-in third-party application patching. You can read more about Patch Manager’s Windows patch management features , but here are the specific items it can help with:
Addressing PCI Requirement:

  • 6.2: Ensure software has latest patches within one month of release: Patch Manager enables you to deploy both Microsoft and third-party updates to ensure machines are kept up-to-date. Out-of-the-box reports allow for easy identification of missing patches and alert you on what machines haven’t been patched within the last month.

Assisting With PCI Requirement:

  • 5.2: Ensure all antivirus mechanisms are current: Patch Manager can perform software inventory to identify all applications installed including their versions. Out-of-date antivirus software can be identified through out-of-the-box software inventory reports.
  • 6.4: Follow change control processes and procedures for all changes to system components: Patch Manager provides granular control over which patches are approved for deployment across your environment. Patches can be approved for test machines to ensure patches are validated prior to deployment to production.

SOLARWINDS NETWORK CONFIGURATION MANAGER (NCM)

SolarWinds NCM is a network configuration management system built to provide auditing of network device policies and changes, and allows users to institute change management procedures (including approvals) around device changes. You can read more info about NCM’s network automation management features as they apply to PCI compliance, but here are the specific items it can help with:
Addressing PCI Requirement

  • 1.1: Establish firewall and router configuration standards: NCM allows users to develop standardized configuration templates, automate the deployment of those templates, schedule regular backups of the configurations, and monitor configurations for changes.

Addressing and Auditing Compliance With PCI Requirement

  • 2.4: Maintain an inventory of system components: NCM has automate device discovery and asset inventory to provide users visibility into the devices connected to their networks. Additionally, NCM monitors devices for firmware vulnerabilities and EoL devices.
  • 4.1: Use the right protocols to safeguard sensitive data: NCM’s policy engine is designed to help users understand what protocols are being used and monitors for changes to them.
  • 6.4: Follow change control processes and procedures: NCM’s change detection and tracking allows users to see when unauthorized changes are made to network device configurations.

Auditing Your Compliance With PCI Requirement

  • 1.2: Building restrictive firewall configurations: NCM’s templates aids users in ensuring all devices share the same restrictive firewall configurations outlined in 1.1 and monitor for changes to them.
  • 1.3: Prohibit direct public access: NCM is designed to analyze router rules to provide visibility into public access. The ability to set baselines and monitor for drift can help enforce corporate standards.
  • 2.1: Change default device passwords and SNMP community strings/remove extra accounts: NCM’s policy engine provides users a way to monitor for violations of specific requirements, alert users to violations, and can automate remediation actions such as updating passwords. Additionally, the ability to set baselines and monitor for drift can help enforce corporate standards.
  • 2.3: Allowing only encrypted admin access to devices: NCM’s policy engine and ability to set baselines provides users a way to monitor for violations of specific requirements, such as old encryption methods being used, and can alert users to these violations.
  • 12.10: Responding immediately to a system breach: NCM detects and tracks all configuration changes to network devices, therefore allowing users to provide proof of immediate responses returning configurations to a secure state. Additionally, NCM monitors devices for firmware vulnerabilities and EoL devices.

NCM provides specific reports for PCI compliance to make it easy to audit configuration settings and changes.
 

SOLARWINDS SERVER CONFIGURATION MONITOR (SCM)

SolarWinds SCM monitors, tracks, and alerts on changes to server and application configuration changes providing an audit trail of when configs change, who changed them, and exactly how they were changed. This helps reduce troubleshooting time and increase security and team accountability. Here are the specific items it can help with:
Addressing PCI Requirement:

  • 11.5: Deploy a change detection mechanism to alert personnel to unauthorized modification: SCM allows users to set baselines for each individual server, when the configurations of or on the server deviate from the baseline users can trigger an alert or receive reports. Additionally, the interface quickly surfaces which servers have been changed recently, which ones aren’t in compliance with the baseline, and who made the change.

Assisting With and Auditing Compliance for PCI Requirement:

  • 5.2: Ensure all antivirus mechanisms are current and running: With customization, SCM can tell you if antivirus is installed, running, and if configurations have been changed.
  • 6.2: Ensure all system components and software are protected with latest patches: With SCM’s software inventory tracking and change monitoring users can confirm if patches were completed successfully by setting a baseline prior to an update.
  • 6.4: Follow change control processes and procedures: SCM monitors, detects, and alerts on changes to server and application configuration changes. Therefore, if an unauthorized change is made (one outside change control), you’ll be notified and have an audit of what was changed and by whom.

SOLARWINDS SECURITY EVENT MANAGER (SEM)

SolarWinds SEM is a lightweight Security Information & Event Management (SIEM) built to provide log collection and normalization, real-time correlation/notification/response, flexible and extensive historical search, compliance reporting, and some endpoint security. You can read more about SEM’s PCI DSS compliance tools, but here are the specific items SEM can help with:
Addressing PCI Requirement:

  • 2.1: Usage of default accounts: SEM can monitor and alert on generic usernames appearing in your log data. Default account names can be added to a user-defined group to aid with creation of correlation rules and log filters.
  • 5.2: Ensure AV is generating log data: SEM includes out-of-the-box antivirus log parsers and filters to easily view alerts from your AV software. The filter can be used to validate your AV is generating log data.
  • 5.3: Ensure antivirus mechanisms are actively running and unaltered: SEM can monitor for AV processes and services starting upon system boot-up. Any changes to these services can be alerted on by out-of-the-box correlation rules.
  • 7.1: Least privilege access to sensitive data: File Integrity Monitoring can audit who’s accessing and making changes to sensitive data. SQL Events can also be used to audit access to sensitive data stored within a SQL database. Any access violating least privilege can be alerted upon.
  • 8.5: Usage of inactive/default/generic/shared accounts and other account policies: SEM can monitor for authentication events originating from these accounts. Correlation rules are provided to alert and respond to usage on these accounts, e.g., logon attempts from an inactive account.
  • 8.7: All access to cardholder data must be restricted: SEM can monitor all access to cardholder data, without files and databases. Alerts can be configured to alert to any unauthorized access. Reports can also be leveraged to review access to cardholder data.
  • 10.2: Logging various audit trails: SEM provides support for a vast array of log sources ranging from network devices, operating systems, IDS/IPS, antivirus, DLP tools, and more. The full list of supported parsers is available here.
  • 10.3: Include timestamps with logs: SEM includes a timestamp with all log data ingested into the appliance. Two timestamps are associated with each log, the time at which the event was detected from the source and the time it was inserted into the SEM database.
  • 10.4: Changes to clocks: SEM can alert upon any changes made to system clocks, including changes to a non-synchronized source. 
  • 10.5: Secure Audit Trails: SEM protects the completeness, accuracy, and integrity of audit trails via several controls listed here: SEM Appliance Security and Data Protection.
  • 10.6 Review logs for all system components: SEM includes an array of PCI content out of the box to assist with log data reviews, including correlation rules, log filters, charts, and reports.
  • 10.7: Retain Logs: SEM relies upon a high-compressed and secure log database for long-term log retention. Scheduled archives can also be configured to allow for offloading of log data from the SEM database to cold storage.
  • 11.5: Deploy a change detection mechanism for example file integrity monitoring: SEM’s FIM functionality allows you to monitor for sensitive access and changes to files, directories, and registry keys. PCI FIM templates are included out of the box to help you monitor changes and access critical system files.

SEM provides extensive audit log reporting capabilities for all collected log data, whether it’s for auditing compliance with any of the standards mentioned above, or the specific items mentioned in 10.6.
 

SOLARWINDS ACCESS RIGHTS MANAGER (ARM)

SolarWinds ARM enables IT and security admins to quickly analyze user authorizations and access permission to systems, data, and files to help them protect their organizations from the risks of data loss and breaches. Customized reports showing who has access to what (and when they accessed it) can be generated to support compliance requirements. User provisioning and deprovisioning can also be performed quickly using role-specific templates, assuring conformity of delegating access privilege in alignment with security policies. ARM makes user provisioning, deprovisioning, documentation, and monitoring easier while minimizing exposure to insider threats. Here are the specific requirements ARM can help with:
Addressing and Auditing Compliance for PCI Requirement:

  • 7.1: Limit access to system components and cardholder data: ARM’s user provisioning functionality allows admins to easily create user accounts in Active Directory, populate related attributes, assign group memberships, and support timely, complete deprovisioning of user access. Compliance can be quickly demonstrated with reports created on-demand or scheduled for automated delivery.
  • 8.1: Define and implement procedure to ensure proper user identification management: ARM’s user provisioning functionality allows admins to easily create user accounts in Active Directory, populate related attributes, assign group memberships, and support timely, complete deprovisioning of user access. Compliance can be quickly demonstrated with reports created on-demand or scheduled for automated delivery.
  • 8.7: All access to any database containing cardholder data must be restricted: ARM’s user provisioning functionality allows admins to easily create user accounts in Active Directory, populate related attributes, and assign group memberships, and support timely, complete deprovisioning of user access. Compliance can be quickly demonstrated with reports created on-demand or scheduled for automated delivery.
  • 10.1: Implement audit trails to link all access to system component to each user: ARM’s logging functionality supports monitoring access to relevant data and the definition of alert patterns to notify on suspicious activity.
  • 11.2 Run internal and external network vulnerability scans quarterly: Using ARM’s risk assessment dashboard quarterly can help users identify potential misconfigured access rights exposing sensitive data to the risk of unauthorized access and data breaches.

Assisting With PCI Requirement:

  • 7.2: Establish an access control system restricting access based on a user’s need to know: ARM’s functionality for permission visibility and management allows users to implement, control, and enforce processes for least privilege access to relevant data. By supporting the data owner concept and recertification of user access rights ARM helps to ensure the right people have access at any time needed.
  • 12.2 Implement a risk assessment process: ARM’s risk assessment dashboard supports risk assessment processes with data about potential misconfigured access rights exposing sensitive data to the risk of unauthorized access and data breaches.

SOLARWINDS SERV-U MANAGED FILE TRANSFER (MFT)

Serv-U® MFT provides the ability to ensure security of transferred files, supporting configurations keeping your sensitive data out of the wild. If you use file transfer when it comes to cardholder data, Serv-U is for you. More detail is available on the Serv-U site: FTP Server PCI Compliance, but here’s the specific items it can help with:
Assisting With PCI Requirement:

  • 1.3: Restrict access from the internet/untrusted networks
  • 3: Protect stored cardholder data
  • 4: Encrypt transmission of cardholder data
  • 7: Limit access to cardholder data
  • 8: Use unique access credentials

DO MY SOLARWINDS PRODUCTS NEED TO BE “PCI COMPLIANT” THEMSELVES?

No. SolarWinds products do not capture credit card data directly, provide access to card data directly, or authenticate card data directly. Products “in scope” for PCI compliance themselves would include things like databases, file servers, firewalls, and routers used for networks storing or accessing cardholder data, user accounts used to directly access cardholder data. Our management products are used to meet specific PCI requirements at what you could think of as a meta level—they aren’t providing the cardholder data, they’re providing information about access to the cardholder data, networks, and systems.

For SEM, when we collect audit trail data, this data doesn’t include cardholder data, again, only information about access to cardholder data. With NCM, you can approve/modify firewall configurations, but we aren’t collecting or reviewing network traffic. With other products monitoring or living on the network (like NPM and NTA), we’re not collecting or storing actual network traffic containing cardholder data, only information about network traffic. With SAM, we’re similarly monitoring system activity, but not activity directly related to cardholder data itself. With WPM, your recorded transactions contain the data you choose to submit, this won’t include the customer cardholder data they’ve submitted to the same site (if you’re testing performance on a form related to card number submission). Patch Manager can inform you of missing patches or the state of patching of a system storing or accessing cardholder data, but never accesses the system for any purpose other than patching.
 

EVEN THOUGH MY SOLARWINDS INSTALLS DON’T FALL UNDER PCI, I WANT TO IMPLEMENT SOME BEST PRACTICES. CAN I?

Requirements such as default user accounts, SNMP communities, and audit trails are often general security best practices. Some of them can be applied to SolarWinds products, others can’t. The answer is a solid “it depends.”

Specific configuration changes we’ve been asked about:

  • SNMP community strings. The big issue with SNMP community strings is how they’re used for making configuration changes. Exposing default SNMP read-write communities puts your devices at risk for unexpected changes. The next big issue is SNMP communities for monitoring, which can lead to information exposure. Even with SNMP read-only, you can view device statistics, log data, and configuration settings. The last capability of SNMP is trap sending and receiving, which is generally informational activity, often used for alerting or in place of syslog. In this case, setting default communities is less critical, because it’s generally a one-way communication mechanism outbound from your devices to ours.
    • Active SNMP monitoring (not traps) using non-standard communities: all SolarWinds products collecting data via SNMP monitoring (connecting to devices and polling via SNMP) allow you to specify a non-standard community. You can also set systems providing SNMP monitoring to non-standard communities. Some products, such as SEM, do not have SNMP monitoring capabilities and this doesn’t apply. The Orion Platform family products live on Windows systems, if you’re monitoring those systems with SNMP, the SNMP settings apply to the system, not our products.
    • Active SNMP configuration changes (not traps) using non-standard communities: The good news is, no SolarWinds monitoring products modify system configuration settings via SNMP (SEM, NCM, NPM, etc.). SNMP, in these cases, is either used for monitoring (NPM, SAM) or only with traps (SEM).
    • SNMP trap sending: Many SolarWinds products can send alerts via SNMP traps. All products capable of submitting traps to other systems allow you to specify the address and community to use, if not standard.
    • SNMP trap receipt: Many SolarWinds products can also receive alerts via SNMP traps. As of today, in some cases including SolarWinds SEM, the community string is the default (“public”) and cannot be modified. As mentioned above, these SNMP traps are consumed by SolarWinds systems for storage and search, and do not make direct changes to any of your systems by their nature.
    • SNMP v3/encryption support: Several SolarWinds products do support using SNMPv3 for monitoring activity. Some trap-receiving systems, including SolarWinds SEM, do not provide the ability to use SNMPv3 as it stands today (meaning, traps submitted to SEM will not be encrypted, much like syslog data).
  • Admin credentials and default users. Many customers have a desire to apply best practices around default admin credentials, even though our systems do not fall directly under PCI requirements themselves.
    • Changing admin passwords: All SolarWinds products have the ability for customers to change the default administrator user’s password.
    • Adding additional admin users (and not using the default): All SolarWinds products have the ability for customers to add more than one administrative user and not use the out-of-the-box administrator. This allows you to use named users for making administrative changes and avoid using a shared admin account.
    • Disabling the out-of-the-box admin user: Some SolarWinds products don’t have the ability to delete or disable the default admin user. SolarWinds SEM, for example, doesn’t allow customers to delete the default admin, to ensure there’s always an admin present to be reset and used in event of administrative turnover. SolarWinds Virtualization Manager, on the other hand, provides the ability to delete the built-in user if another administrative user exists.
  • Least Privilege Access/Use
    • Active Directory integration: Many SolarWinds products allow you to retrieve group information or authenticate against Active Directory. For basic authentication and information, you don’t have to be a user with administrative access.
    • Monitoring: For SolarWinds remote-polling products, it’s generally possible to use lower privilege users (i.e., not root or administrator). Specifically, SAM polling can be done against a non-administrative user with these instructions
    • Installation and services: In most cases, SolarWinds products need to have administrative or broad system privileges to install and run, due to technical limitations. Where installers require administrative privileges on Windows, generally they’ll show the UAC prompt for administrative access automatically.

 

A QUICK NOTE ABOUT PCI DSS V3.2.1

Most of the changes in PCI DSS v3.2.1 don’t affect your SolarWinds implementations, and product changes aren’t necessary though your implementation and processes might need to be tweaked. Notable changes applicable to SolarWinds products:

  • In general, the PCI council added guidance about integrating products into ongoing PCI compliance. Having a SIEM helps customers be more proactive in this process instead of only looking at logs when an audit comes through—focusing on security, not just compliance. We didn’t have to make product changes here, but it’s noteworthy.
  • Requirement 10 changed slightly to focus more on identifying suspicious activity and more flexibility in reviewing less critical logs. We didn’t have to make product changes here either, but Requirement 10 is the one specifically dealing with logs, so it’s noteworthy. (Customers may have to generate, or review fewer reports of “normal” activity for auditors.)
  • Requirement 2 added a specific note about detecting changes to default passwords for service/backup accounts, not just user accounts, which SEM can help monitor (and NCM can help manage as well). We didn’t have to make product changes to help deal with this, but the clarification helps customers implement it properly.

 

QUESTIONS ABOUT IMPLEMENTING OR AUDITING FOR PCI DSS?

If you have questions about how SolarWinds products are used for PCI, what specific reports or features to look for, or how to implement any of the best practices security configurations, leave them in the comments. I’ll update this page with any other common questions we get related to PCI configuration and can direct link any helpful features.

Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment. You elect to use third-party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.