TDE for PCI DSS

Is it PCI complient to encrypt the DB with the sensitive data using TDE (with external EKM)?

We were planning to implement the encryption using TDE and somebody today told me that for PCI the encryption has to be done with an external tool so that the DBA can't see clear PAN (Card holder) data.

Is this true?

November 2nd, 2011 8:15pm

Hi,

Hopefully this should help. http://parentebeard.com/wp-content/uploads/2011/09/Payment-Card-Industry-Whitepaper.pdf

This is referenced by Microsoft from the following security and compliance site http://www.microsoft.com/sqlserver/en/us/solutions-technologies/mission-critical-operations/security-and-compliance.aspx

 

Free Windows Admin Tool Kit Click here and download it now
November 2nd, 2011 8:42pm

Is there a way, using TDE with EKM, not to allow the DBA to read the sensitive data?
November 2nd, 2011 9:42pm

I think you'd have to look at cell/row level encryption for that, and that would require some application changes (probably)
Free Windows Admin Tool Kit Click here and download it now
November 3rd, 2011 8:33am

Dear all,

I'm doing with PCI-DSS project. At now, We use IBM-Guardium to mask card no with 6first-4end cardno in SQL. PCI-DSS recommend that not use select left, right to see clear text (full pan).

March 20th, 2015 1:29am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics