EFT Server High Security-PCI Add-on Module
Raise EFT Server security to the level required by the Payment Card
Industry - Data Security Standard (PCI-DSS)
The High Security-PCI add-on module achieves or exceeds security practices
mandated by PCI-DSS, HIPAA, and Sarbanes-Oxley for data transfer,
access, and storage.
The module ensures:
- data is stored and disposed of securely
- account and password security policies adhere to PCI-DSS
- strong encryption ciphers and keys are used exclusively
- violations are reported and compensating controls are applied
- changes are monitored and recorded
Key Benefits
Protection of Data at Rest
The HS-PCI solution, in concert with EFT Server and DMZ Gateway server, helps organizations comply with data storage requirements, including not storing data in the network DMZ, using repository encryption, and securely sanitizing deleted data so that it cannot be reconstituted.
Protection of Data in Transit
The HS-PCI solution protects data in transit by enforcing the use of secure protocols, strong ciphers and encryption keys, and maintaining password policies that strictly follow PCI-DSS guidelines.
Controlled Access to Data
The High Security PCI solution lets you restrict accounts and require unique IDs for access. For user authentication, you can use an AD, NTML, LDAP, or ODBC-compatible database or
EFT Server's authentication manager to isolate a specific group of users from other groups in your domain. The Auditing and Reporting Module (ARM) captures all server activity in a fully relational database.
Ongoing PCI-DSS Compliance
With PCI DSS, you cannot "set it and forget it." Compliance, with the ultimate goal of securing sensitive company data, requires continuous monitoring and validation of security policies and controls. GlobalSCAPE makes it easy for an administrator to create and maintain file-transfer services that comply with the PCI standard. The solution provides a setup “wizard” that walks administrators through configuring a new PCI DSS-enabled file transfer service, sets security settings default values, disallows low security options, captures compensating controls, and generates a PCI DSS compliance report for auditing the system’s PCI DSS compliance status.
Achieving PCI compliance with EFT Server's High Security-PCI add-on module
The following table lists the PCI-DSS requirements and outlines specifically how GlobalSCAPE can help you become compliant.
Setup wizards provide administrators with an easy, step-by-step method to configuring a new PCI-DSS-enabled site.
Contact Us
If you would like more information regarding evaluating or purchasing the HS-PCI module for EFT Server, please call us at 1-800-290-5054 (U.S.) or 1-210-308-8267 (international), or submit a request for a product trial and a representative will contact you shortly.