• No results found

PCI DSS Configuration Checklist

you configure your computers and your networks for basic compliance.

The Site Checklist for PCI DSS and FACTA Compliance is designed as a separately printable ‘leave-behind’ checklist to help a site administrator perform a quick evaluation as to the compliance status, or lack thereof, of a specific site.

PCI DSS Configuration Checklist

The steps to PCI DSS compliance are many, and occasionally confusing. Use this checklist as a guide, and to measure your progress, as you configure your own database for compliance. If you are viewing this doc-ument in PDF format, click any blue link to move immediately to the topic it references for more informa-tion. Each topic also lists its page number, if you are using a printed copy.

System Configuration:

Begin configuring your Aloha installation for PCI DSS compliance at the most basic level, initial installa-tion.

Install the latest version of Aloha validated against the applicable data security standards. Contact a member of the Radiant team to identify the latest validated version of Aloha.

Obtain and run the DelTrack utility, to remove any residual customer data remaining in your installa-tion, page 40, after upgrading to a PCI DSS validated version of Aloha.

Configure alternate security devices for use on the FOH terminals, such as fingerprint scanners, when installed. Activate fingerprint scanners in Maintenance > Hardware > Terminals > Readers tab, page 34.

Network Security Configuration:

Configure your Windows and Aloha networks for security, to give yourself the best chance of maximizing data integrity in your installation.

Verify Windows is configured to purge the paging file each time you restart the BOH file server.

Information about how to do this is available in the Microsoft Knowledge Base, page 15.

Disable the ‘Guest’ user in Control Panel. Procedures for doing this vary slightly from one operating system to another, page 14.

Reconfigure all Aloha data and program directories relevant to remove the ‘Everyone’ user from them, page 14. Verify their configuration permits access only by the system administrator or other autho-rized accounts.

Disable and remove ‘auto-logon’ on the BOH file server, if currently in use. Remove residual config-uration for auto-logon, if it has ever been used on the BOH file server, page 14 and page 28.

Install antivirus software, and obtain updates for it routinely and often, page 26. Daily is not too often.

Change all default passwords in routers, remote administrative software, or other third-party hardware or software, as appropriate, page 6.

Install Aloha(QS) in a secondary directory beneath the root, as in C:\Bootdrv\Aloha(QS), page 14.

Ensure procedures are in place to prevent opening a direct Internet connection from any computer on the Aloha network, page 15.

Create a Windows user account specifically for use in the Aloha network, independent of any other network requirements, page 15.

Use Local Security Policy to block the Aloha network-specific user from logging on to the system page 15.

Configure CtlSvr, EDCSvr, RFSSvr, and any other Aloha related service, devices, and BOH user accounts to use the network user account created specifically for this purpose, page 16.

Delete any default Windows user accounts provided by Radiant Systems or affiliated companies for use in initial configuration, page 45.

Configure Aloha EDC to use an alternate path, outside the BootDrv share, by creating a new environ-ment variable, EDCProcPath, and moving the contents of the current EDC folder to the new location, page 16.

Disable the System Restore feature in Windows. Refer to “Configuring the Windows Network” on page 13 for information about how to disable this feature.

Disable Remote Desktop in Windows. Refer to “Configuring the Windows Network” on page 13 for information about how to disable this feature.

Aloha POS Configuration – Tender Configuration:

Configure your payment card tenders to protect you and your customers.

Create secure payment card tenders, by suppressing expiration date printing, and by requiring the use of the card itself for transactions, in Maintenance > Payments > Tenders > Type tab, page 21.

Select Use Magnetic Card ONLY.

Clear Print Expiration.

On the Identification tab, clear Print on Check.

Note: Not required for PCI DSS compliance, but recommended as a best practice.

Aloha POS Configuration – Store Settings:

Store Settings provides you with several opportunities to tighten security in your installation.

Configure printer output to mask the card number and to omit the expiration date, in Maintenance >

Store Settings > Credit Card group > Voucher Printing 2 tab, page 23.

Select Only show last 4 digits on all vouchers from the ‘Credit Card Number Mask’ drop-down list.

Select Suppress Expiration dates.

Require and configure passwords for use on the Front-of-House (FOH) terminals, in Maintenance >

Store Settings > Security group > POS Password Settings tab, page 29.

Require complex, expiring BOH passwords, in Maintenance > Store Settings > Security group > POS Password Settings tab, page 31.

Stop EDC event logging, in Maintenance > Store Settings > System group > Aloha Settings tab, page 35.

Aloha POS Configuration – Labor Settings:

Configuring your labor settings helps you to keep your Aloha network secure.

Configure back office security levels that provide no more access than required for each employee type, in Maintenance > Labor > Back Office Security Levels, page 36.

Require each employee to use FOH passwords, and set them to expire regularly, in Maintenance >

Labor > Job Codes > Job Code tab, page 31.

Related documents