Part 1: Major Events Documentation
Scenario: You visit a retail establishment, shop around, and finally carry several products to one of the point of sale (POS) terminals distributed openly around the store. You produce a credit card, the salesclerk processes the transaction, bags your goods, and hands you the receipt. On your way to the exit, a store employee asks to see your receipt and checks the contents of the store bag. Document each of the major events just described and explain them in terms of the PCI compliance standard. Include this report in your assignment.
Part 2: PCI Compliance
This part of the assignment will cover PCI. Please refer to the attached file in your responses.
Respond to and address the following in essay style:
1. Suppose HGA’s mainframe, depicted in Figure B-1, stored cardholder data in the private databases. What steps should be taken to protect that data in order to be PCI compliant?
2. HGA’s mainframe has network connectivity. Assuming that cardholder data is transmitted across these networks, describe how data should be protected in transmission.
3. Users are located at various sites connected to the HGA network. Suggest appropriate access controls to restrict unauthorized users from looking at cardholder data.
4. The PCI specification notes that all systems and network devices connected to a system that stores, transmits, or processes cardholder data is in scope and must comply with PCI specifications. To avoid having the whole network subject to PCI specifications, how would you segment the network to reduce the scope of compliance?
Assignment Requirements:
Submit your assignment in the usual double-spaced APA-styled report. At least four pages of material are expected beyond the title page, table of contents, abstract, and references page.
· Answers contain sufficient information to adequately answer the questions
· No spelling errors
· No grammar errors
CRSS Network Diagram
Copyright Rasmussen, Inc. 2013. Proprietary and Confidential.
1
1
image3.png
image5.png
FedRAMP Security Assessment Plan (SAP)
Third Party Assessment
Prepared by
<Your Name>
for
Country Roads Space Systems
&
NASA
CRSS Information Systems. Administration and Classified Networks
Version #.#
<DATE>
MOCK Plan
CRSS Information Systems. Administration and Classified Networks | Version #.# Date
Controlled Unclassified Information Page | 10
System Assessment Plan
Prepared by
Identification of Organization that Prepared this Document
Student NameEnter Your Name
Rasmussen Email AddressEnter Rasmussen Email Address
ClassEnter Class Name
Course and SemesterEnter Section Number and Semester
Prepared for
Identification of Cloud Service Provider
Organization NameNASA
Street Address300 E St. SW
Suite/Room/BuildingIA Office Floor 2
City, State ZipWashington DC 20546
Revision History
Date
Description
Version of SSP
Author<Date><Revision Description><Version><Author><Date><Revision Description><Versi.