Wireless Networks

 

Point-of-Rental Software Expert does not require wireless connectivity.

If you choose to deploy a wireless network infrastructure to support communications between deployed systems, or you connect a wireless network to the environment supporting the Point-of-Rental Software Expert application, you must do so in a manner compliant with the current PCI DSS standards. The secure deployment of a wireless network is solely your responsibility. In order for you to achieve PCI DSS compliance, the following guidelines must be followed for deployment of a wireless network:

      wireless encryption keys must be changed from default at installation, and must be changed anytime anyone with knowledge of the keys leaves the company or changes positions;

      default SNMP community strings on wireless devices must be changed;

      default passwords/passphrases on access points must be changed;

      firmware on wireless devices must be updated to support strong encryption for authentication and transmission over wireless networks;

      other security-related wireless vendor defaults must be changed, if applicable; and

      wireless networks transmitting cardholder data or connected to the cardholder environment must use industry best practices to implement strong encryption for authentication and transmission.

If you have wireless network deployed within your environment and it is not part of your cardholder network, a firewall is required between any wireless networks and the cardholder data environment. The firewall must be configured to deny or control any traffic from the wireless environment into the cardholder data environment.