You might want to take a look at the following link.
Navigating PCI DSS Document
https://www.pcisecuritystandards.org/pd ... ng_dss.pdf
There is a lot of discussion about what is meant by Requirement 8: Assign a unique ID to each person with computer access.
In this document they have the following guidance
8.1 Assign all users a unique ID before allowing them to access system components or cardholder data.
Guidance
By ensuring each user is uniquely identified—instead of using one ID for several employees—an organization can maintain individual responsibility for actions and an effective audit trail per employee. This will help speed issue resolution and containment when misuse or malicious intent occurs.
8.2 In addition to assigning a unique ID, employ at least one of the following methods to authenticate all users:
Password or passphrase
Two-factor authentication (for example, token
devices, smart cards, biometrics, or public keys)
Guidance
These authentication items, when used in addition to unique IDs, help protect users’ unique IDs from being compromised (since the one attempting the compromise needs to know both the unique ID and the password or other authentication item).
RetailEdge does allow you to turn on security and track Clerk IDs and require passwords, so that you can track what a person is doing within the program. In addition, RetailEdge has an Audit log and so almost every action in RetailEdge is tracked and with clerk tracking turned on, we can tell who did what, when.
In addition, you should also be doing other things like only allowing clerks to log into the Windows system as a regular user and not an Administrator. This can also prevent employees and clerks from installing programs that might cause problems when they misuse the system or are doing something with malicious intent.
If you have questions like this you might also want to check with the person helping you with the PCI compliance issues. When using PPI or MPS who RetailEdge has a direct integration with, they have relationships with people who will do the remote port scans and also will help you with the SA Questionnaires. In addition, PPI has insurance program that will help protect you against breaches in the event that your system is compromised. If you are using another processor for your credit card processing, you should check with them to see what kind of service and/or help they can provide.
wildman wrote:bobdist wrote:Yes, some of the questions are pretty complex. And there's lots of interesting issues to think about... Just as an example, one of the requirements is that each user have their own unique login id. In our environment, where we have several clerks all accessing the same two registers many, many times per day, it seems impractical to have each one do a Windows login each time they want to use a register. So, I recently started assigning clerk ids, and turned on clerk tracking. But, I have no idea if that meets the intent of that requirement. I'd love to hear how other RetailEdge users handled some of these issues.
Bob
I would also like to know how this will affect us? We also have multiple users,with each having a clerk ID's, but will they have to have a separate password and log into the machine every time they make a sale. If this is a requirement, it will be a major pain in the rear, one would probably have to switch back to stand alone terminals.