Skip to main content
Question

VERTICA and Payment Card Industry (PCI) standard compliance

  • May 23, 2019
  • 3 replies
  • 18 views

MaciejPaliwoda
Forum|alt.badge.img+2

Hi All,
Has anyone have more detailed information how we can be compliant with PCI standard.
I have only found small statement in VOLTAGE brochure:

Solution Highlights Voltage SecureData brings a unique proven data-centric approach to the protection of sensitive data in Vertica. It also helps in significantly reducing the scope of regulatory compliance audits, such as Payment Card Industry (PCI) and Health Insurance Portability and Accountability Act (HIPAA). Voltage SecureData calls for de-identifying the data as close to its source as possible, transforming the sensitive data elements with usable, yet de-identified, equivalents that retain their format, behavior, and meaning. This protected form of the data can then be used in subsequent applications, analytic engines, data transfers, and data stores while readily and securely re-identified for those specific applications and users that require it.

Any experiences to share? Any customer stories?
Thanks in Advance

Maciej

3 replies

Jim_Knicely
Forum|alt.badge.img+2
  • Participating Frequently
  • May 23, 2019

MaciejPaliwoda
Forum|alt.badge.img+2
  • Author
  • Participating Frequently
  • May 23, 2019

Cool, thanks Jim, haven't seen this before. Very usefull.


mosheg
Forum|alt.badge.img+2
  • Participating Frequently
  • May 23, 2019

Shva is the main company in Israel that connects businesses to clearing companies. All credit cards transactions and approvals are done by Shva. The system handles millions of daily transactions and requests permission to salvage businesses details of millions of transactions made by credit cards. The system updates the final information businesses of clearing the companies required to operate. The system enables information on transactions made in the business and broadcasts detail transactions concentration. Transaction records are processed and forwarded to the clearing firms and clearing companies transfer business finances in accordance with their agreement.

On October 2015, we did the following PoC and won.
At the time the following PCI requirements mentioned:

  • Do not keep details of TRACK2
  • Do not keep CVV data
  • Credit card numbers are encrypted retain only
  • Data access will be a controlled user name and password
  • Protect and make AUDIT access to data

From the following two offered options, B was chosen.
A. Save the encrypted credit card information in a single database
B. Keep only the Tokens in Vertica while other details store in a separated dedicated database.

PoC components:

  • Established HP Vertica cluster on 3 x DL380 servers
  • Predefined queries
  • Concurrent queries
  • Adhoc queries on few years of history
  • Present a resolution using MySQL and Vertica to satisfy PCI requirements.
  • Raw data ~10TB

Since January 2016 Shva use Vertica in production as follows:
a. Data is loaded to Vertica
b. Card details are loaded to MySQL
only its token saved in Vertica
c. Approved User query for Card Number
d. UDX query MySql for specific token
e. Vertica get Card Number from Token and present
its last four digits
f. An Audit process keep all info about accesses