Work · MAISTREAM, payment services and e-commerce
A PCI DSS environment from scratch
The company's payment services needed a PCI DSS compliant environment. There wasn't one, so I built it from scratch and took it through the audits.
The task
Card data can only be processed in an environment that meets the PCI DSS standard, and an external auditor checks it. The company didn’t have one. I had to design it, set it up, and prove to the auditor that everything works the way the policies say.
What I did
- Network segmentation and access. I separated the environment from the rest of the infrastructure. The only way in is through OpenVPN.
- Logging and event analysis. I set up OSSEC and wrote my own log analysis rules, including rules for nftables logs, with security alerts by email.
- Monitoring. Zabbix on the environment’s servers: agents, triggers for server and service health, email alerts.
- Database backups. Oracle Database backups: a bash script runs RMAN from cron as the oracle user.
- Policies and procedures — the auditor checks them as carefully as the configuration.
- Scans and pentests. I prepared the infrastructure for external and internal vulnerability scans and penetration tests, worked with the auditors on the technical side, and closed their findings.
- Technical tests with BPC (БПЦ): POS Concentrator, Belkart InternetPassword, Mir Accept.
The result
The company passed 2 PCI DSS audits and 1 PCI 3DS audit with no critical findings.
What I learned
Security is not one setting. It’s a process and evidence. An auditor doesn’t ask “did you set up logging?” — they ask you to show last month’s logs. So everything I do has to leave a trace: in the logs, in the procedures, in the change history.