4g Lte and Pci Compliance
4g Lte and Pci Compliance
4g Lte and Pci Compliance
PCI-COMPLIANCE
What Every Retailer
Should Know
The Emerging Mandate
For 4G LTE in Retail
Whether its speed, efficiency, cost-effectiveness or quality, in the thin-margin world of retailing,
its essential to capitalize on every possible advantage to achieve and preserve profitability. In
addition, businesses are at serious risk if they fail to implement rigorous security frameworks
that also comply with stringent industry and regulatory standards. However, these regulations
are saddling retailers with additional processes, cycles and costs that are hampering the In 2013, 89 percent
retailers mission. Nowhere is this truer than with the Payment Card Industry Data Security
of companies were
Standard (PCI DSS, or more frequently, simply PCI).
non-compliant. In
PCI is an industry standard that defines how retailers and other participants in the payment 2014, 80 percent
lifecycle must securely handle branded credit cards from major card issuers, such as were. Are you
MasterCard, Visa, American Express, Discover and others. The objective is to increase control in the 9 percent
and limit visibility of cardholder data to reduce fraud. Thats an essential mandate for retailers that moved into
if only because consumers trust that every purchase and every transaction they make takes compliance -- or
place on a foundation of privacy, safety and security.
the 80 percent
The balance of this paper will provide background about LTE and some insights about how it
that are still
can be utilized by M2M devices now and in the future. noncompliant?
From POS terminals and kiosks to ATMs and other connected devices, retailers are increasingly
looking at the benefits of new 4G LTE networks, but need to ensure they transmit card data in
ways that ensure PCI compliance.
In this white paper, Digi examines the issues surrounding 4G LTE and PCI compliance:
The Advantages of 4G LTE
Mythbusting: Cellular Connectivity in Retail
Avoiding Common Security Mistakes
Designing 4G LTE Networks for PCI Compliance
PAGE 1
4G LTE AND PCI-COMPLIANCE
Reasons to Move from 3G to 4G
Speed Typical data rates are in the 1-50 Mbps range, instead of 0.5-5 Mbps. With peak data
rates, speeds are measured in Gbps.
Low Latency 4G LTE offers latency of less than 100 ms, instead of 100-300 ms.
Lower Frequency Operating in the 700-750 MHz range, 4G LTE can cover larger service areas
with better signal penetration (such as inside a shopping mall).
More Bands You can use aggregated bandwidth and higher throughput.
In the past, cellular connectivity has also faced criticism regarding its manageability. However,
cell strategies are far easier to manage than USB modems distributed across the retail
enterprise. More importantly, todays cellular routers embedded with 4G LTE modules are
designed for distributed M2M applications that can be centrally managed over cloud-based or
server-based SNMP network-management systems tools. Manageability is literally built-in.
While most market- and technology-watchers agree that 4G LTE offers compelling advantages, a
key question remains: How does it best fit into retailing?
PAGE 2
4G LTE AND PCI-COMPLIANCE
At an entry level, 4G LTE provides an ideal platform for wireless backup, such as backing up
POS transactions that are otherwise transmitted across a traditional terrestrial network. As
the stability and popularity of wireless grow earning retailers trust we see a move toward
wireless as the primary connectivity conduit (particularly outside the U.S.). That translates into
more flexibility and lower cost.
And, as retailers move beyond their brick-and-mortar locations and edge closer to their
customers through line-busting kiosks or kiosks at airports, for instance, 4G LTE actually helps
create entirely new customer points for the retailer.
Even with the best-protected, properly certified systems, problems will occur. One need only
reflect on high-profile penetrations at Target, The Home Depot, PF Changs, Michaels and others
to acknowledge that significant breaches can occur. Adding LTE to the mix, therefore, requires
careful planning and protection.
PAGE 3
4G LTE AND PCI-COMPLIANCE
A Network Thats Designed for PCI
Compliance
The PCI Audit
A carefully designed 4G LTE-based network can be ideally suited for retail thanks to a favorable
economic profile, excellent reliability, complete flexibility and near-universal coverage. But In a PCI audit, the auditor
these networks also move sensitive credit card data on a continuous basis. And that means examines your systems,
theyre all subject to PCI compliance mandates that require merchants to process card scrutinizes your network,
information in a secure manner and in a secure environment. identifies vulnerabilities,
and issues directives to
improve your ability to
prevent data from being
Traditional PCI Network Design compromised.
Work Scanners,
Stations Inventory
Management
Report
Server Segmentation Point
4G
Signage
4G
4G
PAGE 4
4G LTE AND PCI-COMPLIANCE
The goal of a PCI network design is to segment any and every network element that has
payment data (or other critical information) from anything else on the network even if that
requires the redundancy of separate routes and separate routers. It can even include separate
transport carriers (not simply additional resold lines) that provide secure private routes, which
are significantly harder to break into.
When you add 4G LTE technology to the network design, segmentation of cardholder data
remains a crucial requirement, but there are now two different endpoints in the network that
must maintain PCI compliance. Thats accomplished in several key ways:
Protecting Cardholder Data Retailers must protect stored cardholder data and encrypt the
transmissions of that data across open, public networks.
Limiting Vulnerabilities Merchants must protect their systems from malware exposure and
regularly update antivirus software and programs. All systems and applications should be
developed and maintained with security as a primary feature.
Ensuring Strong Access Controls Systems must identify and authenticate all users with
access to system components.
Validating Vendor Security Capabilities Its easy to integrate security and even encryption
features to a product. Merchants should insist on third-party audits and security testing
(e.g., penetration testing). Ask vendors to show evidence of PCI security compliance. For 4G
LTE network routers and software, for example, a PCI Attestation of Compliance indicates a
vendor has passed rigorous third-party testing.
Conclusion
With speed, efficiency and cost-effectiveness, 4G LTE networks offer tremendous advantages
to retail enterprises if implemented properly. For the right level of security and full PCI
compliance its clear that a fully private network, with sufficient separation of payment-
processing elements, is the only satisfactory choice. For more information on how Digi can
help you achieve highly secure, PCI-compliant networks, visit www.digi.com.
PAGE 5
4G LTE AND PCI-COMPLIANCE
Key Takeaways
3 Omanageability,
ffering new levels of speed, throughput, larger service areas, and centralized
4G LTE is an ideal technology for retail communication.
3 4previously
G LTE connectivity provides excellent reliability and manageability that had been
absent in other cellular technologies.
3 Pinfrastructure.
CI compliance is a non-negotiable requirement for retailers, regardless of network
3 E4Gxpansion
of the merchant network infrastructure to capitalize on the advantages of
LTE requires a careful focus on security and the design of the network to isolate
payment-processing systems and data.
Digi International
Worldwide HQ
11001 Bren Road East
Minnetonka, MN 55343
Copyright 2016 Digi International Inc. All rights reserved. 91003216 A1/116
While every reasonable effort has been made to ensure that this information is accurate, complete and up-to-date, all information is provided AS IS without warranty of any kind. We disclaim liability for any
reliance on this information. All registered trademarks or trademarks are property of their respective owners.