
and authentication solution will allow for secure transmission of
sensitive data between all entities across an enterprise.
16.6.1 Firewalls
In general, all administrative ports should be blocked from external
networks. Access control lists (ACLs) should be set up to restrict
access to certain devices on the network. For example, if a network-
based security appliance resides on the network, only those devices
that require access for administrative or cryptographic operations
should be granted access.
1
16.7 Encryption of multiple columns: database
considerations
If multiple columns of a database table are encrypted, it is strongly
recommended to use different ...