Issue Description: To handle sensitive financial or cardholder data (PCI) must ensure that the data is protected throughout the entire integration lifecycle. Failure to implement standardised encryption and key management can lead to compliance violations and security vulnerabilities during data transit or storage.
Environment Description:This applies to all Boomi Integration runtimes handling sensitive bank data or payment card information, utilizing the Boomi Key Management Service (KMS) and PGP encryption capabilities.
Cause Description: Standard data transmission without enhanced encryption layers is insufficient for PCI DSS (Payment Card Industry Data Security Standard) requirements. Compliance mandates that sensitive data be unreadable to unauthorized parties both while moving across networks and when temporarily residing on a disk.
Resolution Description:
To ensure secure PCI data integration, Boomi provides a multi-layered security framework involving encryption at rest, encryption in transit, and advanced key management.
1. Encryption in Transit and At Rest:
Strong Encryption: Boomi provides native strong encryption for data in transit (via SSL/TLS) and at rest.
PGP Encryption: For high-security requirements, such as bank data integration, use the PGP Encryption/Decryption within your process. This ensures that even if a data payload is intercepted or accessed on a local disk, it remains unreadable without the corresponding private key.
2. Utilize Boomi Key Management Service (KMS):
Centralized Security: The Boomi Key Management Service (KMS) allows you to securely manage the lifecycle of your encryption keys.
HSM Integration: KMS can integrate with Hardware Security Modules (HSM) to provide enterprise-grade protection for your certificates and keys, ensuring they are never exposed in plain text within the application.
Access Control: Use KMS to define who has permission to use specific keys, adding an extra layer of authorization to your PCI-scoped processes.
3. Compliance Best Practices
Minimize Data Footprint: Avoid using "Data Persistence" or "Tracked Fields" for raw cardholder data.
Auditability: Leverage Boomi’s audit logs to track configuration changes to security components and KMS settings to meet PCI DSS reporting requirements.
Environment Extensions: Always use Environment Extensions for connection credentials and security headers to ensure that sensitive production keys are not hard-coded in the underlying XML of the process components.