|
How we can assist you to achieve the PCI Data Security Standard (PCI DSS) Compliance? The Payment Card Information Data Security
Standard (PCI-DSS) was created in 2004 by the leading credit
companies in response to the growing problem of cardholder
information theft. Despite heavy fines for violations and other
costs incurred by retailers, security problems have continued.
Recent high-profile data thefts have increased concerns about
the problem, and generated a strong interest in solving it. To help address the
problem, several of the leading credit firms— American Express,
Discover Financial Services, JCB, MasterCard Worldwide, and Visa
International—established the Payment Card Industry Data
Security Standard, or PCI DSS. They had three goals:
·
To secure
customer credit card information
·
To build trust
among credit card users
·
To cut down on high-risk or dishonest
merchants Like all compliance and
regulatory requirements, there is no single product or
policy/procedure that will assure your compliance. THERE IS NO
SILVER BULLET for PCI COMPLIANCE. PCI compliance requires that
your enterprise deploy many security technologies, and have
specific policies and procedures in place.
StarLink
can assist you to achieve the PCI requirements, this white paper
focuses on the unique issues and solutions associated with both
database security and monitoring and privileged password
management in meeting PCI compliance requirements.
Guardium
Real-time database activity monitoring offers an answer with a
rapid, effective strategy for securing enterprise credit card
data and passing your audit. Guardium Database monitoring
technology uses a network-based appliance to monitor all
activity into and out of a database. The appliance is easy to
install via a passive network tap and does not require any
changes to applications or databases. It simply monitors and
collects detailed information about all database activities,
establishes baselines of normal behavior, recognizes unusual
data access activities, and takes action such as sending
real-time alerts, shutting out the intrusion, or even locking
down the database.
e-DMZ Security
was uniquely designed to solve enterprise security and
compliance issues associated with the management and control of
shared privileged passwords such as root and administrator. The
issue of privileged password management and the unique features
of PAR contribute directly and/or indirectly to many specific
PCI requirements as outlined in below attachment A.
Fundamentally, the compliance audit concerns in the area of
shared privileged password management center on ACCOUNTABILITY
and AUDIT. Given the level of access and shared nature of
accounts like root and administrator, internal and external PCI
audits are taking a close look at existing enterprise controls.
In most cases, the existing manual based policy/procedure
solutions (e.g. Safe – envelope) or internally developed
technical solutions are not standing up to PCI compliance
audits. Under audit scrutiny existing in-house solutions are
failing to deliver assured accountability and adequate audit.
© 2002 StarLink Computer L.L.C. All rights reserved. |