Home > Financial Services Information Security Tips > Compliance and Governance Digest > PCI automation: Discovering the benefits
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE AND GOVERNANCE DIGEST

PCI automation: Discovering the benefits


Spyro Malaspinas, Contributor
06.17.2008
Rating: --- (out of 5)


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Diligent financial organizations that have successfully achieved PCI compliant status are often dismayed to realize that the hard work of achieving PCI compliant status is nearly as painstaking as maintaining it. Key to the perpetual maintenance of PCI compliance for large merchants and service providers is finding opportunities to automate monotonous and resource intensive tasks.
As enterprises grow, systems age, and new administrators gain access to critical systems, it becomes more difficult to ensure the compliance of system settings without a set of automated tools.
Spyro Malaspinas

Identifying automation opportunities: Configuration management
Sprinkled heavily throughout the PCI DSS 1.1 within requirements two, seven and eight are obligatory controls over baseline builds and the variances that these builds are subject to over time. Controls related to password management, unencrypted non-console administrative access, and entitlements are just a few areas that require granular control and oversight over low level system settings. As enterprises grow, systems age, and new administrators gain access to critical systems, it becomes more difficult to ensure the compliance of system settings without a set of automated tools that can query and pro-actively alert system administrators and security staff of security deficiencies.

Benefit: Full population view versus small sample sizes
Rather than sampling, a total population snapshot can take place at regular and frequent intervals. When sampling, it may take months and even years before deficiencies in all system builds are discovered. For PCI purposes, even one deficiency can lead to a failing grade, and may result in a lack of safe harbor status following a breach.

Benefit: Auditors and security staff save time with assessments
With proactive monitoring and alerting, system administrators and security staff can more efficiently spend their time on remediation items instead of assessment drills. Many tools offer the ability to prioritize alerts based upon system classification or severity of security settings. This allows security staff and administrators to focus on those critical systems that may impact an organization more significantly.

Additional benefits include:

  • Automated checks are less time consuming and prone to fewer errors
  • Automated checks usually scale well in very large organizations
  • New checks can be performed in relatively quick fashion
  • Automated checks offer the ability to identify variances in corporate security policies

Identifying automation opportunities: Log management
Requirement 10 of the PCI DSS has traditionally been one of the more time consuming and tedious requirements to fulfill, as each system that stores, processes, or transmits cardholder data (or an in-scope system) must log a minimum set of attributes to comply with PCI.

For more information
Read about the numerous compliance requirements that demand baseline controls

Learn about PCI DSS 3.1 best practices

Manage the process to limit liability, understand PCI DSS pre-assessment

Securing the application and system level local logs of each in-scope system can be challenging in large financial organizations with a more diverse variety of systems. Granular controls and need-to-know access must be restricted to ensure that non-privileged users are not able to modify, access, and/or delete logs or log settings.

The amount of time that it takes to manually review logs can be egregious and boring. Monotonous tasks lead to mistakes, omissions, and a false sense of security.

Manual sorting of the most critical alerts can lead to unnecessarily long security exposures for vulnerable or compromised systems. Alternatively, automated checks allow for predefined prioritization of alerts based upon a variety of different attributes inclusive of log type, source, system type, and other correlated vulnerability data. This enables quick reaction times for the most critical security alerts on the most relevant systems.

Additional benefits: Automated log management:

  • Ability to detect misconfigurations of applications and systems in near real time
  • Improved SLAs to external and internal customers
  • Improved incident response capabilities during compromises
  • Better forensic data through the comparison of correlated information between multiple security devices along with application and system logs

Erecting automated processes that focus on configuration management and audit log management responsibilities can benefit general security best practices, and operational dividends while freeing up cycle time of your IT compliance and security teams to tackle more strategic and thought provoking work.

About the author:
Spyro Malaspinas, CISSP, CISM, CISA, GCIH, CCNA, CSPFA, CCSE+, NSA, Six Sigma, is a Pprincipal at ThreeFactor Security and can be reached at spyrom@threefactor.com. Spyro formerly served as the PCI practice leader at Symantec Corp., a sr. Ssecurity consultant at VeriSign Inc., and security architect at IBM. He has been performed compliance assessments, remediation, risk and compliance program management functions for some of the largest merchants and service providers found globally.


Rate this Tip
To rate tips, you must be a member of SearchFinancialSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Compliance and Governance Digest
Rogue activity thwarted by early warning systems
Red Flags rule: Unclear guidance biggest challenge
Strategic metrics for information security at financial services firms
Metrics don't truly quantify information risk
Why metrics matter
Partner data privacy: Issuing stricter guidelines
Pushing past the perplexity in protecting PIFI
FDIC guidance for managing third party risk
Outsourcing compliance strategies
Protecting third party processes on all levels

PCI DSS compliance
How to use PCI to your (budgetary) advantage
PCI council to start assessor quality assurance program
Case study: How outsourcing services enable PCI DSS compliance
Financial Information Security Decisions 2008: Presentation downloads
PCI DSS pre-assessment: Managing the process to limit liability
For financial firms, numerous compliance requirements demand baseline controls
Next version of PCI standards due in September
Solidcore launches PCI file integrity software
PCI DSS 3.1 best practices
PCI standard, take two

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CISP-PCI  (SearchFinancialSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts