Find White Papers
Home
About Us
List Your Papers
    
> Solidcore > 40% PCI Non-Compliance? How to Beat The Stats Without Breaking a Sweat

40% PCI Non-Compliance? How to Beat The Stats Without Breaking a Sweat

White Paper Published By: Solidcore

New report issued by Fortrex, Emagined Security and Solidcore reveals the cost of PCI compliance is justified. These PCI requirements exist to protect sensitive data - yet, research indicates that these are among the least satisfied requirements across Level 1 merchants, with almost 40% non-compliance. 



Tags : 
security, monitoring, auditing, compliance, data protection, data quality, pci compliance

Solidcore
Published:  Jan 15, 2008
Type:  White Paper
Length:  2 pages

Continuous File
Integrity Monitoring:
A New Approach for PCI DSS Compliance
Introduction DSS compliance specifies that changes to existing data in logfiles must be detected, whereas the addition of new data can beWhen it comes to IT infrastructure, a strong compliance posture ignored. For other files, such as critical configuration files, anyrequires two key components: Trusted state and safe change change may be important. When a change of interest occurs,actions. Payment Card Industry Data Security Standard (PCI the FIM solution needs to provide an alert.DSS) compliance, in particular, highlights the need for safechange actions through the following requirements: Approaches to File Integrity MonitoringPPPPPCCCCCIIIII CCCCCooooonnnnntttttrrrrrooooolllll 1111100000.....55555.....55555: Use file integrity monitoring andchange detection software on logs to ensure that existing There are two approaches to file integrity monitoring: Periodiclog data cannot be changed without generating alerts File Integrity Monitoring (PFIM) and Continuous File Integrity(although new data being added should not cause an alert). Monitoring (CFIM).
PPPPPCCCCCIIIII CCCCCooooonnnnntttttrrrrrooooolllll 1111111111.....55555 ----- Deploy file integrity monitoring . PPPPPeeeeerrrrriiiiiooooodddddiiiiiccccc FFFFFiiiiillllleeeee IIIIInnnnnttttteeeeegggggrrrrriiiiitttttyyyyy MMMMMooooonnnnniiiiitttttooooorrrrriiiiinnnnnggggg (PFIM). Traditionalsoftware to alert personnel to unauthorized modification of monitoring solutions can be characterized as PFIMcritical system or content files. solutions. They detect changes to files by schedulingperiodic system scans. They compare changes madeRecent independent research indicates that these are among between scanning periods and report any differences.the least satisfied requirements across Level 1 merchants, with Changes that are made during the actual scanning processalmost 40% non-compliance. This is why many organizations will not be detected.facing PCI DSS compliance are looking at file integrity monitoringsolutions. Anyone evaluating these solutions should be aware . CCCCCooooonnnnntttttiiiiinnnnnuuuuuooooouuuuusssss FFFFFiiiiillllleeeee IIIIInnnnnttttteeeeegggggrrrrriiiiitttttyyyyy MMMMMooooonnnnniiiiitttttooooorrrrriiiiinnnnnggggg (CFIM). Thethat the technology in this area has evolved significantly and a latest technology monitoring solutions are referred to asnew breed of solution is now available. CFIM solutions. CFIM solutions monitor files constantly.Changes are detected as they happen and any violationsare immediately reported.File Integrity Monitoring (FIM)
File Integrity Monitoring (FIM) is the capability to monitor files Comparing the Approachesand directories on a server for change. The changes can bemade to content, permissions or both. Note that only certain Continuous FIM is a newer technology that compares favorablychanges are relevant in a given situation. For example, PCI to Periodic FIM in every respect. The following table comparesCFIM and PFIM against key selection criteria:Continuous File Integrity Monitoring
RRRRReeeeeqqqqquuuuuiiiiirrrrreeeeemmmmmeeeeennnnnttttt PPPPPFFFFFIIIIIMMMMM CCCCCFFFFFIIIIIMMMMMDetect all changes No YYYYYeeeeesssss About Solidcore SystemsIdentify transient violations No YYYYYeeeeesssssCapture rich forensic data No YYYYYeeeeesssss Solidcore is a leading provider of changeOperational trade-offs Coverage vs. Overhead NNNNNooooonnnnneeeee control for critical systems.
As outlined from the table above, there are four main benefits of using CFIM Solidcore's S3 Control software is thetechnology instead of PFIM: industry's first and only solution toautomate the enforcement of change11111..... DDDDDeeeeettttteeeeeccccctttttsssss aaaaallllllllll ccccchhhhhaaaaannnnngggggeeeeesssss::::: Continuous FIM captures every single change to the management policies. Solidcorefile. Periodic FIM will miss changes if more than one change happens between automatically reconciles infrastructurescans. Detecting all changes is important for sustaining compliance because it changes against change tickets, andallows you to see where your compliance policies are being challenged, and provides real-time change auditing soaddresses inappropriate change at the... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search