Meet PCI Compliance using Security Information and Event Management (SIEM)
Simply deploying a security solution cannot guarantee meeting every Payment Card Industry (PCI) requirement in full. This whitepaper discusses the challenges of PCI compliance and how security information and event management (SIEM) provides the data visibility, log management, end-point security and active response needed to demonstrate and meet each of the 12 PCI compliance requirements.
Javascript Disabled To use our site, you must enable JavaScript.
Published:
Oct 03, 2008
Type:
White Paper
Length:
12 pages
TriGeo Security Information Management in the Payment Card Industry:
Using TriGeo SIM To Meet PCI RequirementsUsing TriGeo SIM To Meet PCI Requirements 1
The challenge of PCI compliance
Today, more than a billion people around the world use payment cards to support commercial transactions. The use of these payment cards represents an enormous opportunity for businesses to increase sales at the counter as well as through rapidly expanding channels such as online shopping.
However, the information associated with these payment cards-commonly referred to as "cardholder data"-is the focus of a growing number of identity theft activities.
To address the need to improve payment card security, the card industry has created a set of global requirements called the Payment Card Industry (PCI) Data Security Standard (DSS). Basically, PCI is a set of 12 data-centric control objectives and associated requirements for ensuring the security and privacy of cardholder data. All 12 requirements must be met for compliance, and the penalties for non-compliance are severe.
©2008 TriGeo Network Security, Inc. All rights reserved. TriGeo and TriGeo SIM are trademarks of TriGeo Network Security, Inc.Using TriGeo SIM To Meet PCI Requirements 2
Compliance with Security Information and Event Management (SIEM)
Simply deploying a security solution cannot guarantee that you will meet every PCI requirement in full. However, SIEM provides the data visibility, log management, end-point security and active response required to demonstrate PCI compliance.
A SIEM can give you deep visibility into data generated by devices across networks, platforms and environments. TriGeoT SIM acts as a central collection point for device data, automatically aggregating and then normalizing this data into a consistent format. Data normalization, in turn, supports correlation-so anomalies and security threats can be easily and quickly identified. Other advantages with SIEM technologies can include automated responses to suspicious events, as well as advanced reporting functionality.
©2008 TriGeo Network Security, Inc. All rights reserved. TriGeo and TriGeo SIM are trademarks of TriGeo Network Security, Inc.Using TriGeo SIM To Meet PCI Requirements 3
In short, SIEM can help you meet your PCI auditing requirements through increased visibility, security and control over consolidated data. With TriGeo SIM in particular, you can take advantage of the following capabilities:
Enhanced security. ? Full 24x7 network security coverage, from the perimeter to the desktop, even with limited IT staff and minimal budget ? Real-time log collection and encrypted agent communication that ensures chain of custody and data integrity ? Real-time event analysis and correlation ? USB detection and prevention ? Bundled Snort® Intrusion Detection System (IDS)
Comprehensive automation. ? Automated remediation that actively responds to defend your network ? Automated notification of network security events to the TriGeo SIM Console, email, cell phone, pager or handheld device ? Automated filtering, aggregation and normalization of network device logs
Ease of use and ownership. ? Rapid deployment of the appliance, with no network downtime ? Over 650 correlations, prebuilt with rules specific to PCI compliance ? Over 240 reports to meet the increasing demands of auditors and regulatory compliance ? Usable and affordable-designed and priced for the mid-market
©2008 TriGeo Network Security, Inc. All rights reserved. TriGeo and TriGeo SIM are trademarks of TriGeo Network Security, Inc.Using TriGeo SIM To Meet PCI Requirements 4
How TriGeo SIM addresses PCI requirements
In the following pages, we will discuss each of the 12 requirements of PCI and how TriGeo SIM can help you meet these requirements in an efficient, cost-effective manner.
Requirement 1: Install and maintain a firewall configuration to protect cardholder data
This requirement is designed to clearly separate the outside world from sensitive areas of the network. To achieve that objective, a firewall must be deployed and also properly configured. Once it is configured, any subsequent access to that configuration must be carefully monitored.
TriGeo SIM supports Requirement 1.1.9, which stipulates that logs must be monito... [download for more]
Browse Technology Topics
Application Integration ,
Analytical Applications ,
Business Intelligence ... more , Configuration Management , Database Development , Data Integration , Data Mining , Data Protection , Data Quality , Data Replication , Database Security , EDI , SOAP , Service Oriented Architecture , Web Service Management , Data Warehousing less Analog Communications ,
Digital Signal Processing ,
Electronic Design Automation ... more , System On A Chip , Electronic Test and Measurement , Embedded Design , Boards & Modules , Embedded Systems and Networking , Electromechanical & Mechanical , Optoelectonics & Displays , Packaging and Interconnects , Passive & Discrete Components , Power Sources & Conditioning Devices , Integrated Circuits and Semiconductors , Sensors & Actuators less Application Integration ,
Application Performance Management ... more , Best Practices , Business Activity Monitoring , Business Analytics , Business Integration , Business Intelligence , Business Management , Business Metrics , Business Process Automation , Business Process Management , Call Center Management , Call Center Software , Change Management , Corporate Governance , Customer Interaction Service , Customer Relationship Management , Customer Satisfaction , Customer Service , EBusiness , Enterprise Resource Planning , Enterprise Software , EProcurement , Extranets , Groupware Workflow , HIPAA Compliance , IP Faxing , IT Spending , Marketing Automation , Performance Testing , Product Lifecycle Management , Project Management , Return On Investment , Risk Management , Sales & Marketing Software , Sales Automation , Server Virtualization , Simulation Software , Supply Chain Management , System Management Software , Total Cost of Ownership , Video Conferencing , Voice Recognition , Voice Over IP , Workforce Management , Incentive Compensation , Spend Management , Manufacturing Execution Systems , International Computing less Human Resources Services ,
Payroll Software ,
Time and Attendance Software ... more , Workforce Management Software , Financial Management , Employee Monitoring Software , Employee Training Software , Recruiting Software/Services , Employee Performance Management , ELearning , Benefits Management , Expense Management less Collaboration ,
Collaborative Commerce ,
Contact Management ... more , Content Delivery , Content Integration , Content Management System , Corporate Portals , Customer Experience Management , Document Management , Information Management , Intranets , Messaging , Records Management , Search And Retrieval , Search Engines , Secure Content Management , SLA less Active Directory ,
Bandwidth Management ,
Convergence ,
Distributed Computing ... more , Ethernet Networking , Fibre Channel , Gigabit Networking , Governance , Grid Computing , Infrastructure , Internetworking Hardware , Interoperability , IP Networks , IP Telephony , Local Area Networking , Load Balancing , Migration , Monitoring , Network Architecture , Network Management , Network Performance , Network Performance Management , Network Provisioning , Network Security , OLAP , Optical Networking , Quality Of Service , Remote Access , Remote Network Management , Server Hardware , Servers , Small Business Networks , TCP/IP Protocol , Test And Measurement , Traffic Management , Tunneling , Utility Computing , VPN , Wide Area Networks , Green Computing , Cloud Computing , Power and Cooling , Data Center Design and Management , Colocation and Web Hosting less AS/400 ,
Domino ,
Linux ,
Microsoft Exchange ,
Oracle ,
PeopleSoft ... more , SAP , Siebel , Solaris , Tivoli , Unix , Web Sphere , Windows , Windows Server less Access Control ,
Anti Spam ,
Anti Spyware ,
Anti Virus ,
Application Security ... more , Auditing , Authentication , Biometrics , Business Continuity , Compliance , DDoS , Disaster Recovery , Email Security , Encryption , Firewalls , Hacker Detection , High Availability , Identity Management , Internet Security , Intrusion Detection , Intrusion Prevention , IPSec , Network Security Appliance , Password Management , Patch Management , Phishing , PKI , Policy Based Management , Security Management , Security Policies , Single Sign On , SSL , Secure Instant Messaging , Web Service Security , PCI Compliance , Vulnerability Management less .NET ,
C++ ,
Database Development ,
Java ,
Middleware ,
Open Source ... more , Software Outsourcing , Quality Assurance , Scripting , SOAP , Software Testing , Visual Basic , Web Development , Web Services , Web Service Security , XML less Backup And Recovery ,
Blade Servers ,
Clustering ,
IP Storage ... more , ISCSI , Network Attached Storage , RAID , Storage Area Networks , Storage Management , Storage Virtualization , Email Archiving , Data Deduplication less 802.11 ,
Bluetooth ,
CDMA ,
GPS ,
Mobile Computing ,
Mobile Data Systems ... more , Mobile Workers , PDA , RFID , Smart Phones , WiFi , Wireless Application Software , Wireless Communications , Wireless Hardware , Wireless Infrastructure , Wireless Messaging , Wireless Phones , Wireless Security , Wireless Service Providers , WLAN less