Find White Papers
Home
About Us
List Your Papers
    
> ArcSight > Digital Fraud & Identity Theft Made Protection of Payment Card Information More Critical Than Ever

Digital Fraud & Identity Theft Made Protection of Payment Card Information More Critical Than Ever

White Paper Published By: ArcSight

Whitepaper highlighting the twelve PCI DSS requirements and the technology necessary to address the PCI DSS 1.2 requirements.



Tags : 
pci dss, pci dss 1.2, log management, arcsight logger, siem, payment card industry, pci, dss

ArcSight
Published:  Mar 04, 2009
Type:  White Paper
Length:  9 pages

White Paper
ArcSight Logger and PCI DSS 1.2
Table of Contents
Background 3ArcSight Logger and PCI DSS 1.2 3 Four Categories of Logs 4 PCI Requirements and ArcSight Logger 5 Conclusion 9
ArcSight Logger and PCI DSS 1.2 2BackgroundDigital fraud and identity theft incidents have made the protection of payment card information more critical than ever. Cardholder security programs started as early as 2001, and credit card issuers joined together in 2004 to publish the first Payment Card Industry (PCI) Data Security Standard (DSS). Visa, MasterCard, American Express, Discover Bank and JCB all now endorse the standard. The PCI DSS is unique from other information security regulations as it receives governance from private industry rather than elected officials, which means the PCI Security Standards Council (SSC) retains the authority of managing the DSS.The DSS is comprised of a list of twelve requirements to which members, merchants and service providers must adhere. It applies to any organization that stores, processes or transmits cardholder data. The requirements include the use of data encryption, end-user access controls and activity monitoring and logging, as well as the need to regularly test security systems and processes. Companies face stiff fines or even may be barred from the card acceptance program if they do not comply. The PCI DSS extends to all "system components" of these organizations, which means all technology involved with or connected to cardholder data is considered applicable to the standard.
ArcSight Logger and PCI DSS 1.2ArcSight Logger is delivered in a slim appliance form-factor that supports ease of configuration and deployment. It provides high-performance log collection from any source into highly-compressed yet easily-searchable and self-managing log data repository. ArcSight Logger addresses the growing need for collection, storage and analysis of data for all sizes and types of organizations. It can function both as a standalone appliance to achieve log management as well as a complement to the ArcSight ESM platform, which provides a foundation for IT Risk and compliance management.The DSS requires implementation of a robust information security management system including monitoring and maintaining audit trails. Version 1.1 of the DSS was published in September 2006 with an 'Appendix B: compensating controls.' This appendix addresses the complexity of encryption and that controls often cannot be immediately absorbed by entities facing compliance. Compensating controls, such as advanced logging capabilities to protect keys and enhance identity management, increase the relevance of logs. Version 1.2 was released on Oct 1, 2008, as the Security Standards Council uses a two year lifecycle, and provides clarifications to make it easier for organizations to interpret and implement the DSS without losing the intent.Combined together, Appendix B and the changes in version 1.2 make it clear that log management serves as a foundation for PCI compliance. The importance of maintaining a trail of who, what, where, and when of cardholder data should not be underestimated. Even policy and risk assessment depend to a degree on data that is collected in logs and analyzed in a timely fashion. Requirement 10 is perhaps the most obvious as it calls on organizations to "track and monitor all access to network resources and cardholder data."
ArcSight Logger and PCI DSS 1.2 3ArcSight Logger is the industry leading solution for this Requirement. It establishes a process to link user access to systems, especially for privileged accounts such as root and administrator. Additionally, it implements automated assessment trails for all system components to reconstruct specified events, records specified assessment trail entries for all system components for each event, secures the assessment trails so they cannot be altered, provides numerous storage options to retain history for more than one year, and provides a user-friendly interface and powerful reporting engine for daily review of all system component logs. ArcSight Logger also goes beyond Requirement 10 and assists members, merchants and service providers that store, process or transmit cardholder data by making the rest of their PCI compliance program more efficient, effective and auditable. It automatically collects information from system components covered under PCI and provides an intelligent logging sol... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search