Blog Archive
Blog Archive: Compliance
- June 20, 2011
- Got PCI? Get an MSS.
The latest version of PCI DSS promises to be a game changer. Unlike previous versions which left certain areas up for interpretation, this year’s update forces retail company security officers to put increased effort into securing the systems that face the greatest risks—this is where the private credit-card data exists, of course.
Read More- By S.L. Sweet
- Comments(0)
- January 10, 2011
- Retailers: Look beyond PCI DSS Compliance
Many retailers that have recently completed security audits are scrambling to implement new measures as their auditors begin to insist on full compliance with key areas of the Payment Card Industry (PCI) Data Security Standard (DSS).
Read More- By S.L. Sweet
- Comments(0)
- November 30, 2010
- Tips for Choosing a MSSP
Security as a Service (SaaS) offerings are prompting many businesses to consider finding new ways to manage their network security functions. Yet there can be a high level of anxiety when you think about handing something as critical as network security over to an outside party. The question becomes, how do you find a SaaS provider matches well with the way you want to manage your network security?
Read More- By S.L. Sweet
- Comments(0)
- September 14, 2010
- A Retailer's View of Security Information Management
If your company accepts payment cards, it can be hard to keep up with the data storage and log review requirements of the Payment Card Industry Data Security Standard (PCI DSS). For device log data, the standard requires storage for at least one year, with the most recent 90 days of data retrievable immediately. This applies to all of the systems within your cardholder data environment and particularly your point-of-sale systems that need daily review for potential security breaches.
Read More- By S.L. Sweet
- Comments(0)
- August 16, 2010
- Now Is The Time To Step Up Your Security Practices
The United States Secret Service, working in collaboration with Verizon, recently released a report [PDF} investigating cybercrimes which reveals that data breaches of electronic records last year involved external agents 70% of the time, insider agents 48% of the time, that 11% of the events implicated business partners, and that 27% involved multiple parties.
Read More- By Michael Francois
- Comments(0)
