- Palm unwraps the unlocked 3G Treo Pro
- FTC targets prerecorded telemarketing drivel
- New algorithm offers hope for old routers
- Microsoft hires Seinfeld to bite Apple
- 'White space' spectrum debate to get hotter
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
Myriad merchants find themselves at the end of the PCI compliance barrel and are spending significant amounts of time, money and effort in achieving PCI compliance. Advice from companies that have been there can help smooth your path.
One of the biggest mistakes organizations make is jumping into their PCI remediation effort without first understanding their company's gaps. It's crucial to realize that every organization has a different maturity level when it comes to technology and compliance. Without first knowing what level you are at, taking a "one size fits all" approach to fixing PCI will spell disaster.
A pre-compliance assessment is imperative and enables you to understand what your PCI compliance effort will entail. The output is a document identifying gaps between your current state and what the PCI DSS (Data Security Standard) requirements necessitate.
Some of the items covered in the pre-compliance assessment include:
-- Review of IT infrastructure; PCI-relevant application architecture, policies, procedures and processes; overall network
design
-- Gap analysis
-- Network vulnerability scanning
-- Risk analysis
-- Mapping business flows to technology flows
Determine your current state by completing the PCI Self-Assessment Questionnaire (SAQ) from the PCI Security Standards Council. The SAQ is divided into six sections focusing on a specific area of security. After completing the SAQ, you will have a good idea of which controls and tools are in are in place.
Cross-Organizational Interaction
PCI requires the whole organization to play nicely together; too many organizations have different IT groups that have developed their own fiefdoms and act in semi-autonomous states. PCI doesn't support such an approach--it requires different groups to collaborate whether they like it or not.
Success with PCI is dependant on how the numerous groups work together and maintain reasonable expectations. How well this is executed has a direct impact on compliance. The best way to ensure understanding is to set effective ground rules at the beginning of the compliance effort.
Vendor Remediation Support
Your organization has older software and hardware that isn't PCI-compliant. Similar to preparing for Y2K, getting vendors to ensure their products comply with PCI can be a significant issue. How much of an issue depends on your importance to the vendor and the importance of PCI to the vendor.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comment