Showing posts with label PCI DSS. Show all posts
Showing posts with label PCI DSS. Show all posts

Friday, January 1, 2010

Firms failing on PCI DSS


A huge 81% of organizations that are subject to the Payment Card Industry’s Data Security Standard (PCI DSS) were found to be non-compliant prior to a data breach, according to a new study.

But according to telco Verizon Business’ Risk team, which published the findings, a “fairly new” threat in the shape of RAM scrapers is increasingly being used by online thieves to bypass PCI DSS rules requiring credit card data to be encrypted anyway.

The company’s 2009 Data Breach Investigations Report found that 74% of security incidents were the result of external attacks. Such events resulted in a huge 285 million records being compromised over the last year - mainly via online systems.

Only 20% of data breaches were caused by insiders, 32% by business partners and 39% by multiple parties. Some 67% of the incidents occurred because the attacker exploited errors made by the victim, while a further 64% were the result of hacking and 38% of malware. infosecurity

Wednesday, December 16, 2009

Firms failing on PCI DSS


A huge 81% of organizations that are subject to the Payment Card Industry’s Data Security Standard (PCI DSS) were found to be non-compliant prior to a data breach, according to a new study.

But according to telco Verizon Business’ Risk team, which published the findings, a “fairly new” threat in the shape of RAM scrapers is increasingly being used by online thieves to bypass PCI DSS rules requiring credit card data to be encrypted anyway.

The company’s 2009 Data Breach Investigations Report found that 74% of security incidents were the result of external attacks. Such events resulted in a huge 285 million records being compromised over the last year - mainly via online systems.

Only 20% of data breaches were caused by insiders, 32% by business partners and 39% by multiple parties. Some 67% of the incidents occurred because the attacker exploited errors made by the victim, while a further 64% were the result of hacking and 38% of malware.

But in its 2009 Supplemental Report called Anatomy of a Data Breach, Verizon Business also pointed to the rising threat of RAM scrapers. infosecurity



Sunday, November 22, 2009

Lessons Learned From PCI Compliance


Assessors reveal mistakes companies make with data security standard.
Whether you think PCI is a useful standard that makes our credit card data safer or a credit card industry whitewash that merely creates the illusion of security, PCI compliance is a fact of life.

As part of PCI compliance, companies that process a high volume of credit card transactions must submit to an annual assessment by a qualified security assessor, or QSA. For example, Visa requires it of merchants that process 6 million or more transactions. Assessors work for third-party organizations and generally visit companies to examine their processes and determine whether they comply with PCI rules.

More Security InsightsWhitepapersThe How and Why of PCIIDC Report: Complex Event Processing Opportunity Analysis and Assessment of Key ProductsWebcastsTapping into the Information Pipeline in Real-Time: Creating new levels of visibility and control for the Oil and Gas IndustryLessons From the "2009 Data Breach Investigations Report"ReportsHTML 5 Starts Looking Real (Dr. Dobbs)Hybrid CloudsVideos

Forbes CIO Mykolas Rambus talks about managing cost cutting, the changing role of the CIO, building leadership within, and his company's high priority on mining intelligence from vast amounts of data.

To help companies get ready for a an evaluation, we asked QSAs to describe common problems they encounter when working with IT groups on PCI compliance. What follows are five best practices to help companies better prepare for an assessment and maintain compliance. Information Week

Monday, November 16, 2009

PCI DSS: No Angel, but Certainly Not the Devil


Security luminaries Anton Chuvakin and Ben Rothke explain why 451 Group analyst Josh Corman is off his rocker when he compares PCI security to a devil and "No Child Left Behind."

 Fifty years ago, The Coasters had a top-10 hit with the song "Charlie Brown." The song is best known for the phrase "Why's everybody always pickin' on me?" Charlie Brown was a loveable character who was often beat up and picked on for no reason.

A Guide to Practical PCI Compliance

Far too many in the industry similarly see PCI as such a loser and criticize it relentlessly. In our article PCI Shrugged: Debunking Criticisms of PCI DSS from April 2009, we wrote that the PCI DSS is a valuable standard. We did not then, and do not now, feel that the PCI DSS is perfect, but it is in the best interest of the industry and consumers that it be maintained, developed and expanded as well as adapted to today's threats.

However, let's briefly step away from this debate and consider this: imagine a large distributed retailer that has somehow survived without investing in information security. Yes, they've updated antivirus subscriptions on their desktops and have added a firewall, but they haven't gone beyond that (it goes without saying that this said organization was consistently compromised by malicious hackers).

The advent of PCI worried this retailer and now they have to take security actions like encrypt, log, monitor, educate employees, and more. However, this retailer is now fighting PCI with all their strength since they believe that "PCI is too much security." Their worldview of security is that "no security" is "just enough security." CIO IT News