The Experts below are selected from a list of 72 Experts worldwide ranked by ideXlab platform

Branden R Williams - One of the best experts on this subject based on the ideXlab platform.

  • logging events and monitoring the Cardholder Data environment
    PCI Compliance (Fourth Edition)#R##N#Understand and Implement Effective PCI Data Security Standard Compliance, 2015
    Co-Authors: Branden R Williams, Anton A Chuvakin, Derek Milroy
    Abstract:

    The Payment Card Industry Data Security Standard (PCI DSS) Requirement 10 directly addresses logging. The requirement itself is called “Track and monitor all access to network resources and Cardholder Data” and is organized under the “Regularly monitor and test networks” heading. Specifically, Requirement 10.1 covers “establishing a process for linking all access to system components to each individual user. Section 10.5.1 of PCI DSS covers the confidentiality. Section 10.5.2 of PCI DSS mentions that one needs to protect audit trail files from unauthorized modifications. Many pieces of network infrastructure such as routers, and switches are designed to log to an external server, and only preserve a minimum of logs on the device itself. Thus, for those systems, centralizing logs is most critical. Requirement 10.5.4 of PCI DSS states the need to “copy logs for wireless networks onto a log server on the internal LAN.” The final Requirement 10.7 deals with log retention. It mandates to “retain audit trail history for at least one year, with a minimum of three months online availability.”

  • chapter 6 protecting Cardholder Data
    PCI Compliance (Second Edition)#R##N#Understand and Implement Effective PCI Data Security Standard Compliance, 2010
    Co-Authors: Anton A Chuvakin, Branden R Williams
    Abstract:

    Publisher Summary The Payment Card Industry Data Security Standard (PCI DSS) requirement to protect Cardholder Data covers two elements—protect stored Cardholder Data, and encrypt transmission of Cardholder Data across open, public networks. In case of PCI DSS, logging and monitoring requirements are meant to provide auditing, and monitoring for the infrastructure. This key tenet is about knowing who is doing what with the Data at any given time, and on being able to prove it via logging, and monitoring. PCI standards dictate that stored Cardholder Data can be rendered unreadable, such as encrypted, masked, truncated, or tokenized. Encryption will protect the Data from being used by the malicious hackers, and thus, the goal of PCI DSS that is to reduce the risk of transactions will be preserved. Only upon failing to protect the Data with strong cryptography, PCI DSS allows implementing compensating controls to mitigate the risk if one is unable to meet this requirement directly. PCI DSS mandates certain key management practices, if encryption is a chosen method of rendering Data unusable. The document details 12 different items for the proper management of encryption keys.

  • chapter 9 logging events and monitoring the Cardholder Data environment
    PCI Compliance (Second Edition)#R##N#Understand and Implement Effective PCI Data Security Standard Compliance, 2010
    Co-Authors: Anton A Chuvakin, Branden R Williams
    Abstract:

    Publisher Summary The Payment Card Industry Data Security Standard (PCI DSS) Requirement 10 directly addresses logging. The requirement itself is called “Track and monitor all access to network resources and Cardholder Data” and is organized under the “Regularly monitor and test networks” heading. Specifically, Requirement 10.1 covers “establishing a process for linking all access to system components to each individual user. Section 10.5.1 of PCI DSS covers the confidentiality. Section 10.5.2 of PCI DSS mentions that one needs to protect audit trail files from unauthorized modifications. Many pieces of network infrastructure such as routers, and switches are designed to log to an external server, and only preserve a minimum of logs on the device itself. Thus, for those systems, centralizing logs is most critical. Requirement 10.5.4 of PCI DSS states the need to “copy logs for wireless networks onto a log server on the internal LAN.” The final Requirement 10.7 deals with log retention. It mandates to “retain audit trail history for at least one year, with a minimum of three months online availability.”

Anton A Chuvakin - One of the best experts on this subject based on the ideXlab platform.

  • logging events and monitoring the Cardholder Data environment
    PCI Compliance (Fourth Edition)#R##N#Understand and Implement Effective PCI Data Security Standard Compliance, 2015
    Co-Authors: Branden R Williams, Anton A Chuvakin, Derek Milroy
    Abstract:

    The Payment Card Industry Data Security Standard (PCI DSS) Requirement 10 directly addresses logging. The requirement itself is called “Track and monitor all access to network resources and Cardholder Data” and is organized under the “Regularly monitor and test networks” heading. Specifically, Requirement 10.1 covers “establishing a process for linking all access to system components to each individual user. Section 10.5.1 of PCI DSS covers the confidentiality. Section 10.5.2 of PCI DSS mentions that one needs to protect audit trail files from unauthorized modifications. Many pieces of network infrastructure such as routers, and switches are designed to log to an external server, and only preserve a minimum of logs on the device itself. Thus, for those systems, centralizing logs is most critical. Requirement 10.5.4 of PCI DSS states the need to “copy logs for wireless networks onto a log server on the internal LAN.” The final Requirement 10.7 deals with log retention. It mandates to “retain audit trail history for at least one year, with a minimum of three months online availability.”

  • chapter 6 protecting Cardholder Data
    PCI Compliance (Second Edition)#R##N#Understand and Implement Effective PCI Data Security Standard Compliance, 2010
    Co-Authors: Anton A Chuvakin, Branden R Williams
    Abstract:

    Publisher Summary The Payment Card Industry Data Security Standard (PCI DSS) requirement to protect Cardholder Data covers two elements—protect stored Cardholder Data, and encrypt transmission of Cardholder Data across open, public networks. In case of PCI DSS, logging and monitoring requirements are meant to provide auditing, and monitoring for the infrastructure. This key tenet is about knowing who is doing what with the Data at any given time, and on being able to prove it via logging, and monitoring. PCI standards dictate that stored Cardholder Data can be rendered unreadable, such as encrypted, masked, truncated, or tokenized. Encryption will protect the Data from being used by the malicious hackers, and thus, the goal of PCI DSS that is to reduce the risk of transactions will be preserved. Only upon failing to protect the Data with strong cryptography, PCI DSS allows implementing compensating controls to mitigate the risk if one is unable to meet this requirement directly. PCI DSS mandates certain key management practices, if encryption is a chosen method of rendering Data unusable. The document details 12 different items for the proper management of encryption keys.

  • chapter 9 logging events and monitoring the Cardholder Data environment
    PCI Compliance (Second Edition)#R##N#Understand and Implement Effective PCI Data Security Standard Compliance, 2010
    Co-Authors: Anton A Chuvakin, Branden R Williams
    Abstract:

    Publisher Summary The Payment Card Industry Data Security Standard (PCI DSS) Requirement 10 directly addresses logging. The requirement itself is called “Track and monitor all access to network resources and Cardholder Data” and is organized under the “Regularly monitor and test networks” heading. Specifically, Requirement 10.1 covers “establishing a process for linking all access to system components to each individual user. Section 10.5.1 of PCI DSS covers the confidentiality. Section 10.5.2 of PCI DSS mentions that one needs to protect audit trail files from unauthorized modifications. Many pieces of network infrastructure such as routers, and switches are designed to log to an external server, and only preserve a minimum of logs on the device itself. Thus, for those systems, centralizing logs is most critical. Requirement 10.5.4 of PCI DSS states the need to “copy logs for wireless networks onto a log server on the internal LAN.” The final Requirement 10.7 deals with log retention. It mandates to “retain audit trail history for at least one year, with a minimum of three months online availability.”

Derek Milroy - One of the best experts on this subject based on the ideXlab platform.

  • logging events and monitoring the Cardholder Data environment
    PCI Compliance (Fourth Edition)#R##N#Understand and Implement Effective PCI Data Security Standard Compliance, 2015
    Co-Authors: Branden R Williams, Anton A Chuvakin, Derek Milroy
    Abstract:

    The Payment Card Industry Data Security Standard (PCI DSS) Requirement 10 directly addresses logging. The requirement itself is called “Track and monitor all access to network resources and Cardholder Data” and is organized under the “Regularly monitor and test networks” heading. Specifically, Requirement 10.1 covers “establishing a process for linking all access to system components to each individual user. Section 10.5.1 of PCI DSS covers the confidentiality. Section 10.5.2 of PCI DSS mentions that one needs to protect audit trail files from unauthorized modifications. Many pieces of network infrastructure such as routers, and switches are designed to log to an external server, and only preserve a minimum of logs on the device itself. Thus, for those systems, centralizing logs is most critical. Requirement 10.5.4 of PCI DSS states the need to “copy logs for wireless networks onto a log server on the internal LAN.” The final Requirement 10.7 deals with log retention. It mandates to “retain audit trail history for at least one year, with a minimum of three months online availability.”

  • protecting Cardholder Data
    PCI Compliance (Fourth Edition)#R##N#Understand and Implement Effective PCI Data Security Standard Compliance, 2015
    Co-Authors: Ande R Williams, Anto A Chuvaki, Derek Milroy
    Abstract:

    This chapter explains how to protect the card Data stored in your systems, as well as how to protect Data while it is in transit on your network.

Milind Tadvalka - One of the best experts on this subject based on the ideXlab platform.

  • Analysis of Payment Card Industry Data Security Standard [PCI DSS] Compliance by Confluence of COBIT 5 Framework
    International Journal of Engineering Research and Applications, 2017
    Co-Authors: Ashish Ukidve, Ds S Smantha, Milind Tadvalka
    Abstract:

    The Payment Card Industry Data Security Standard (PCI DSS) aims to enhance the security of Cardholder Data and is required when Cardholder Data or authentication Data are stored, processed or transmitted. The implementation of enabling processes from COBIT 5 can complement compliance to PCI DSS. COBIT 5 assists enterprises in governance and management of enterprise IT and, at the same time, supports the need to meet security requirements with supporting processes and management activities. This paper provides analysis of mapping of COBIT 5 supporting processes to PCI DSS 3.0 security requirements. It also presents domains which support the simultaneous application of COBIT 5 and PCI DSS 3.0 which would help create collaborations within the enterpris

Richard Winsborrow - One of the best experts on this subject based on the ideXlab platform.