|
|
|
Continuous File Integrity Monitoring: A New Approach for PCI DSS Compliance
sponsored by McAfee, Inc.
|
|
When it comes to IT infrastructure, a strong compliance posture requires two key components: Trusted state and safe change actions. Payment Card Industry Data Security Standard (PCI DSS) compliance, in particular, highlights the need for safe change actions through the following requirements:
PCI Control 10.5.5: Use file integrity monitoring and change detection software on logs to ensure that existing log data cannot be changed without generating alerts (although new data being added should not cause an alert).
PCI Control 11.5 - Deploy file integrity monitoring software to alert personnel to unauthorized modification of critical system or content files.
Recent independent research indicates that these are among the least satisfied requirements across Level 1 merchants, with almost 40% non-compliance. This is why many organizations facing PCI DSS compliance are looking at file integrity monitoring solutions. Anyone evaluating these solutions should be aware that the technology in this area has evolved significantly and a new breed of solution is now available.
(THIS RESOURCE IS NO LONGER AVAILABLE.)
|
|
|
|
Available Resources from McAfee, Inc.
|
 |
 |
sponsored by McAfee, Inc.
WHITE PAPER -
Data--Protect critical information anywhere it goes. Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.
Posted: 01 Sep 2009 |
Published:
01 Jul 2009
|
|
|
|
|
|
SecurityPark Research Library Copyright © 1998-2009 Bitpipe, Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. TechTarget · 117 Kendrick St · Needham, MA · 02494
Use of this web site constitutes acceptance of the Bitpipe Terms and Conditions and Privacy Policy. webmaster@bitpipe.com
|