Security Park, the leading online news site for security professionals
Home | About us | Contact us | Submit an article | Advertise | Sales leads | Newsletter | RSS Newsfeed | SEARCH




Develop an ISO 27001-compliant Information Security Management System
This useful guide clarifies the steps you have to follow to develop an ISO 27001-compliant ISMS. Each step is integral in how secure your information security system is.

Need a
reference book?
Find it on Amazon:
Security books and magazines in association with Amazon.co.uk

SecurityPark Research Library

Help | Advanced Search
What's New?
What's Popular?
Continuous File Integrity Monitoring: A New Approach for PCI DSS Compliance
sponsored by McAfee, Inc.

When it comes to IT infrastructure, a strong compliance posture requires two key components: Trusted state and safe change actions. Payment Card Industry Data Security Standard (PCI DSS) compliance, in particular, highlights the need for safe change actions through the following requirements:

  • PCI Control 10.5.5: Use file integrity monitoring and change detection software on logs to ensure that existing log data cannot be changed without generating alerts (although new data being added should not cause an alert).
  • PCI Control 11.5 - Deploy file integrity monitoring software to alert personnel to unauthorized modification of critical system or content files.

Recent independent research indicates that these are among the least satisfied requirements across Level 1 merchants, with almost 40% non-compliance. This is why many organizations facing PCI DSS compliance are looking at file integrity monitoring solutions. Anyone evaluating these solutions should be aware that the technology in this area has evolved significantly and a new breed of solution is now available.

(THIS RESOURCE IS NO LONGER AVAILABLE.)
 
Available Resources from McAfee, Inc.
sponsored by McAfee, Inc.

WHITE PAPER - Data--Protect critical information anywhere it goes. Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.
Posted: 01 Sep 2009 | Published: 01 Jul 2009


Library Home | Advertise with Us | Product Library
A Service of Bitpipe