Home > Financial Services Information Security News > Solidcore launches PCI file integrity software
Financial Services Information Security News:
EMAIL THIS

Solidcore launches PCI file integrity software

By SearchSecurity.com Staff
03 Mar 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

The PCI Data Security Standard has become one of the thornier compliance challenges for enterprises and small businesses alike in the last couple of years, and as the standard continues to change, it's likely to get no easier anytime soon. A small cottage industry of assessors, software suppliers and consultants has sprung up to help businesses comply with the requirements, but much of the nuts and bolts is still left to the security and compliance staffs.

To help ease some of this pressure, Solidcore Systems Inc. on is introducing two new offerings designed to help businesses comply with two of the more difficult sections of the standard. Solidcore S3 Control PCI Pro Edition is meant for large enterprises and service providers, those companies with the most complex and involved PCI compliance efforts. The new application is specifically targeted at helping these companies comply with categories 10 and 11 of the PCI standard, which cover the need for software to monitor file integrity and changes. The second offering, aimed at small and medium businesses, is S3 Control Starter Edition.

Solidcore, of Cupertino, Calif., designed the applications as stripped-down versions of the company's flagship S3 Control product with the intent of giving customers just the features they need to comply with PCI DSS and leaving out the extraneous elements.

PCI DSS news tips and advice:
PCI DSS 3.1 best practices: Requirement 3.1 of the PCI Data Security Standard requires minimum cardholder data storage. In this tip, learn how to determine how much data your organization should store.

How Chevron met the PCI DSS deadline: Layered defenses made PCI DSS compliance easy, but one expert sees a need for improved wireless standards.

Look before leaping into database encryption: Encryption is the ultimate mechanism for data protection, but the process of developing an encryption strategy can be daunting.

"They're much easier to install and configure than the enterprise product. You get a single installer and it works with the default settings," said Rishi Bhargava, director of product management at Solidcore. "Right now there is no cost-effective solution for the midmarket if people just want to meet the standard and not bother with all of the other functionality. How can somebody get off the ground right away with less cost and effort?"

Both editions of the software record all of the changes to protected files. It also enables administrators to see which users made changes to files and at what time the changes were made. This capability goes beyond what even the PCI standard dictates, Bhargava said. "All it says right now is that when a critical file changes, you should have an audit trail of that change," he said. "It stops there. That's because that's what the state of the art was when it was written. That will change over time."

Bhargava added that one of the reasons that an estimated 30% of Level 1 enterprises are still non-compliant with PCI DSS is the constantly changing interpretations of the various sections of the standard.

A lot of customers are in pain because of the changing interpretations and how [qualified security assessors] want to report compliance or non-compliance," he said. "PCI DSS hasn't changed. The interpretation has changed. That will be true for the next couple of years. When they write the standard, they can't write the exact interpretation because they don't know what innovations will happen on the product side to meet it."



Tags: PCI DSS: Audits and requirementsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
PCI DSS: Audits and requirements
Vendor contract management: Regulatory guidance is risk-based
Vendor audit and monitoring contractual rights
RBS WorldPay agrees to market VeriFone end-to-end encryption
Companies lagging in PA DSS compliance
Download presentations from Financial Information Security Decisions 2009
Two conversations about risk assessment
Why financials should pay attention to NERC CIP
Infosecurity pro pitfalls
RBS WorldPay regains spot on Visa's PCI compliance list
Tokenization and PCI compliance

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CISP-PCI  (SearchFinancialSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Financial Security News Topics: Compliance, Management Strategy, Security Technology
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts