Home > Financial Services Information Security Tips > Compliance and Governance Digest > How to use PCI to your (budgetary) advantage
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE AND GOVERNANCE DIGEST

How to use PCI to your (budgetary) advantage


Spyro Malaspinas, Contributor
06.24.2008
Rating: --- (out of 5)


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


A deeper dive into the PCI requirements and how they may help justify your security expenditures in the coming quarters and years is something that all security practices should engage in.
Spyro Malaspinas
PCI can offer a means to an end for those budgets which are consistently denied for secure email solutions, firewalls to protect your infrastructure, and training for security personnel. Embrace these controls for training and new technology that can be leveraged for other infrastructure, best practices and regulatory controls.

Firewalls: Requirements 1.1.3, 1.3.4, 1.3.9, 6.6
Essential to any feasible defense against widespread malware attacks and malicious internal and external connections, is segmentation at the network layer by way of a stateful firewall. Several PCI requirements mandate the use of firewalls at all Internet connections, between the DMZ and internal networks, and in front of all databases that store cardholder data. Leverage these requirements for your capital request of a firewall that will allow for multiple physical or virtual interfaces; these will allow for segmentation and inspection of all traffic, above and beyond packets destined for the cardholder environment.

Remember that application firewall you always wanted? PCI has armed any financial organization subject to PCI with a hammer in requirement 6.6. As of June 30, 2008 all Web facing applications must be protected from known attacks by means of an exhaustive code review or an application-layer firewall. Annual code reviews can be a great deal more expensive than the purchase of an application-layer firewall. Like network-based firewalls, application-layer firewalls can be used to protect other applications on the DMZ. It should be noted that several of the more progressive security vendors today offer the ability to filter at the application and network layer.

Lastly, personal firewalls are required for any system that connects remotely to your cardholder environment. This can be used as justification to procure and secure all laptops.

Wireless access points: Requirements 2.1.1, 4.1.1, 11.1
The TJX breach revealed an estimated 45 million compromised credit card numbers. The breach was linked back to the use of WEP, a dated and obsolete wireless encryption protocol. WEPs replacement, WPA/WPA2, though not required by PCI DSS yet, will likely be the baseline standard in the next PCI DSS standard 1.2, which is expected in September, 2008. Irrelevant of its requirement, TJX is the motivation behind ensuring the use of secure wireless solutions which enforce WPA/WPA2. Newer access point technologies provide organizations with increased bandwidth, quality of service filtering, better management, and rogue access point detection.

Encryption and key management: Requirements 3.4-3.6
If your organization chooses to store cardholder data electronically, it must do so via an encrypted means that adheres to what many call PCI's most challenging requirements, encryption and key management controls. Adhering to this standard is trying; more often than not encryption appliances or encryption specific software is purchased to handle the numerous enterprise applications that both read and write cardholder data from information stores. The benefit of such a solution is that these appliances and software solutions can be used to encrypt any sensitive information inclusive of social security numbers, personnel records, intellectual property, and health and customer records.

Training: Requirements 12.6, 12.9.4
Perhaps the biggest complaint I hear amongst security practitioners is the lack of training that they are afforded on an annual basis. Economic pressures are forcing nearly all organizations to cut back on "discretionary" costs. First to go for many organizations is security training for IT staff and general security awareness for all personnel. PCI has an answer to this in Requirement 12.6 and 12.9.4.

More information
Learn how to manage the PCI DSS process to limit liability.

PCI automation can be very beneficial: Read more.
Requirement 12.6 mandates a formal security awareness program for all employees that have access to, or handle cardholder data. Some of the most successful training materials can be delivered via PCI workshops and Web training modules. There are several security vendors that have effective pre-built Web training modules for dissemination to geographically diverse organizations.

Requirement 12.9.4 stipulates that all incident response staff attend an appropriate training for fulfillment of their duties. The most effective training will often come from outside organizations. Not only will formal incident response/security training help your organization in the event of a security incident, but it can do wonders for the morale of your security staff.

Other requirements that can be leveraged as justification for investment in security tools and or training:

  • Email encryption: Requirement 4.2
  • Separate test and development requirements: Requirement 6.3.2
  • Formalize security policies: Requirement 12
  • Penetration testing services: Requirement 11.3

This list is not exhaustive; a deeper dive into the PCI requirements and how they may help justify your security expenditures in the coming quarters and years is something that all security practices should engage in. When preparing your budget for review, it's important to note that many of these security tools will improve an organizations security posture while creating operational efficiencies.

About the author
Spyro Malaspinas, CISSP, CISM, CISA, GCIH, CCNA, CSPFA, CCSE+, NSA, Six Sigma, is a Principal at ThreeFactor Security and can be reached at spyrom@threefactor.com. Spyro formerly served as the PCI Practice Leader at Symantec, a Sr. Security Consultant at VeriSign, and Security Architect at IBM. He has been performing compliance assessments, remediation, Risk and Compliance Program Management functions for some of the largest merchants and service providers found globally.


Rate this Tip
To rate tips, you must be a member of SearchFinancialSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Compliance and Governance Digest
Shifting to a flexible information security framework
Vendor contract management: Regulatory guidance is risk-based
Vendor audit and monitoring contractual rights
Data breach protection: Implementing vendor breach safeguards
How to manage security risks in vendor contracts
Red Flags Rule and preparing for new regulations
Companies lagging in PA DSS compliance
Social media: Risk management strategies for financial institutions
FFIEC guidance on RDC: Guidance overview
FFIEC guidance on RDC: Risk management basics

PCI DSS: Audits and requirements
Vendor contract management: Regulatory guidance is risk-based
Vendor audit and monitoring contractual rights
RBS WorldPay agrees to market VeriFone end-to-end encryption
Companies lagging in PA DSS compliance
Download presentations from Financial Information Security Decisions 2009
Two conversations about risk assessment
Why financials should pay attention to NERC CIP
Infosecurity pro pitfalls
RBS WorldPay regains spot on Visa's PCI compliance list
Tokenization and PCI compliance

Information security awareness training
Social engineering tests should make sense, not headlines
Laid off workers likely to steal company data, survey warns
Phishing, malware to strain banks in 2009
How to make information security a company-wide effort
The Societe Generale fraud story: Keith White on fraud
Rogue activity thwarted by early warning systems
An overview of the FFIEC IT Examination Handbooks
Bank boosts security after couriers lose backup tapes
Security survival skills critical to weathering shrinking budgets
Online tax firm seeks exemption from hackers

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CISP-PCI  (SearchFinancialSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Finance Sector Security - Anti-Phishing, Remote Access Security, Firewall Systems
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts