Showing posts with label PCI. Show all posts
Showing posts with label PCI. Show all posts

Tuesday, December 24, 2013

Are You a "Target"?

   By now, most of you have probably heard about the Target credit card information breach.  This is very big here in Minneapolis, home of Target.  All the details aren't out yet but it appears that credit card information for brick-and-mortar stores between Friday Nov. 27 ("Black Friday") and Sunday Dec. 15.  Here are some articles covering the story.  Here's Target's response and an FAQ.

   I'd like to talk a bit about next steps.  If you've been the victim of a data breach... what next?

   First... for consumers.  Target is a retail company and the direct victims of the breach are those of us who shopped at a Target store during the dates in question.  Consumers have two concerns here: credit card fraud and identity fraud. (I don't like the term "identity theft" even though it is commonly used.  No one can steal your identity... you still have it.  They can improperly discover, and misuse, the details... a.k.a. fraud.)

Tuesday, August 20, 2013

Beyond the Checklist - Compliance v. Security

   SC Magazine put out a good article last week entitled Beyond the Checkbox: PCI DSS.  The article cover new revisions in the Payment Card Industry (PCI) security standard (Data Security Standard DSS).

   The point of the article is something I've been saying for years... That we can simply treat security regulatory standards as checklists.  It's not about just meeting the minimum requirements.  It's about integrating the standards into your security program.

   Now, I'm not completely dismissing checklists.  In fact, I think they have some great places within your program.  For example: server build checklists; server hardening checklists, and; an SDLC checklist.  I'm a big fan of the CIS checklists for hardened configurations.  I also like a standardized secure engineering process (or SDLC) with specific steps.

   As I've discussed here in the past, one size does not fit all.  While we can all share our processes, it's critical to tailor any process or checklist to your environment.

   But here's my main point... Compliance does not equal Security!