By now, most of you have probably heard about the Target credit card information breach. This is very big here in Minneapolis, home of Target. All the details aren't out yet but it appears that credit card information for brick-and-mortar stores between Friday Nov. 27 ("Black Friday") and Sunday Dec. 15. Here are some articles covering the story. Here's Target's response and an FAQ.
I'd like to talk a bit about next steps. If you've been the victim of a data breach... what next?
First... for consumers. Target is a retail company and the direct victims of the breach are those of us who shopped at a Target store during the dates in question. Consumers have two concerns here: credit card fraud and identity fraud. (I don't like the term "identity theft" even though it is commonly used. No one can steal your identity... you still have it. They can improperly discover, and misuse, the details... a.k.a. fraud.)
A place to talk about information security, Internet safety and, of course... coffee!
Thoughtful, sometimes controversial, but not following the crowd unless I'm in line at the coffee shop.
Showing posts with label PCI. Show all posts
Showing posts with label PCI. Show all posts
Tuesday, December 24, 2013
Tuesday, August 20, 2013
Beyond the Checklist - Compliance v. Security
The point of the article is something I've been saying for years... That we can simply treat security regulatory standards as checklists. It's not about just meeting the minimum requirements. It's about integrating the standards into your security program.
Now, I'm not completely dismissing checklists. In fact, I think they have some great places within your program. For example: server build checklists; server hardening checklists, and; an SDLC checklist. I'm a big fan of the CIS checklists for hardened configurations. I also like a standardized secure engineering process (or SDLC) with specific steps.
As I've discussed here in the past, one size does not fit all. While we can all share our processes, it's critical to tailor any process or checklist to your environment.
But here's my main point... Compliance does not equal Security!
Labels:
access,
alignment,
basics,
business,
checklist,
compliance,
computer,
cybersecurity,
effectiveness,
encryption,
framework,
good_practices,
infosec,
PCI,
program,
requirements,
SDLC,
security
Subscribe to:
Posts (Atom)