close

What Is Truth to Power?

dedicated to bridging the gaps between governance and practice, technology and business, regulation and control, risk management and real market pressures, and your own knowledge and the knowledge of your peers.
built to create a common pool of knowledge—one big brain—that lets you work more efficiently, build technology and business practices more effectively, and endure audits more effortlessly.
a neutral hub through which you can reach many valuable information nodes, resource collections, and organizations that are helping people like you already, but in fractured ways.
against the idea that auditors, analysts, and consultancies can control information simply through their ability to collect and distill it. T2P's goal is to unlock the vast body of knowledge, insight, and conventional wisdom that we all have, make it freely available to you, and help you digest and interpret it—without undue cost, bias, or hype.
Top Panel
WHAT IS T2P?
Top Panel
Research: PCI: Requirements to Action

A More Rational Approach to Card Data Security

The Payment Card Industry Data Security Standard (PCI) is as notable for the guidance it offers as for that it omits. By parsing card data protection into a 12-step program, PCI provides an accessible guide to a reasonably complete information security practice.

Yet, by assuming much of the security- and risk-management context that provides efficiency and effectiveness in enterprise implementations, PCI leaves many opportunities for budgetary gaffes and breach events.

Addresses key PCI gaps ad assumptions, this research paper supports integration of the standard into strategic risk- and security-management programs. Content includes:

  • More than 240 procedural action items, categorized by PCI DSS Section
  • An analytical perspective on PCI requirements
  • Concrete, experience-based advice on how to use PCI as a lever to build and advance the overall organizational security program
  • References to useful resources that support an integrated compliance approach
  • Translating PCI assessment requirements into implementable actions

New Advisory Supplement:
10 High-Impact Steps to Harden Commerce Systems

Although information security may be a continuous process, security risk is inconstant. Environmental variables, such as seasonal business fluctuations and conditions, emergent threats, staff resource availability, and budget levels impact practical security needs and priorities. Your ultimate goal might be to secure all system components all of the time; however, high-stress situations beg the question: "What can I do right now to secure critical information?"

This Advisory Supplement, bundled with the Truth to Power research paper PCI: Requirements to Action, addresses the question with more than 30 practical recommendations for quickly:
  • Securing routers, firewalls, and wireless access points
  • Reducing the risk exposure of  user accounts and network resources
  • Training retail sales-floor staff to enforce security procedures
  • Improving incident response capabilities



This research bundle is a Truth to Power original resource, freely available to all registered members of the community. If you are not yet a member, please join now. It's free.


Note: This resource is made possible by the support of Tripwire, Inc. T2P does not charge for research offerings and strictly observes vendor neutrality in all community publications (more about that here). Companies such as Tripwire support this model by underwriting our research efforts in exchange for the contact information of individuals who download the paper. We hope you agree that sharing your contact information is a good-value proposition for substantive guidance. However, if you do not wish us to share your information, do not access this resource.






The new supplement includes more than 30 specific checklist steps for:

-- Securing routers, firewalls, and wireless access points

-- Reducing the risk exposure of  user accounts and network resources

-- Training sales-floor staff to enforce security procedures

-- Facilitating more efficient, effective incident responses

Comments
Add New RSS
Write comment
Name:
Email:
 
Website:
Title:
UBBCode:
[b] [i] [u] [url] [quote] [code] [img] 
 
 
Please input the anti-spam code that you can read in the image.

3.26 Copyright (C) 2008 Compojoom.com / Copyright (C) 2007 Alain Georgette / Copyright (C) 2006 Frantisek Hliva. All rights reserved."