05.02.2013 Views

download issue 24 here - Help Net Security

download issue 24 here - Help Net Security

download issue 24 here - Help Net Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

To achieve this, retailers must shift their view<br />

of security and compliance from a checklist<br />

mentality for passing an audit to a state of<br />

continuous IT security.<br />

Permanent and uncompromising process discipline<br />

must be instituted on the data security<br />

domain to achieve consistent, effective protection<br />

for the sensitive and confidential customer<br />

information collected and stored.<br />

While this may sound like a daunting task—especially<br />

for smaller retail merchants—using<br />

an automated IT Governance, Risk and Compliance<br />

(IT GRC) solution provides the type of<br />

information and the security framework<br />

needed for achieving and sustaining a high<br />

level of continuous compliance—and security.<br />

The GRC model<br />

"GRC" refers to a class of automated systems<br />

that help organizations integrate and control<br />

the management of complex regulatory mandates<br />

and operational risk in alignment with<br />

appropriate high level company governance.<br />

GRC is a strategic approach to the universal<br />

concept of compliance. It can help retailers<br />

meet PCI compliance requirements as well as<br />

providing a controls management framework<br />

to protect other types of customer-confidential<br />

information.<br />

PERMANENT AND UNCOMPROMISING PROCESS DISCIPLINE MUST BE<br />

INSTITUTED ON THE DATA SECURITY DOMAIN TO ACHIEVE CONSISTENT,<br />

EFFECTIVE PROTECTION FOR THE SENSITIVE AND CONFIDENTIAL<br />

CUSTOMER INFORMATION COLLECTED AND STORED.<br />

The information security policy<br />

While many retailers approach PCI DSS compliance<br />

as a technology problem, itʼs just as<br />

much a people problem. Simply installing the<br />

best firewall and encryption technologies is<br />

just the first part of the solution. Following IT<br />

security best practices and establishing a written<br />

security policy is the next step, but if employees<br />

arenʼt following those policies the organization<br />

remains vulnerable. According to<br />

Deloitteʼs “The 6th Annual Global <strong>Security</strong><br />

Survey,” “people are the problem.”<br />

The report states that, “Human error is overwhelmingly<br />

stated as the greatest weakness<br />

this year (86%), followed by technology (a distant<br />

63%).” The Computing Technology Industry<br />

Association, Inc. (CompTIA) echoes that<br />

assessment in its "Committing to <strong>Security</strong>: A<br />

CompTIA Analysis of IT <strong>Security</strong> and the<br />

Workforce," survey stating that, “Human error,<br />

not technology, is the most significant cause of<br />

IT security breaches.”<br />

To reduce security risk cause by human error,<br />

a retailer must have a process for distributing<br />

its IT security policy and ensuring that each<br />

employee has read and understands the pol-<br />

icy and acknowledges their responsibility in<br />

protecting the organizationʼs information and<br />

data. GRC systems have <strong>Security</strong> Awareness<br />

modules make it easy for retailers to educate<br />

employees on general IT security practices<br />

and internal IT security policies. The Awareness<br />

module also tracks who takes each<br />

course and records test scores.<br />

Business continuity planning<br />

The impact of a data breach can be devastating.<br />

IT GRC systems include a Business Continuity<br />

Planning (BCP) component that provides<br />

retailers with a single source repository<br />

for the guidance, information and plans necessary<br />

to respond to a data breach incident.<br />

Continuous PCI compliance for small merchants<br />

Smaller merchants are an appealing target for<br />

cybercriminals because they often do not have<br />

the expertise to properly secure card holder<br />

data. A GRC tool delivered as “Software as a<br />

Service” (SaaS), hosted at a remote location<br />

and delivered over the Internet, makes it affordable<br />

and adaptable for any size merchant.<br />

www.insecuremag.com 78

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!