Data Auditing Blog View Mantra V5

Photo: Prat Moghe
 

Prat Moghe was the founding CEO of Tizor and led the company from 2002 to 2006 including driving the launch of its product into the data auditing market. Prat led Tizor through two financing rounds and established its security and compliance market strategy.
Read More »

Subscribe By Email

Your email:

Keepers

Current Articles | RSS Feed RSS Feed

PCI Q&A Session with Retailers

 | Digg digg it | Reddit reddit | del.icio.us del.icio.us 
James Deluccia IV (Compliance Expert and Author of upcoming book on IT Controls) and I hosted an online seminar focusing on PCI Compliance last week. Bill Bartow moderated the session; Stephanie Weagle did an excellent job of managing the logistics. We had over one hundred Level 1 and Level 2 retailers, financial services organization and energy companies attend the session. All the participants were invited to ask us questions surrounding PCI –James and I went through these questions and provided our thoughts on how to address them. For an on-demand recording of the session, please check out: So you think you're compliant

Here are the top few popular questions (in no particular order):
  1. What are the key data protection technology investments we should make to keep credit card data safe?
  2. Should we be concerned with internal threat or external threat?
  3. What exactly are the retention and encryption requirements for data at rest and data in transit?
  4. What are the challenges around encryption projects and what are the compensating controls for encryption?
  5. How do we address PCI 10 Audit Trail requirement? Are log scraping tools or SIM solutions adequate for this?
  6. What are the expectations when it comes to securing the audit trail?
  7. How should we discover and inventory where the credit card data is stored?
  8. What type of reports should we generate and how should we manage the workflow with assessors and auditors?
If you have additional questions or comments, please email me below or at prat@tizor.com

Posted by Prat Moghe on Mon, Dec 10, 2007 @ 12:16 PM

COMMENTS

Currently, there are no comments. Be the first to post one!
Post Comment
Name
 *
Email
 *
Website (optional)
Comment
 *

Allowed tags: <a> link, <b> bold, <i> italics

Receive email when someone replies.