Home > PCI DSS Requirement 10: Track and monitor network access
Learning Guide:
EMAIL THIS

PCI DSS Requirement 10: Track and monitor network access

19 Sep 2007 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Many organizations have disparate networks and must manually track each system's log files in order to comply with PCI DSS. Individually sifting through system logs can not only be an extremely time-consuming process, but the task can also be a major drain on IT, especially when you need to determine the cause of a compromise. Organizations have to track and monitor all access to network resources and cardholder data, including real-time, daily and active events. Aside from managing these logs, most organizations don't have a good policy that addresses the various types of information being logged, and companies have no way of sustaining the integrity of the logged data. When it comes to having access to credit card data, organizations should not only have audit trails in place, but they should also only provide this kind of sensitive information to people who absolutely need to know it.

How to pass PCI Requirement 10
Even though analyzing logs and event data analysis is directly specified in the PCI DSS, it is simply good practice for any organization to monitor events. In an average information systems environment, event data is distributed, very large and at times hard to decipher. Most operating systems, by default, have utilities that analyze events, but they only offer basic features. Consequently, there is often no way for IT personnel to be alerted when specific critical events are logged, such as the unauthorized access of cardholder information. For the most part, the event browsing and filtering capabilities provided by these tools are restricted.

However, there are a number of impressive software- and hardware- based security information management (SIM) products that provide comprehensive log management. SIM tools can centralize events, automate the aggregation and correlation of event data, issue alerts and provide extremely detailed reporting capabilities. While aggregating events, SIMs will not only assist in creating a baseline of normal network activity, but they will also provide built-in rules to categorize them, triggering alerts and procedures as a result. Many security information management products also provide default rule sets that classify events according to PCI requirements.


A GUIDE TO PASSING PCI'S FIVE TOUGHEST REQUIREMENTS

  Requirement 3: Protecting stored data
  Requirement 11: Regularly test security systems and processes
  Requirement 8: Assign a unique ID to users
  Requirement 10: Monitor access to network resources, data
  Requirement 1: Install and maintain a firewall configuration
  Conclusion

ABOUT THE AUTHOR:
Craig Norris, CISSP, CISA, G7799, MCSE, Security+, CAPM, TICSA, is a Regional Engagement Manager at an IT consulting firm in Dallas. He has been involved with information technology and security for over 12 years. He can be contacted via canvip@yahoo.com.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Compliance Regulation and Standard Requirements
PCI DSS requirements still baffling as compliance deadline approaches
Make PCI DSS compliance easier by reducing scope, outsourcing data
Cloud computing compliance: Exploring data security in the cloud
Encryption basics: How asymmetric and symmetric encryption works
SIEM systems streamline compliance processes, offer security benefits
No major PCI DSS revision expected in 2010
PCI QSAs, certifications to get new scrutiny
Tips to achieve PCI compliance
PCI DSS requirements: Get ready for stricter enforcement, fines
Data Protection Act breach could cost companies 500,000 pounds

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Basel II  (SearchSecurityUK.com)
Code of Connection (CoCo)  (SearchSecurityUK.com)
EU Data Protection Directive  (SearchSecurityUK.com)
Financial Services Authority  (SearchSecurityUK.com)
IFRS (International Financial Reporting Standards)  (SearchSecurityUK.com)
UK Identity Cards Act  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




UK Network Security: VPN, Threat Management, Endpoint Protection, Wireless Security
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts