SecureWorks Provides Solutions to Help with Paymen
web hosting directory web hosting dedicated server colocation hosting web hosting services servers web hosting company web hosting article web host news web host news

web hosting
Cheap web hosting
Windows web hosting
Linux web hosting
Unrestricted hosting
Ecommerce web hosting
Virtual server VPS
Reseller hosting
by US State
by US City
Web Hosting coupons
VPS coupons
Articles

Cheap dedicated servers
Best dedicated servers
Windows dedicated servers
Linux dedicated servers
Unrestricted server
dedicated managed server
dedicated server unmetered
by US State
by US City
Dedicated server coupons
Articles

Cheap colocation hosting
Unrestricted Colocation
by US State
by US City
Coupons Promotion
Articles

Domain Registration
SSL Certificate
Website Statistics
Merchant account
Control panel
WebSite monitor

Intel Servers
AMD servers
SCSI Servers
Cheap Servers

Web hosting company
Dedicated Hosting
Colocation hosting
Web Hosting Services
Server manufacturer
Reviews

So you want to know how you decide what web host is best!

What is 1Mbps 95th percentile ?

Top 10 Dedicated servers May 2010

Westmere Dedicated server the best deal

Using CMS to create Websites

Top 10 Dedicated Servers March 2010

Control Panel Benefits

Top 10 Dedicated servers January 2010

More Articles


Ring the Christmas Bells with Infrenion Networks 50% Discount!

WebHost.UK.Net: offering web hosting great deals this Christmas.

Action Web Group Introduces The All New RubberBand Plan To Take The Place Of Unlimited Web Hosting!

Vision Helpdesk Christmas Madness is back! HO-HO-HO Huge Discounts!

Codero Names Jonathan Ewert as President and CEO

Lunarpages Boosts Reseller Plan

More News




SecureWorks Provides Solutions to Help with Payment Card Industry PCI Data Security Standard DSS Version 12

SecureWorks Provides Solutions to Help with Payment Card Industry PCI Data Security Standard DSS Version 12
Thursday October 2, 2008 13:10:02

SecureWorks Provides Solutions to Help with Payment Card Industry (PCI) Data Security Standard (DSS) Version 1.2

ATLANTA, Oct. 2 -- SecureWorks, a leading Security as a Service Provider (SaaS), announced today that they remain committed to helping organizations meet the Data Security Standard (DSS) version 1.2 released Oct. 1st by the Payment Card Industry (PCI) Security Standards Council. The revised standard provides clarification and changes intended to help organizations more effectively protect cardholder data.

SecureWorks is a Qualified Security Assessor Company (QSAC) and also an Approved Scanning Vendor (ASV) for PCI which enables SecureWorks to provide Reports on Compliance (ROCs) and to provide external and/or internal vulnerability scanning services required as part of the DSS version 1.2 specification. In addition, SecureWorks provides many other services that help companies meet various requirements of PCI DSS v1.2.

"We are pleased with the thoughtful modifications made by the Security Council," states Kathy Jaques, Chief Marketing Officer of SecureWorks. "The clarifications provide both assessors and companies with a better understanding of the intent of each section and, in some cases, create more flexibility to economically do what is needed to protect cardholder data while still meeting regulatory requirements. The PCI Community meeting held on September 22-24th, 2008 in Orlando, Fla. offered a helpful opportunity for assessors, vendors and merchants to ask additional questions to clarify intent."

The following is a subset of the changes made by the PCI Security Standards Council that most directly affect typical SecureWorks clients as well as a brief description of how SecureWorks can help companies meet each specific requirement as appropriate:

Requirement 1: Install and maintain a firewall configuration to protect cardholder data

SecureWorks provides firewall and other device reporting, monitoring and management services that can ensure that technologies are appropriately placed to segment the network to protect cardholder data from internet and internal threats. Our workflow and reporting provide an audit trail that firewall policies are reviewed as needed and no less often than required by PCI. PCI DSS version 1.2 changed the requirement to review firewall policies from every quarter to every six months.

Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters

Although ensuring that default passwords are re-set is largely a manual effort for merchants and other PCI organizations, SecureWorks helps companies meet section 2.2 by ensuring that the cardholder systems are regularly scanned for vulnerabilities and promoted for remediation according to the company's policy.

Requirement 3: Protect stored cardholder data

Requirement 3 speaks to the need to minimize storage of cardholder data and to use "strong cryptography" (updated from the previous specification to use "encryption") to protect cardholder data and to follow guidelines for secure cryptographic key generation, distribution and storage. As a QSAC, SecureWorks can work with companies to architect cryptographic controls that fit the business.

Requirement 4: Encrypt transmission of cardholder data across open, public networks

The PCI DSS v1.2 specification restricts the implementation of new wireless networks using WEP after March 31, 2009 and requires that current wireless implementations discontinue use of WEP after June 30, 2010. In addition, requirement 4 speaks to using strong cryptography and security protocols to protect data during transmission over open public networks and also speaks to protection of data communicated via standard messaging technologies such as email, chat and instant messaging. SecureWorks helps with a small piece of this requirement by providing an encrypted email solution to safeguard the email channel. This solution prevents cardholder data or personal confidential information from leaving or entering the company according to the company's policies - and without the need to alter business processes.

Requirement 5: Use and regularly update anti-virus software or programs

Companies are required to deploy and keep current software that detects and defends against malicious software. With PCI DSS version 1.2, the definition of anti-virus is expanded to include protection against all known types of malicious software, not just viruses. SecureWorks' Intrusion Prevention services protect companies at both the host and the network edge to ensure that desktop users are protected with a sound "defense-in-depth" solution. These rapidly deployed countermeasures provide protection even while desktop measures are being updated.

Requirement 6: Develop and maintain secure systems and applications

Requirement 6 is about staying informed on the threat landscape, ensuring systems are patched for vulnerabilities and following a sound software development lifecycle (SDLC) that is disciplined and provides for secure code review. SecureWorks provides a Threat Intelligence Service to help satisfy the requirement to "implement a process to identify newly discovered vulnerabilities" as stated in 6.2. In addition, SecureWorks is an Approved Scanning Vendor (ASV) and can provide internal and external scans of systems to determine where they are vulnerable. SecureWorks' scanning service prioritizes remediation efforts to support a risk-based approach to remediation with a necessary audit trail. PCI DSS version 1.2 6.6 requires that either web application vulnerability scanning or web application firewall tools be implemented to protect internet-facing web applications. Both of these services are available from SecureWorks. Finally, SecureWorks provides professional services to perform application code reviews as specified in sections 6.3.7 and 6.5.

Requirement 7: Restrict access to cardholder data by business need-to-know

Section 7 of PCI DSS 1.2 focuses on restricting access to systems with cardholder data to those who "need to know." SecureWorks provides log monitoring and retention solutions to track actual logins and failed login attempts in addition to other logs to ensure that policies are being followed. In addition, the professional services team of SecureWorks can work with companies to identify and document which systems require what level of access and where "default accept" access is the default so that these systems can be changed.

Requirement 8: Assign a unique ID to each person with computer access

Requirement 8 ensures that each user has a unique ID making it possible for actions taken on cardholder data to be associated with a specific user. SecureWorks' professional services team can help define the policies and processes needed and can test whether those policies and processes are being followed consistently.

Requirement 9: Restrict physical access to cardholder data

PCI DSS version 1.2 requirement 9 focuses on ensuring that physical access to cardholder data is restricted and monitored and that physical locations where data is stored are periodically inspected. SecureWorks' professional services organization can help develop policies and procedures to ensure physical security of cardholder data and can test whether those policies and procedures are being followed consistently.

Requirement 10: Track and monitor all access to network resources and cardholder data

Companies must demonstrate that they are logging and tracking all user access to cardholder data to provide early identification of problems and essential information to resolve problems. SecureWorks provides log monitoring and log retention services to capture all information required by section 10 and to meet the requirement for daily log reviews (either by technology or by security analysts) and log retention with immediate access to archived logs should it be required. This is offered as a managed service and also as a SaaS-delivered solution.

Requirement 11: Regularly test security systems and processes

Requirement 11 of PCI DSS version 1.2 clarifies that both internal and external penetration testing is a yearly requirement for PCI compliance. Penetration testing is different than performing a vulnerability assessment (a point of confusion for many companies) in that vulnerability scanning is automated and is done regularly to identify where patches are required while penetration testing is done periodically and includes manual methods to both find vulnerabilities and attempt exploits. Penetration testing can include methods such as phishing and social engineering that test other aspects of a company's readiness for hacking techniques. Penetration testing must include testing of the application layer. SecureWorks offers a PCI compliant penetration test.

Requirement 11.4 requires the use of intrusion prevention systems (host and/or network) that can monitor network traffic and alert staff to suspected compromises. SecureWorks provides Network Intrusion Prevention and Host Intrusion Prevention monitoring and management services that can either alert on or block malicious activity. Leveraging visibility across a large client population (2,000+) and a robust Attacker Database (patent pending), SecureWorks protects clients from electronic perpetrators.

Requirement 12: Maintain a policy that addresses information security for employees and contractors

Requirement 12 requires a robust security policy that is well-communicated to all employees and significant partners and vendors. In addition, companies are required to implement security awareness training programs that provide documentation for assessors of an effective and unilateral education program. Companies must also have an incident response plan in place and a thorough vendor/partner management program to ensure that risk is not introduced by connected entities. SecureWorks offers Security Awareness Training Programs, incident response planning, and is launching a new service called Compliance Central(TM) that will aid with vendor and partner security management. We also have a PCI policy package to help speed along compliance efforts.

"The PCI Security Council made several other important changes to the standard to clarify scope, third parties, sampling and compensating controls," continued Jaques. "In addition, the Council is implementing a Quality Assurance program that will provide for regular audits of QSA and ASV providers to ensure that they are providing services that fully meet the intent of the PCI DSS standard. SecureWorks is committed to providing high-quality and high-integrity services to serve the PCI community and applauds the PCI Security Standards Council for implementing Quality Assurance controls."

For detailed information on PCI DSS Requirements and Security Assessment Procedures Version 1.2 and for additional guidance on changes made in version 1.2, please visit https://www.pcisecuritystandards.org/.

About SecureWorks

With over 2,000 clients, SecureWorks is one of the market's leading Security as a Service providers. Organizations are protected from external and internal cyber-threats through SecureWorks' On-Demand Security Information and Event Management (SIEM) platform, the SecureWorks Counter Threat Unit(TM) and three fully synchronous Security Operations Centers (SOCs) staffed with SANS GIAC certified analysts working 24x7 to safeguard client systems. SecureWorks has won SC Magazine's "Best Managed Security Service" award for 2006, 2007 & 2008, Best Intrusion Prevention 2006 and has been named to the Inc 500 and Deloitte lists of fastest-growing companies.

www.secureworks.com.





Related Articles

SecureWorks Inc Wins SC Magazines Reader Trust Award for Best Managed Security Service for Four Years Running
SecureWorks, Inc. Wins SC Magazine's Reader Trust Award for Best Managed Security Service for Four Years Running ATLANTA, April 23 -- SecureWorks(R), one of the market's leading Security as a...
Thursday April 23, 2009 15:10:01
Security
Major Retailers Experience 161% Increase in Attempted Hacker Attacks According to SecureWorks
Major Retailers Experience 161% Increase in Attempted Hacker Attacks, According to SecureWorks Online Shoppers and Retailers Advised to Take Protective Steps this Holiday Season and Beyond ATLANTA,...
Thursday December 4, 2008 15:10:01
Security
SecureWorks and Microsoft Collaborate to Deliver Enhanced Protections for Security Vulnerabilities
SecureWorks and Microsoft Collaborate to Deliver Enhanced Protections for Security Vulnerabilities The Microsoft Active Protections Program (MAPP) Clears the Way for a More Rapid Response to...
Tuesday October 14, 2008 13:10:01
Windows
SecureWorks Provides Solutions to Help with Payment Card Industry PCI Data Security Standard DSS Version 12
SecureWorks Provides Solutions to Help with Payment Card Industry (PCI) Data Security Standard (DSS) Version 1.2 ATLANTA, Oct. 2 -- SecureWorks, a leading Security as a Service Provider (SaaS),...
Thursday October 2, 2008 13:10:02
Security
Community Bankers Association of Oklahoma Endorses SecureWorks as their IT Security Services Provider of Choice
Community Bankers Association of Oklahoma Endorses SecureWorks as their IT Security Services Provider of Choice ATLANTA, and OKLAHOMA CITY, June 30 -- Community Bankers Association of Oklahoma...
Monday June 30, 2008 11:10:02
Security
SecureWorks Wins SC Magazines Readers Trust Award for Best Managed Security Service for Three Years Running
SecureWorks Wins SC Magazine's Readers' Trust Award for Best Managed Security Service for Three Years Running ATLANTA, April 11 -- SecureWorks, one of the market's leading Security as a Service...
Friday April 11, 2008 11:10:01
Security
Security Services Provider SecureWorks Partners with Corporate America Credit Union to Deliver Security Services to Credit Unions Nationwide
Security Services Provider SecureWorks Partners with Corporate America Credit Union to Deliver Security Services to Credit Unions Nationwide ATLANTA, Feb. 5 -- SecureWorks(R), one of the market's...
Tuesday February 5, 2008 12:10:01
Security
SecureWorks Designated as a Qualified Security Assessor for PCI Audits
SecureWorks Designated as a Qualified Security Assessor for PCI Audits Now able to certify retailers, utilities, financial institutions, healthcare organizations and others ATLANTA, Dec. 18 --...
Tuesday December 18, 2007 12:10:01
Web Host
Number of Hackers Targeting Utilities Increases 90 Percent According to SecureWorks Data
Number of Hackers Targeting Utilities Increases 90 Percent According to SecureWorks' Data Firm Warns of Browser Attacks ATLANTA, Oct. 5 -- SecureWorks, one of the industry's leading managed...
Friday October 5, 2007 08:10:01
Web Host
SecureWorks Positioned in the Leaders Quadrant for Advisory Firms Managed Security Services Provider Magic Quadrant for 1HO7
SecureWorks Positioned in the Leaders Quadrant for Advisory Firm's Managed Security Services Provider Magic Quadrant for 1HO7 Evaluation Based on Completeness of Vision and Ability to Execute...
Friday August 3, 2007 11:10:07
Hardware

Related Categories

Search news  
AskWebHosting Top Categories

Dedicated Hosting DirectoryServer Colocation DirectoryRackmount Server Directory
Webmaster Resources DirectorySpecial offersArticles
Shared Web Hosting Directory




Special offer



TOP 10 Best Dedicated Servers January 2011


AskWebhosting.com recommends 3dstats.com real time web statistics for tracking your visitors.

SingleHop Review
Codero Review
1&1 USA Review
DedicatedNOW Review
TurnKey Review
iWeb Review
ServerPronto Review

iPage Review
JustHost Review
FatCow Review
CoolHandle Review
midPhase Review
HostMonster Review
BlueHost Review
Hostgator Review

Core2Quad Q9650 • 2x 500 GB HDD • 8 GB MEMORY • 6TB Bandwidth Unmetered • $165 mo dedicated server

hetzner ex4 dedicated server for transfer special server

Core2Duo 2GB RAM 400GB HD 10TB Bandwidth 1GigE $39 95 m dedicated server

Single Dual Quad Xeons 100 TB Bandwidth 20% OFF LIFE 12 GB Ram dedicated server

OBHosting com Intel Xeon 4GB Ram 500GB HDD 2TB Traffic 95$ per month dedicated server

USDediDirect Dual Quad 2 5Ghz 8GB Ram 500GB HD 10TB BW $75 M dedicated server

pure web technologies us dedicated servers $99 premium bandwidth 24 7 support

NL InstantDedicated com E31260L 8 GB RAM 1 Gbit 30 TB for 115 EUR dedicated server

Awesome new managed EU and US builds for LOW LOW PRICES dedicated server

cpanel linux dedicated server offers r1soft™ cdp and more us

loopbyte india dedicated servers i3 i5 i7 e31230 1200gb bandwidth from $149 m

$160 lt MONTHLY gt 16Gb RAM XEON E31230 2x1T HDDs dedicated server

guardhosts comunmetered dedicated servers from $35 monthfr

Zuya Host LLC Dual Quad Core 8GB Ram 500GB HD 10TB BW $30 mo dedicated server

eu quad core dedicated server 24 core dedicated server optional free plesk

SingleHop coupon

Web Hosting deals

VPS Hosting deals

Colocation deals

More Deals


Free Web Stats
Web Statistics
Web Templates
Free Photos


2010 AskWebHosting.com    Contact-us    Advertise    Register    Web Hosting Questions    Privacy Policy