Showing posts with label banking. Show all posts
Showing posts with label banking. Show all posts

Tuesday, April 24, 2012

Complying with PCI DSS–Part 5: Regularly Monitor and Test Networks

According to the PCI SSC, there are 12 PCI DSS requirements that satisfy a variety of security goals.  Areas of focus include building and maintaining a secure network, protecting stored cardholder data, maintaining a vulnerability management program, implementing strong access control measures, regularly monitoring and testing networks, and maintaining information security policies.  The essential framework of the PCI DSS encompasses assessment, remediation, and reporting.  We’re exploring how F5 can help organizations gain or maintain compliance and today is Regularly Monitor and Test Networks which includes PCI Requirements 10 and 11.  To read Part 1, click: Complying with PCI DSS–Part 1: Build and Maintain a Secure Network, Part 2:Complying with PCI DSS–Part 2: Protect Cardholder Data, Part 3: Complying with PCI DSS–Part 3: Maintain a Vulnerability Management Program and Part 4: Complying with PCI DSS–Part 4: Implement Strong Access Control Measures.

Requirement 10: Track and monitor all access to network resources and cardholder data.
PCI DSS Quick Reference Guide description: Logging mechanisms and the ability to track user activities are critical for effective forensics and vulnerability management.  The presence of logs in all environments allows thorough tracking and analysis if something goes wrong.  Determining the cause of a compromise is very difficult without system activity logs.
Solution: The spirit of this requirement is to ensure appropriate systems generate logs, with implementation and monitoring of log aggregation and correlation systems.  The ability to monitor and log all user sessions and requests for access to sensitive information, such as cardholder data and Social Security numbers, is critical to any security environment.  F5 offers a suite of solutions that are session-based, not packet-based. With this full reverse proxy architecture, the BIG-IP platform has the ability to manage full user sessions, regardless of the transport mechanism or network, and match those user sessions to specific data actions, supplying log data and a full audit trail from the user to the data.  This allows F5 application security devices to ensure the confidentiality, integrity, and availability of all application data on the network.
All F5 products support remote logging, allowing logs to be pushed to secure networks and devices for archiving. In addition, the TMOS architecture can manage isolated, secure logging networks in conjunction with the application networks, using features such as mirrored ports, VLANs, and virtualized administrative access.  Protecting network resources and application data 24 hours a day, seven days a week, without affecting network performance, is a core function and the foundation of all F5 security products.

Requirement 11: Regularly test security systems and processes.
PCI DSS Quick Reference Guide description: Vulnerabilities are being discovered continually by malicious individuals and researchers, and being introduced by new software.  System components, processes, and custom software should be tested frequently to ensure security is maintained over time.  Testing of security controls is especially important for any environmental changes such as deploying new software or changing system configuration.
Solution: The spirit of this requirement is to ensure that the complying organization itself tests its security system and processes.  Since F5 does not offer a penetration testing service, this is one of just two PCI DSS requirements that F5 products cannot significantly address.
Next: Maintain an Information Security Policy
ps
Related:
Technorati Tags: F5, PCI DSS, virtualization, cloud computing, Pete Silva, security, cloud, credit card, compliance, web, internet,cybercrime, holiday shopping, identity theft,
Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, October 13, 2011

Our Identity Crisis

As as kid, my mom would constantly remind me that I was a Hawaiian Prince – a direct descendant of King Kamehameha’s grandparents and the Kekaulike (23rd Moi of Maui) line.  I was born in Hawaii but grew up on the East Coast so as a kid, I was embarrassed to be of Hawaiian Royalty since it was different from the typical ethnic groups of the New England states but that was/is Who I Am.  Of course as I got older I like being 254th in line to the Hawaiian throne…if it was still a sovereign kingdom.  Your identity is what makes you, You.  It is made up of things like, Your Family, Your history, What you say, What you know, Where you are, What you share, Who you know, Your preferences, Your choices, Your reputation, Your profession, Your biggest fears, Your greatest love and all the nuances that make each of us an individual. This information is available on the web, in profiles, contacts, email, data, documents, music, images, blogs, favorites…. Networks… you name it.  Some may confuse ‘image’ or ‘persona’ with identity.  Many celebrities have images to keep, or present a persona that they want their audience to latch to but many times, it is not their true identity and who they really are at their core. There are also certain pieces of our identity we’d also like to keep secret.  That’s the same information that the crooks want.

As we approach the holidays, this is an especially critical time to keep an eye on our information and those devices that contain our information, like our mobile devices.  You may have seen the recent commercials about making payments over your smartphone – the one where everyone pulls out their phones after dinner to pay their share and the guy with cash looks like the fool.  Huh?  I got real, crisp, green money in my hand, right from the ATM and nobody wants it.  The mobile payment infrastructure is still in the early stages but you can imagine the schemes already being hatched by those who would love to intercept those transactions. 

And speaking of crooks, did you see that 111 arrested in massive ID theft bust in New York?  Prosecutors are calling it the largest ID theft fraud case in US history.  For two years, law enforcement dug in for ‘Operation Swiper,’ which targeted a very sophisticated ID theft ring who recruited and paid restaurant workers, retail cashiers and even bank tellers to steal credit card numbers and quickly convert that data into cash.  They had everything – computers, skimmers, card readers, embossers, credit card blanks and shopping crews who went coast-to-coast buying high end merchandise while staying in 5-star hotels.  They made off with over $13 Million in less than a year and a half.

On a separate but positive note, a new Federal law was passed to protect foster children from identity theft.  This new law requires states to run credit checks on older foster children and work to resolve ID theft cases so when the child reaches adulthood, they have a clean slate.  Foster children are prime targets for and face greater risks of ID theft since their information passes through so many hands and agencies.  Most states also still use the foster child’s SSN to identify them, adding to the risk.  Many foster children enter adulthood with massive debt due to someone else leaving them with bad credit.  This law is intended to both protect against that and help those who have been victims.

And lastly, next week is the 4th annual National Protect Your Identity Week (PYIW).  Multiple Better Business Bureaus are joining several government agencies and other national advocacy organizations to offer educational workshops, free document shredding and computer recycling.  Javelin Strategy and Research noted that in 2010, 8.1 million adults were victims of identity theft resulting in the loss of $37 billion.  Plus, according to AllClear ID, children are 51 times more likely to have their identity stolen.

So as the year end festivities start heating up, don’t forget to keep an eye on you along with protecting and embracing your identity.

ps

Related:

Technorati Tags: F5, PCI DSS, virtualization, cloud computing, Pete Silva, security, cloud, credit card, compliance, web, internet, cybercrime, holiday shopping, identity theft,

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, January 19, 2011

The New Wallet: Is it Dumb to Carry a Smartphone?

When I was a teenager, I used to have one of those cool nylon surfer wallets with the Velcro close, you remember those don’t ya?  While pumping diesel (had a VW Rabbit) one day at an old Gulf station, I left the wallet on top of the car and drove off.  Realizing that my wallet was not snug in the sun visor when I got home, I retraced my path and found it - parts of it - scattered all over Route 1.  Luckily, I got most of my belongings back but had that sickened feeling of almost losing my most precious possession at the time, my fake I……um, my driver’s license.  I then got a leather wallet and shoved so many things in there I could have been mistaken for George Costanza, not to mention the hole that evolved right at the bottom point of my back pocket.  Not liking the bump on my butt, I eventually moved to ‘money-clip’ type holders, you know those money holder things you carry in your front pocket.  I felt ‘safer’ knowing it was in my front pocket and I only carried the essentials that I needed, rather than the reams of receipts I’d have in my wallet.  When I was younger, I’d use tie clips, metal binder clips, and other things until I got a nice Harley-Davidson one which holds credit cards and clips currency.  I’d still feel sick if I lost it however.

Not having a wallet, purse, money clip or other currency container at all, may eventually be our new reality.  You see, our smartphones are starting to carry all that digital information for us and according to a recent CNNMoney article, our smartphones are becoming one of our most dangerous possessions.  We can do banking, make payments, transfer money, use the phone for loyalty card swipes along with credit card transactions.  At the same time, mobile users more vulnerable to phishing attacks, some banking apps for Android, iPhone expose sensitive info, Android Trojan Emerges In U.S. Download Sites and how IPv6: Smartphones compromise users' privacy.  We knew it would eventually happen but the crooks are now adapting to the explosive mobile growth, the rise of mobile banking and our never ending connection to the internet.  Don’t get me wrong, like many of you, I love having email, contacts, calendar and entertainment at my fingertips along with the convenience of having all my stuff with me; but the chances of losing much more greatly increase since you have the equivalent, or even more, of all your credit cards, personal and private information and other sensitive stuff right on your smartphone.  Sure there are backup programs but how many of you actually backup your computer on a weekly basis?  How many have wipe or lock software installed to destroy everything on the smartphone if it is stolen?  How many have tracking software if it is lost?  How many have your actual home address in the GPS navigator so the offender can find where you live and visit while you are away?  How many have sensitive corporate information stored on the smartphone since you use it for both personal and business use?  Now I’m starting to spook myself. 

Many people will willingly trade some personal info for personal convenience.  You might never give a total stranger your home address and phone number but if they add, ‘in exchange, we’ll give you this branded card and you’ll get 10% off every purchase,’ more than likely, we’ll turn that personal info over.  If you understand that every purchase will be scanned, sent to a database and used for marketing or as the merchant describes, to ‘provide you with the best service and offerings,’ then you might accept that.  If you accept and understand the risks of doing mobile banking, transferring money, making payments and carrying around your entire life on your mobile device….and take actions to mitigate those risks, like using encryption, backups, wipe/locate software, antivirus, OS updates and other mobile security precautions along with practicing the same discretion as you would with your home computer (like not clicking links from strangers) then you should stay relatively safe.  Unless, of course, you leave that digital wallet on the top of your vehicle and drive off.

ps

Resources

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, banking, trojan, Pete Silva, security, business, education, technology, application delivery, ipad, cloud, context-aware, mobile, iPhone, web, internet, security, android, privacy, smartphone,