When checking system access, make sure you look at all the different items that affect the user’s access. For example, the user might need one or more of the following:
- Application ID
- Application role or group
- Membership in an local server group, Active Directory (AD) group, or UNIX Group
- Access to the application’s share and/or folder on the server
- Database ID
- Database role, including access permissions (read/write)
- Other permission (from a home-grown application code or enterprise identify management system)
Continue reading →
Filed under Audit, How to..., Security, Technology
Tagged as access, active, AD, admin, application, Audit, batch, confidential, contractor, data, database, directory, employee, file, financial, folder, format, generic, group, hipaa, HR, ID, LDAP, log, membership, new, non-personal, OS, PCI, permission, personal, role, script, setup, share, sox, system, Unix, user
Filed under Audit, Security
Tagged as active directory, Audit, auditor, checklist, configuration, openDNS, PCI, sans, session controls, settings, ssh, VMWare, web application, web filter, without
Dan Goodin reports that RBS WorldPay and Heartland Payment Systems are no longer considered Payment Card Industry (PCI) compliant by VISA. Both credit card payment processors had recent breaches.
Gartner analyst Avivah Litan, who tracks payment card security, said, “Retailers and other companies are not allowed to do business with processors that are not PCI compliant so this puts all of Heartland’s customers and all of RBS’s customers out of compliance,” she told The Register. “It’s nebulous, as most of PCI enforcement is.”
If you’re PCI compliant, it’s a good time to remind management that compliance isn’t the end of the road. Being compliant does not mean your security is ironclad; it means that you have taken some of the first steps forward. Don’t rest.
More on the PCI Data Security Standard.
Filed under Security
Tagged as breach, compliance, compliant, enforcement, Gartner, hacker, Heartland, PCI, RBW WorldPay, Security, VISA