180 likes | 385 Views
Cardholder Data Discovery Andrew Henwood. May 2012. Typical College / University / Council Network. Unprotected Cardholder Data. Where is it?. Database Servers. Back Office. Finance. Library. Onsite Retail. Commercial Services. Course and Accommodation Fees. Service Payments.
E N D
Cardholder Data Discovery • Andrew Henwood May 2012
Typical College / University / Council Network • Unprotected Cardholder Data. Where is it? Database Servers Back Office Finance Library Onsite Retail Commercial Services Course and Accommodation Fees Service Payments
Where is the Cardholder Data to be found? • Unprotected Cardholder Data. Where is it? • Where is Unprotected Cardholder Data stored? • Files/locations used in daily use • Internet browser logs, xml files, binary files (database dumps), within compressed files (ZIP etc), backups, file shares etc. • Very difficult to find - deleted files, unallocated files, slack space.
Where is the Cardholder Data to be found? • Unprotected Cardholder Data. Where is it? Database Servers Back Office Finance Library Commercial Services Onsite Retail Course and Accommodation Fees Service Payments
Cardholder Data Environment • Entire Organisation in Scope of Compliance Database Servers Back Office Finance Library Commercial Services Onsite Retail Course and Accommodation Fees Service Payments
PCI DSS Compliance - Reality • PCI DSS & being secure is HARD (if not approached sensibly) • Simplify the Cardholder Data Environment • Scope Reduction is CRUCIAL • Focus your compliance activity, reduce efforts, reduce long term costs
CHD Discovery Tools Use a Cardholder Data Discovery Tool do the heavy lifting and validation of PCI data & flows
From PCI DSS • Standards - PCI DSS v2.0 • Page 10: • “The first step of a PCI DSS assessment is to accurately determine the scope of the review. At least annually and prior to the annual assessment, the assessed entity should confirm the accuracy of their PCI DSS scope by identifying all locations and flows of cardholder data and ensuring they are included in the PCI DSS scope. “
Cardholder Data Discovery • Cardholder Data Discovery - DEFINE • DEFINE and Identify Cardholder Data • Unaware of unknowns • Threat of Compromise & fraud is significant. • Identify data leaks in: • Badly configured payment software • Broken/changed business processes • Insecure payment software storing data it should not Persistent - Proactive - Protection
Cardholder Data Discovery • Cardholder Data Discovery – PROTECT • PROTECT (or eradicate) identified CHD • Reduce risk of compromise. • Provide user time to evaluate risk tobusiness processes. • Protect – Encrypt / Tokenise / Hash etc. • * These systems are still in scope for PCI DSS. Persistent - Proactive - Protection
Cardholder Data Discovery • Cardholder Data Discovery – ASSURE Persistent • ASSURE • Cardholder data not appearingwhere it should not • Applications / systems performingas they should Monitoring Persistent Monitoring = Ongoing Risk Management Persistent - Proactive - Protection
Cardholder Data Environment • Entire Organisation in Scope of Compliance Database Servers Back Office Finance Library Commercial Services Onsite Retail Course and Accommodation Fees Service Payments
Post Data Discovery and Remediation • New Cardholder Data Environment Database Servers Back Office Finance Library Commercial Services Onsite Retail Course and Accommodation Fees Service Payments
Summary • Summarising Cardholder Data Discovery • After implementing an ongoing Cardholder Data Discovery solution via: • Opensourceor Commercial / DLP based or PCI specific • Unknowns become known • Knowns are confirmed Persistent - Proactive - Protection
Summary • Summarising Cardholder Data Discovery • Facilitates: • Consolidation • Account data sterile environments • Restricted in scope environment • Easier and more manageable PCI compliance Persistent - Proactive - Protection
Post Data Discovery and Remediation • New Cardholder Data Environment & Sterile Env. ✓ ✓ ✓ Database Servers Back Office Finance Library ✓ ✓ ✓ ✓ Support Canteen Contact Centre Significant risk reduction for the College / University / Council, their bank and the card schemes. Fees Office
Stay Safe & Risk Aware Andrew Henwood - Director ahenwood@foregenix.com Foregenix Wesley House Bull Hill Leatherhead Surrey KT22 7AH United Kingdom Tel: 0845 309 6232 Web: www.foregenix.com