Harden Server Configuration to remove Vulnerabilities
"PCI DSS Version 2.0 Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters"
From the moment a server is powered up it becomes vulnerable to attack. Assuming that leaving your key application servers turned off is not an option it will be necessary to implement security measures advocated by the PCI DSS.
PCI Requirement 2 calls for configuration hardening of servers, EPoS PC's and network devices. The headlines of the requirement call for removal of default usernames and passwords, and a need to stop any unnecessary services. However, beyond these initial measures there are a vast number of additional configuration setting changes recommended by 'best practice' authorities (such as SANS Institute, CIS and NIST) all of which help to mitigate security threats. If you haven't already adopted a hardened configuration standard then any of these organizations can assist, although a good configuration auditing and config change tracking system will typically be pre-packed with a hardening checklist you can adopt. This type of system will automate not just the initial hardening assessment but will also do so on a continuous automatic basis so you can be alerted when any configuration drift occurs.
As with most elements of the PCI DSS Requirements, there are a number of checks and balances to provide evidence that adequate hardening measures have been applied. In common with the overall ethos of the PCI DSS, there is always a high degree of overlap to guarantee comprehensive coverage.
Similarly, event log management and file integrity monitoring measures will serve to provide additional checks to verify security measures have not been changed or compromised at all times.
Active Testing of PCI DSS Security Measures - Pen Testing and Vulnerability Scanning
PCI Requirement 11 covers Penetration Testing and Vulnerability Scanning - we'll discuss these in turn.
Friday, December 30, 2011
PCI Compliance Server Hardening Doesn't Have to Be Hard
Subscribe to:
Post Comments (Atom)
-
▼
2011
(1190)
-
▼
December
(85)
- Acer 4741G Upgrade Acer 5750G Notebook Review
- Online Microsoft Office Training Courses And Exami...
- What Are Virtual Private Servers and How Do They Work
- The .net training in Ahmedabad is an added advanta...
- Creative Studio France- Your Key to Success
- PCI Compliance Server Hardening Doesn't Have ...
- Top Qualities To Look For In An IT Support Team
- Android Development – The Fastest Growing Demand...
- Benefits of virtualization solutions
- Repair Corrupt Excel 2000 Against Corruption
- How What You Do on Twitter Could Negatively Affect...
- SharePoint 2010 as a facing application delivery p...
- How a Windows Dedicated Server Allows you to Makes...
- Two types of programming languages
- X Code Developer Tools For iPhone Development
- What is an iPad and What are The Features of an iPad
- Firefox Hijacked by Mediashifting.com redirect vir...
- Exactly what Document Scanning Services Are Able T...
- How to Play AVI in QuickTime on Mac Lion, Snow Leo...
- Vitality of a Network Operating System to the Busi...
- Information Data Protection save Your Business
- 3 People That Will Thrive With Microsoft Certifica...
- Revolutionizing E-learning Solutions
- Lexmark Printer Troubleshooting: Learn How to Do-i...
- The wizards of scripting on web pages
- Ruby on Rails Development – A Landmark in Ruby P...
- Android Development – At a Glance
- SysTools SQL Password Recovery Tool One Of The Apt...
- Technology Continues to Change the World of Art & ...
- Getting your Gmail messages in Microsoft Outlook
- Recover your deleted data using Mac platform
- Advantages of ASP.Net Development and Importance o...
- Transfer PST to Notes NSF Perfectly with Proper Pl...
- Why Compare Broadband Deals Yourself?
- Computer File encryption in USB Stick
- IT Support Birmingham: Maintain Computer Network a...
- IPhone App Development – Need of the Day
- Magento Website Development Company India
- Considerations When Buying Cheap Laptops
- Best iPhone Apps Singapore
- The android training in Ahmedabad is your future
- Revolutionary Software Solution for Various Logist...
- Hire PHP Developer To Give Your Business Higher Gl...
- Hire Mambo Developer for Easy CMS
- How to disable User Account Control in Windows Vis...
- 11-Inch Dell Inspiron M101z Notebook Review Huge C...
- Php Clone web scripts
- New D-Link DIR-857 Wireless N900 Router Vs Linksys...
- Get authentic java training in Ahmedabad
- At Australia Web Designers Small Businesses Finds ...
- Can Google docs use at workplace be made secured ?
- Understanding Unmetered Server And Dedicated Seedb...
- The real deal about bingo sites with a free sign u...
- What is a Terminal Emulator, and how can I tell if...
- Rival Steel DELL Latitude E6410 Notebook Review
- The New I5 Processor Dell Inspiron 1464 Notebook R...
- Resolving Network Operating System Problems Throug...
- Easy Techniques To Alter Wmv Into Mov On Windows A...
- EML to PST Converter Launched for Swiftly Moving E...
- How to shut out hackers by using disk quotas?
- Removal of Trojan Viruses Software
- Easy Self-Help Guide To Alter Wmv To Mov On Window...
- Justice Points with Buying Cheap WoW Gold
- WoW Gets Real Money Trading
- Hassle free administration with government service...
- Dynamics GP versus SAP Business One or which Popul...
- Why Comprobantes Fiscales Digitales Are Better Tha...
- Giving Away Free Software Boosts the Market of Bus...
- Enjoy the Use of iPod with Windows Media Player
- The Benefits of 3D Rendering
- Samsung Laptops Find a Ground in Indian PC Market
- How to deal with sound problems in Toshiba Mini No...
- Key Benefits of Mobile Computing Technology
- Online Software Training: Effectively Improving Em...
- Understanding SharePoint Development Security
- They Can Create Excellent Results through Playing ...
- League of Legends detailed review and advices for ...
- Remove Essential Cleaner - How To Remove Essential...
- You Have to Decide Whether You Want to Maintain Wo...
- Choose Free Outlook Email to Export Lotus Notes Ve...
- The evergrowing phase of software company india
- Speed up your Windows XP or Windows 7 PC
- Internet TV on PC Software Reviews : The Benefits ...
- Antispam Software: A Shorter Introduction on What ...
- The Benefits to Network Performance Management
-
▼
December
(85)
No comments:
Post a Comment