The
Payment Credit Card Industry Data Security Standard (PCI DSS) requires PCI
members, merchants, and service providers that store, process, or transmit
cardholder data to apply security requirements to all “system components” -
defined as any network component, server, or application included in, or
connected to, the cardholder data environment.
PCI DSS Requirement 1 requires you to install and maintain a firewall
configuration and to periodically review firewall policies. Requirement 3
requires encryption of cardholder data or to install monitoring as a
compensating control. PCI DSS Most importantly, requirement 10 mandates to
“track and monitor all access to network resources and cardholder data,”
including a requirement to retain log data for one year, with a minimum of 3
months available online, and to review log data “daily”.
LogLogic Benefits
The benefits of LogLogic’s solutions for PCI compliance:
The LogLogic Open Log Management platform in conjunction with the LogLogic Compliance Suite: PCI Edition and LogLogic Compliance Manager add-on products provide the foundation for log collection, archival, and review (Requirement 10).
LogLogic Security Event Manager speeds up the process of daily log review by prioritizing incidents.
LogLogic Database Security Manager provides monitoring as a compensating control for database encryption (Requirement 3).
|
|
|