Information Security in the Real World. Confidentiality, Availability, Integrity, Practicality.

Wednesday, 29 September 2010

InfoReck blog, great minds etc...

I'm delighted to have found this blog, written by Robb Reck, because we share a common belief that Compliance does not equal Security, and worse, that Compliance efforts can make you less secure. This post summarises his position and is essential reading for Infosec professionals and CISOs.

InfoReck» Blog Archive » Security Leads to Compliance

Amusingly we both wrote mid-year on the subject of compliance regimes hindering security efforts. I swear I had not read Robb's column before writing mine. Enjoy.

Thursday, 26 August 2010

55% care about PCIDSS

41 of 74 respondents to a poll on Anton Chuvakin's Security Warrior blog put PCIDSS top of their list of concerns. Alright it was a leading question and unscientific, but I'm pleased to see such interest anyway. Maybe this reflects the looming Level 1 deadline for full compliance and regular audits. Maybe it's the fact that the PCI are now collecting fines at an alarming rate. Whatever, up to now we've seen a very slow uptake for a mandatory standard with tough penalties and this is good news. I guess the standard's arrival during a recession has caused a bit of a "wait and see" attitude in the boardroom. But this is risky. PCIDSS is not just another regulation. If you're not compliant, you're at risk of serious fraud, data loss and reputational damage.

You shouldn't comply with PCIDSS to get a tick in the box and a certificate for the lobby. You should do it to preserve your business.

Monday, 12 July 2010

The case for PCI-DSS and Ripped Abs.

I just caught up with this post (which I had squirrelled away to read later with my Google Bookmarks toolbar and just rediscovered). Some nice work here by Bob Tarzey in summing up the main requirements of PCIDSS, the advantages of getting ready and the basic implications of breach. PCI might be the kick that some firms need to re-assess security: the regularity of the audits might just make the difference. It's easy to put off spending money to counter a threat with an Annual Rate of Occurence (ARO) calculated as 0.1 (i.e. every 10 years) - human nature and available time dictate that the auditor landing on your desk every quarter wins hands down.

Check out too the comments on this post, also on silicon.com. The griping about variable approaches from the assessors is to be expected with any new standard, I think this will settle down in time. On the particular issue about voice recordings of CCV2 numbers, I would hope encryption and strong access control over the voice recordings would suffice but would welcome clarification from the PCI on this or any views from QSAs reading this.

In any case, as I have blogged before, don't make compliance with the standard your goal, make good security your goal and you will achieve compliance as a direct consequence. Or as Papa_K puts it rather nicely on that comment thread: "If you prepare for compliance audits like you prepare for a punch in the stomach to prove your abs are strong then you'll not be prepared for the sucker punch."

Thursday, 8 July 2010

New IBM developerWorks blog: zSecurity

I've opened a new blog on the excellent IBM developerWorks platform called zSecurity. My readers who are not interested in System z issues will be delighted, as I will keep System z-specific content to that blog (and it might spill out into wikis later but that's another story) and stick to wider InfoSec stuff here.

zSecurity is here, please take a look and subscribe to the feed if you're interested in RACF, zSecure, Tivoli Security Software for z/OS and Linux on z and Enterprise Security with a Mainframe.

If you're already following me on Twitter as @alanjharrison then you will be happy to know that I will tweet my dW blog updates just as I tweet these Blogger ones, so nothing else to do there.

Thanks for reading, InfoSec people stay here, System z people: see you on dW! Thanks.