<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!--Web 2.0 Content Powered by MyST Blogsite® (http://blogsite.com)-->
<!--A service of MyST Technology Partners, Inc. (http://myst-technology.com)-->
<?xml-stylesheet href="http://blog.solidcore.com/public/styles/etc/object.xsl" type="text/xsl"?>

<?myst-baseUrl http://blog.solidcore.com/public/?>

<MySmartChannels Public="true" UserID="183000" dT="56" t0="1227345842233">
     <GetChannelItem_Result>
      <Item>
       <Resource>
        <ObjectID>201499</ObjectID>
        <ObjectClass>Resource</ObjectClass>
        <OwnerID ObjectClass="Domain" Title="[Weblog] IT Compliance">183005</OwnerID>
        <CreatedByID ObjectClass="User" Title="erinswanson">183122</CreatedByID>
        <ModifiedByID ObjectClass="User" Title="erinswanson">183122</ModifiedByID>
        <CreateTime Title="2008-04-09 23:09:11 EDT">1207796951142</CreateTime>
        <ModifyTime Title="2008-04-09 23:12:48 EDT">1207797168410</ModifyTime>
        <SecurityModel>Controlled</SecurityModel>
        <Name>PCI For Stores: Take the Short Cut or the Path to Real Protection?</Name>
        <Summary>Retailers focusing on PCI compliance must become more critical of point of sale systems</Summary>
        <Description>&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="verdana,arial,helvetica,sans-serif" color="#000000"&gt;There is a lot of buzz around Visa&amp;rsquo;s &lt;a href="http://www.pcisecuritystandards.org/tech/index.htm"&gt;&lt;strong&gt;&lt;u&gt;PCI Standard&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;these days. Companies are scrambling to be compliant, auditors are experiencing Y2K kind of consulting revenue growth, and technology vendors are claiming to solve all your problems.&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;Many companies find themselves at a crossroads: &lt;span style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/span&gt;Do I take the short cut or the path to real, ongoing protection of customer data. For example, most PCI Level 2 merchants can do a self assessment and say they are compliant. If they are later audited and some problems are found they get 6 months to fix those problems and get compliant again, before they face any fines. But what if there&amp;rsquo;s a data breach in the meantime?&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="verdana,arial,helvetica,sans-serif" color="#000000"&gt;Like anyone else, I am a consumer. I buy groceries Safeway and Albertsons. &lt;span style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/span&gt;I take my girls out to buy beads from small art stores and ice cream from Dairy Queen. Before walking into any of these shops I don&amp;rsquo;t think about whether the store is a level 1, level 2, level 3 merchant. &lt;span style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/span&gt;But, maybe I should.&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;We use credit cards in all those stores indiscriminately and even if they are all PCI compliant, the risk of our credit card data being stolen may be different orders of magnitude. &lt;span style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/span&gt;This whole mess reminds me of when I came to the &lt;country-region w:st="on" /&gt;US&lt;/country-region /&gt; as a student couple of decades back and in those days the &lt;placename w:st="on" /&gt;Stanford&lt;/placename /&gt; &lt;placename w:st="on" /&gt;International&lt;/placename /&gt; &lt;placename w:st="on" /&gt;Student&lt;/placename /&gt; &lt;placetype w:st="on" /&gt;Center&lt;/placetype /&gt; advised us not to use our credit cards in very small shops &lt;place w:st="on" /&gt;&lt;city w:st="on" /&gt;San Francisco&lt;/city /&gt;&lt;/place /&gt;. They advised us to use cash.&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="verdana,arial,helvetica,sans-serif" color="#000000"&gt;So, if you are CEO or CFO at a company with retail stores what do you do? If you pass a PCI DSS compliance assessment how safe and secure should you feel? Others companies in the industry like &lt;a href="http://www.baselinemag.com/c/a/Security/Hannaford-Bros-PCI-Compliance-Claims-Spurs-Questions/"&gt;&lt;strong&gt;&lt;u&gt;Hannaford&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; were PCI compliant but still had problems.&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;You have the stamp of compliance but what does that mean for your business?&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="verdana,arial,helvetica,sans-serif" color="#000000"&gt;There are no easy answers but the one thing I can guarantee is that all retailers have &amp;ldquo;STUFF RUNNING ON THEIR &lt;a href="http://www.solidcore.com/solutions/retail_pos.html"&gt;&lt;strong&gt;&lt;u&gt;POINT OF SALE&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; SYSTEMS&amp;rdquo; which should not be there. How would I know?&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;Solidcore technology ships on a huge number of POS systems and the software creates an inventory of all the software it finds on the POS and store back office systems. &lt;span style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/span&gt;The results are often shocking. And it doesn&amp;rsquo;t matter if your IT folks tell you we run anti-virus or we have a strict gold image; the reality is very different. This is not entirely the IT folks fault as stores are typically serviced by local people and employees have physical access to these machines 24x7.&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;font face="verdana,arial,helvetica,sans-serif" color="#000000"&gt;The &lt;a title="Solidcore solution for point of sale systems" href="http://www.solidcore.com/solutions/retail_pos.html" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Solidcore solution for POS&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; and Store Back Office Machines makes sure that only the right things run (runtime control) and can&amp;rsquo;t be tampered with (change control). When we designed this solution in 2003 it was not with PCI in mind, it was to solve the problems that customers were having with keeping these machines operational given that they are remotely dispersed and the fact that Anti-Virus on these machines was practically useless as the signatures were almost never updated.&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="FONT-SIZE: 11pt; LINE-HEIGHT: 115%; FONT-FAMILY: "&gt;&lt;font face="verdana,arial,helvetica,sans-serif" color="#000000" size="2"&gt;Our PCI solution for data center servers has now emerged as the market leader with the leading QSA&amp;rsquo;s blessing it and recommending it to their customers.&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;The combination of these two solutions is becoming a standard for store-based companies that are avoiding shortcuts and pursuing the path towards sustainable protection of customer data.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="MARGIN: 0in 0in 10pt"&gt;&lt;span style="FONT-SIZE: 11pt; LINE-HEIGHT: 115%; FONT-FAMILY: "&gt;&lt;font color="#000000" size="2"&gt;&lt;strong&gt;Rosen Sharma&lt;/strong&gt;&lt;br /&gt;President &amp;amp; CEO&lt;br /&gt;&lt;a title="Rosen Sharma email address" href="mailto:rosen@solidcore.com" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;rosen@solidcore.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;</Description>
        <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
        <ContentType>application/xml</ContentType>
        <ContentDocument>
         <ItemProperties>
               <CommonProperties>
                <Hidden>false</Hidden>

                <Keywords>
                 <Keyword>Hannaford</Keyword>

                 <Keyword>PCI compliance</Keyword>

                 <Keyword>PCI DSS</Keyword>

                 <Keyword>point of sale</Keyword>

       </Keywords>

                <Links>
                 <Link>
                  <Title>PCI Data Security Standard (PCI DSS)</Title>

                  <Synopsis>PCI Security Standards Council Web site where a copy of the PCI DSS spec can be accessed</Synopsis>

                  <URL>http://www.pcisecuritystandards.org/tech/index.htm</URL>

        </Link>

                 <Link>
                  <Title>Solidcore S3 Control Embedded for point of sale systems</Title>

                  <Synopsis>Solidcore web site with information about sustaining PCI compliance on point of sale systems</Synopsis>

                  <URL>http://www.solidcore.com/solutions/retail_pos.html</URL>

        </Link>

                 <Link>
                  <Title>Hannaford PCI Compliance Spurs Questions</Title>

                  <Synopsis>Baseline magazine article about Hannaford data breach and PCI compliance</Synopsis>

                  <URL>http://www.baselinemag.com/c/a/Security/Hannaford-Bros-PCI-Compliance-Claims-Spurs-Questions/</URL>

        </Link>

       </Links>

      </CommonProperties>

               <RemoteInfo>
                <UserAgent>Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Comcast Install 1.0; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727)</UserAgent>

                <RemoteHost>127.0.0.1</RemoteHost>

                <RemoteAddr>127.0.0.1</RemoteAddr>

                <RemoteUser>erinswanson</RemoteUser>

                <ForwardedFor>67.187.228.183</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
        </ContentDocument>
       </Resource>
       <Shares/>
       <Subjects/>
       <UserPermissions>
        <CanDelete>false</CanDelete>
        <CanDiscover>true</CanDiscover>
        <CanEdit>false</CanEdit>
        <CanEditPermissions>false</CanEditPermissions>
        <CanRead>true</CanRead>
       </UserPermissions>
       <CommentInfo>
        <CommentChannelRef AllowAnonymous="true" Inherited="true">
         <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">183020</ChannelID>
         <UserPermissions>
          <CanCreateChannelItem>false</CanCreateChannelItem>
          <CanDelete>false</CanDelete>
          <CanDiscover>true</CanDiscover>
          <CanEdit>false</CanEdit>
          <CanEditPermissions>false</CanEditPermissions>
          <CanPublish>false</CanPublish>
          <CanRead>true</CanRead>
         </UserPermissions>
        </CommentChannelRef>
        <Comments/>
       </CommentInfo>
       <Views>
        <SourceID ObjectClass="Channel" Title="[Weblog] IT Compliance">183005</SourceID>

               <View>
                <Name>blog</Name>

                <Model>blogsite/SolidCore/web</Model>

                <Style/>

                <Scheme/>

       </View>

      </Views>
        <Views>
         <SourceID ObjectClass="Channel" Shared="true" Title="[Public] What's New">183014</SourceID>

                <View>
                 <Name>blog</Name>

                 <Model>blogsite/SolidCore/whatsnew</Model>

                 <Style/>

                 <Scheme/>

       </View>

      </Views>
        </Item>
       </GetChannelItem_Result>
      </MySmartChannels>
