<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!--Web 2.0 Content Powered by MyST Blogsite® (http://blogsite.com)-->
<!--A service of MyST Technology Partners, Inc. (http://myst-technology.com)-->
<?xml-stylesheet href="http://blog.solidcore.com/public/styles/etc/object.xsl" type="text/xsl"?>

<?myst-baseUrl http://blog.solidcore.com/public/?>

<MySmartChannels Public="true" UserID="183000" dT="28" t0="1212395368534">
     <GetChannelItem_Result>
      <Item>
       <Resource>
        <ObjectID>203395</ObjectID>
        <ObjectClass>Resource</ObjectClass>
        <OwnerID ObjectClass="Domain" Title="[Weblog] IT Compliance">183005</OwnerID>
        <CreatedByID ObjectClass="User" Title="erinswanson">183122</CreatedByID>
        <ModifiedByID ObjectClass="User" Title="erinswanson">183122</ModifiedByID>
        <CreateTime Title="2008-05-09 00:48:17 EDT">1210308497304</CreateTime>
        <ModifyTime Title="2008-05-09 00:43:54 EDT">1210308234108</ModifyTime>
        <SecurityModel>Controlled</SecurityModel>
        <Name>Retailers find the solution to PCI Compliance on POS Devices</Name>
        <Summary>Solidcore provides most cost effective solution for meeting critical audit trail and file integrity monitoring PCI requirements</Summary>
        <Description>&lt;p&gt;Our &lt;strong&gt;&lt;a href="http://www.solidcore.com/products/pci.html"&gt;&lt;u&gt;PCI products&lt;/u&gt;&lt;/a&gt;&lt;/strong&gt; launched earlier this year have been a tremendous success. The traction and pull we are seeing from the market is phenomenal.&amp;nbsp; We closed two deals with really large retailers who are interested in using our PCI products on their Point of Sale (POS) systems.&amp;nbsp;Now, POS itself is an overloaded term. What we generally know as &lt;a title="SearchSecurity.com article on targeted POS systems" href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1311702,00.html" target="_blank"&gt;&lt;u&gt;&lt;strong&gt;POS devices&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt; are actually called PC-based cash registers (that one you see at the counter).&amp;nbsp;Retailers call even the back office server a POS. These are Windows 2003 servers with lots of disk space and they run database servers on these machines.&lt;/p&gt;&lt;p&gt;One of the aforementioned retailers has over 300 retail locations across the west coast. Each store has at least two cash&amp;nbsp;registers and all the cash registers are connected to a back-office POS system running SQL Server 2005.&amp;nbsp;This retailer has started using solidcore for creating an audit trail of all File and database changes on these critical back office systems.&amp;nbsp;Our database product has the ability to track:&lt;/p&gt;&lt;p&gt;1. Schema changes&lt;br /&gt;2. Data changes&lt;br /&gt;3. Activities like Logon/Logoff, User/Role creations, privilege grants, etc, and&lt;br /&gt;4. Accesses (SELECT)&lt;/p&gt;&lt;p&gt;While this is great, tracking all such changes would result in a very low signal-to-noise ratio.&amp;nbsp;We solve this problem using our filter profiles which allows users to specify various conditions like: &amp;quot;Track changes made to the cardholder table ONLY when they are made by applications other than the payment processing application,&amp;quot; or &amp;quot;create an audit trail of all SELECT statements that are issued by accounts (users) other than the ones used by the application.&amp;quot;&amp;nbsp;Out of the box reports also help the DBAs get a summary of all suspicious and unauthorized activity across all stores on a daily, weekly, or custom interval.&amp;nbsp;I was talking to one of the leading PCI industry analysts today who was very impressed at Solidcore's capability to collect and maintain an audit-trail of all in-scope PCI servers, databases and network devices.&amp;nbsp;This analyst mentioned that Section 10 was the main play of &lt;a title="Network World article about SIM market" href="http://www.networkworld.com/newsletters/nsm/2007/0827nsm2.html" target="_blank"&gt;&lt;u&gt;&lt;strong&gt;Security Information Management&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt; (SIM) vendors like&amp;nbsp;Arcsight and Loglogic.&amp;nbsp;So, if you are in the market looking for a SIM product for PCI Section 10, you owe it to yourself to put Solidcore on your list.&amp;nbsp; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Rajesh Rajamani&lt;/strong&gt;&lt;br /&gt;&lt;a title="Rajesh Rajamani email" href="mailto:raj@solidcore.com" target="_blank"&gt;&lt;u&gt;&lt;strong&gt;raj@solidcore.com&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;</Description>
        <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
        <ContentType>application/xml</ContentType>
        <ContentDocument>
         <ItemProperties>
               <CommonProperties>
                <Hidden>false</Hidden>

                <Keywords>
                 <Keyword>compliance</Keyword>

                 <Keyword>PCI</Keyword>

                 <Keyword>PCI DSS</Keyword>

                 <Keyword>point of sale</Keyword>

                 <Keyword>POS</Keyword>

       </Keywords>

                <Links>
                 <Link>
                  <Title>Solidcore PCI Products</Title>

                  <Synopsis>Solidcore PCI products web page</Synopsis>

                  <URL>http://www.solidcore.com/products/pci.html</URL>

        </Link>

                 <Link>
                  <Title>Credit card thieves target flawed POS systems</Title>

                  <Synopsis>SearchSecurity.com article about cardholder theft and POS devices</Synopsis>

                  <URL>http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1311702,00.html</URL>

        </Link>

                 <Link>
                  <Title>SIM market</Title>

                  <Synopsis>Network World article about the security information management market</Synopsis>

                  <URL>http://www.networkworld.com/newsletters/nsm/2007/0827nsm2.html</URL>

        </Link>

       </Links>

      </CommonProperties>

               <RemoteInfo>
                <UserAgent>Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)</UserAgent>

                <RemoteHost>127.0.0.1</RemoteHost>

                <RemoteAddr>127.0.0.1</RemoteAddr>

                <RemoteUser>erinswanson</RemoteUser>

                <ForwardedFor>67.187.228.183</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
        </ContentDocument>
       </Resource>
       <Shares/>
       <Subjects/>
       <UserPermissions>
        <CanDelete>false</CanDelete>
        <CanDiscover>true</CanDiscover>
        <CanEdit>false</CanEdit>
        <CanEditPermissions>false</CanEditPermissions>
        <CanRead>true</CanRead>
       </UserPermissions>
       <CommentInfo>
        <CommentChannelRef AllowAnonymous="true" Inherited="true">
         <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">183020</ChannelID>
         <UserPermissions>
          <CanCreateChannelItem>false</CanCreateChannelItem>
          <CanDelete>false</CanDelete>
          <CanDiscover>true</CanDiscover>
          <CanEdit>false</CanEdit>
          <CanEditPermissions>false</CanEditPermissions>
          <CanPublish>false</CanPublish>
          <CanRead>true</CanRead>
         </UserPermissions>
        </CommentChannelRef>
        <Comments/>
       </CommentInfo>
       <Views>
        <SourceID ObjectClass="Channel" Title="[Weblog] IT Compliance">183005</SourceID>

               <View>
                <Name>blog</Name>

                <Model>blogsite/SolidCore/web</Model>

                <Style/>

                <Scheme/>

       </View>

      </Views>
        <Views>
         <SourceID ObjectClass="Channel" Shared="true" Title="[Public] What's New">183014</SourceID>

                <View>
                 <Name>blog</Name>

                 <Model>blogsite/SolidCore/whatsnew</Model>

                 <Style/>

                 <Scheme/>

       </View>

      </Views>
        </Item>
       </GetChannelItem_Result>
      </MySmartChannels>
