<?xml version="1.0" encoding="UTF-8" standalone="yes"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xml:base="http://blog.solidcore.com/public/" version="2.0"><!--

MyST Blogsite® RSS Web Feed | Powered by MySmartChannels™ Weblog Application Server

MyST Blogsite and MySmartChannels are services of MyST Technology Partners, Inc.
For more information, including standard terms of service, see:
http://myst-technology.com and http://blogsite.com

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Customize this feed by adding any of the following URL parameters:

  description=none|summary|full (default=full)
  channelDescription=none|summary|full (default=value of 'description' parameter)
  itemDescription=none|summary|full (default=value of 'description' parameter)
  enhanced=true|false (default=false)
  limit=n (default=15)
  score=none|emoticon|simple|stars|text (default=text)
  smartPoints=true|false (default=true)
  sortKey=CreateTime|ModifyTime|Name|...any MyST-ML child element... (default=CreateTime)
  sortOrder=ascending|descending (default=descending)
--><channel>
     <title>IT Compliance | Solidcore Blog</title><link>http://blog.solidcore.com/public/blog/183005</link><description>IT Compliance and Management
        &lt;p&gt;This weblog provides information on how IT companies provide continuous compliance across the IT datacenter for PCI compliance and Sox compliance verification.  By using software that closes the change control gap between IT service management and the IT infrastructure, you can significantly reduce the cost of compliance for both PCI and SOX.&lt;/p&gt;
		&lt;p&gt;Subjects covered include:  PCI compliance, payment card industry compliance, payment card industry data security standard, PCI DSS, PCI compliance verification, SOX compliance, SOX compliance verification, Sarbanes-Oxley compliance, Sarbanes-Oxley 404 compliance, file integrity monitoring, and how change control software provides overall continuous compliance across the IT datacenter.&lt;/p&gt;
    </description><atom:link type="application/rss+xml" rel="self" href="http://blog.solidcore.com/public/rss/183005?"/><language>en-us</language><copyright>Copyright (C) 2008 Solidcore--All Rights Reserved -- This channel is part of the Solidcore Blog blogsite--Powered by MyST Blogsite®.</copyright><pubDate>Thu, 13 Sep 2007 23:45:17 -0400</pubDate><lastBuildDate>Mon, 18 Aug 2008 23:54:15 -0400</lastBuildDate><generator>MySmartChannels V3.0 (MyST Web Service Platform V5.00.0725)</generator><image><url>http://blog.solidcore.com/styles/blogsite/SolidCore/images/rss.jpg</url><height>31</height><width>88</width><link>http://blog.solidcore.com/public/blog/183005</link><title>IT Compliance | Solidcore Blog</title><description>Solidcore: Change Management and Change Control Solutions</description></image>
       <category>IT Compliance</category><category>PCI compliance</category><category>IT management</category><category>SOX Compliance</category><category>IT Service Management</category><category>Change Control</category><category>IT infrastructure</category><category>IT change control</category><category>IT Data Center</category><category>Change Management</category>
       
       
      
    
     <item><title>Easing PCI Compliance and Security on Retail POS Systems</title><link>http://blog.solidcore.com/public/item/211391</link><description>Runtime Control solution more optimized for POS systems than whitelisting, intrustion prevention and anti-virus&lt;p&gt;&lt;img style="WIDTH: 80px; HEIGHT: 91px" height="91" alt="Retail POS security and compliance" hspace="0" src="http://www.solidcore.com/images/pos_image.jpg" width="80" align="baseline" border="0" /&gt;To ease the pain of &lt;a href="http://www.pcisecuritystandards.org/"&gt;&lt;strong&gt;&lt;u&gt;PCI compliance&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; and security on &lt;a href="http://www.solidcore.com/retail"&gt;&lt;u&gt;&lt;strong&gt;retail&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt; point of service (POS) systems, Solidcore today released POS Check and Control. The product is based on Solidcore&amp;rsquo;s &amp;ldquo;runtime control&amp;rdquo; technology that solves the rigors of POS security, malware protection and Payment Card Industry Data Security Standard (PCI DSS) compliance with minimal system and operational overhead.&lt;/p&gt;&lt;p&gt;Solidcore is already an established leader for securing &lt;a href="http://en.wikipedia.org/wiki/Point_of_sale"&gt;&lt;u&gt;&lt;strong&gt;POS&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt; systems and is deployed on nearly 100,000 POS systems worldwide.&amp;nbsp; Unlike application whitelisting, host intrusion prevention systems (HIPS) and anti-virus, Solidcore provides runtime control capabilities that deliver comprehensive security with low overhead.&amp;nbsp; Runtime control ensures only pre-authorized software and code can run on POS systems while securely allowing software updates from trusted sources, such as those generated by retail coupon engines.&amp;nbsp; Solidcore&amp;rsquo;s runtime control also prevents disk tampering, and provides advanced memory protection to authorized software to defend against buffer overflow vulnerability attacks and zero-day exploits.&lt;/p&gt;&lt;p&gt;According to Gartner's John Pescatore, &amp;ldquo;Financially motivated, targeted attacks are definitely focusing on POS systems. As&amp;nbsp;with all business-critical systems, merchants must ensure they start with secure POS&amp;nbsp;software and configurations,&amp;nbsp;and then implement and enforce&amp;nbsp;strong change control and vulnerability management processes to make sure that only authorized&amp;nbsp;updates are allowed.&amp;rdquo;&lt;/p&gt;&lt;p&gt;Tony Thompson&lt;br /&gt;&lt;a href="mailto:tthompson@solidcore.com"&gt;tthompson@solidcore.com&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.pcisecuritystandards.org/" target=%quot;_blank%quot;&gt;PCI Compliance&lt;/a&gt;&lt;br/&gt;Payment Card Industry Standards Council&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.solidcore.com/retail" target=%quot;_blank%quot;&gt;Solving the retail security and compliance challenges&lt;/a&gt;&lt;br/&gt;Solidcore retail solution web page&lt;/li&gt;&lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/Point_of_sale" target=%quot;_blank%quot;&gt;POS Systems&lt;/a&gt;&lt;br/&gt;Wikipedia point of sale page&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.solidcore.com/public/item/211391</guid><pubDate>Mon, 18 Aug 2008 23:12:32 -0400</pubDate>
        <category>PCI compliance</category><category>POS</category><category>retail</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Credit Card Theft Blame Game</title><link>http://blog.solidcore.com/public/item/208877</link><description>Cardtronics owned 7-Eleven ATMs uncover a new blame game for who is responsible for credit card thefts&lt;p&gt;&lt;img style="WIDTH: 161px; HEIGHT: 186px" height="186" alt="Solidcore is locking down more than 60,000 ATMs worldwide and growing" hspace="0" src="http://www.freewebs.com/ballbustersrus/atm.jpg" width="161" align="baseline" border="0" /&gt;The &lt;a href="http://blog.wired.com/27bstroke6/2008/07/atm-owner-cardt.html"&gt;&lt;strong&gt;&lt;u&gt;7-Eleven/Citibank ATM breach&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; points out the complexity of field deployed self-service kiosks and ATMS. They may be convenient but transactions take a very different path versus a bank-based ATM on the outside of their branch, securely connected on the corporate network.&lt;/p&gt;&lt;p&gt;Using networking lingo, how many &amp;quot;hops&amp;quot; does it take to get a single transaction processed from the remote ATM?&lt;/p&gt;&lt;p&gt;My hypothesis is the following steps:&lt;/p&gt;&lt;p&gt;1- Local processing at the ATM itself &lt;/p&gt;&lt;p&gt;2- Network transport provided by regional and local players to give connectivity&lt;/p&gt;&lt;p&gt;3- Transaction processing of several remote ATMs to aggregate back-end servers within 7-Eleven or Cardtronics &amp;quot;vcom&amp;quot; &lt;/p&gt;&lt;p&gt;4- Connectivity to the third party payment acquirer contracted by 7-Eleven or Cardtronics to provide settlement services&lt;/p&gt;&lt;p&gt;5- Payment Acquirer connectivity and settlement services with Citibank&lt;/p&gt;&lt;p&gt;This is a good example of semi-trusted cooperative networking at its best.&amp;nbsp;The Payment Card Industry Data Security Standard (&lt;a title="Web page for the PCI DSS" href="http://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;PCI DSS&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;)&amp;nbsp;expects that compliance is upheld with all those that touch a payment network. However compliance takes people, process and technology, and it is only&amp;nbsp;a baseline for security. The PCI&amp;nbsp;core strategy is know who is accessing&amp;nbsp;the network and log activity, and to monitor for exceptions. When you outsource or trust a service provider, then who is to blame? With all of the hops listed above, can you believe that a single piece of malware went unoticed at some point in this scenario?&lt;/p&gt;&lt;p&gt;Trust and Faith in partners and suppliers is appropriate. But I also like &lt;a title="Solidcore web site on ATM lock down" href="http://www.solidcore.com/solutions/atm.html" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Control and&amp;nbsp;Prevention&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;. Like many of our current customers, they know that Preventing and Detecting Change is important, that's why Solidcore is used today in over 60,000 ATMs worldwide!&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Kim Singletary&lt;br /&gt;&lt;/strong&gt;Director of Embedded Solutions&lt;br /&gt;&lt;a href="mailto:ksingletary@solidcore.com"&gt;ksingletary@solidcore.com&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.wired.com/27bstroke6/2008/07/atm-owner-cardt.html" target=%quot;_blank%quot;&gt;ATM-Owner Cardtronics Issues Non-Denial Denial in Citibank Breach&lt;/a&gt;&lt;br/&gt;Wired blog on 7-Eleven Citibank hack&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target=%quot;_blank%quot;&gt;Payment Card Industry Data Security Standard&lt;/a&gt;&lt;br/&gt;Web site containing the PCI DSS&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.solidcore.com/solutions/atm.html" target=%quot;_blank%quot;&gt;The ATM Security Solutions&lt;/a&gt;&lt;br/&gt;Solidcore web page highlighting how to lock down ATMs&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.solidcore.com/public/item/208877</guid><pubDate>Thu, 10 Jul 2008 20:58:19 -0400</pubDate>
        <category>7-Eleven</category><category>ATM</category><category>Citibank</category><category>PCI</category><category>PCI DSS</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Tomatoes and Security</title><link>http://blog.solidcore.com/public/item/208734</link><description>Similarities between the recent tomato incident and POS security&lt;p&gt;&lt;img style="WIDTH: 93px; HEIGHT: 84px" height="84" alt="Tomato scare is like POS security" hspace="0" src="http://www.victoriananursery.co.uk/vegetable_seeds_and_plants/vegetable_seeds/tomato_seed_abraham_lincoln/l/tomato_abraham_lincoln.jpg" width="93" align="baseline" border="0" /&gt;&amp;nbsp;As I cooked this weekend, I reached into my refrigerator for some tomatoes. These were not home grown but store bought, and I had just finished reading a New York Times article about the potential for &lt;a href="http://www.nytimes.com/2008/06/11/washington/11tomato.html?ex=1228795200&amp;en=6660db1c09bcccec&amp;ei=5087&amp;excamp=GGGNtomatoscare&amp;WT.srch=1&amp;WT.mc_ev=click&amp;WT.mc_id=GN-S-E-GG-NA-S-tomato_scare"&gt;&lt;strong&gt;&lt;u&gt;salmonella&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;. I inspected the red round fruit and found them to be in perfect shape, with no bruises, cuts or punctures. I also washed them thoroughly and felt I could safely eat them. &lt;/span /&gt;&lt;span class="269385115-16062008"&gt;While it's great that we are able to monitor and track these types situations, but why can't&amp;nbsp;there be better protection from them?&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="269385115-16062008"&gt;&lt;/span&gt;&lt;span class="269385115-16062008"&gt;From the NY Times article: &amp;quot;&lt;/span&gt;No one knows whether food has gotten more dangerous or whether the growing number of outbreaks results from better surveillance, said Dr. Patricia Griffin, the chief of the disease centers&amp;rsquo; enteric disease epidemiology branch. Both may be true, Dr. Griffin said.&lt;span class="269385115-16062008"&gt;&amp;quot;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="269385115-16062008"&gt;&lt;/span&gt;&lt;span class="269385115-16062008"&gt;The Payment Card Industry Data Security Standard (PCI DSS) is all about tracking and monitoring changes in the environment of payment card systems. However, l see many similarities from the tomato incident that also apply to point-of-sale (POS) security.&amp;nbsp;Tracking and monitoring help to triage a situation, but its not security. Some lessons learned that apply to both situations:&lt;/span&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;span class="269385115-16062008"&gt;&lt;/span&gt;&lt;span class="269385115-16062008"&gt;Know what's running on your system. Put it under a microscope and identify only the applications necessary for the POS system - all others should be consider potential harmful.&amp;nbsp; Many threats hide themselves almost invisibly within the system files, very much like the bacteria on the infected tomatoes.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="269385115-16062008"&gt;&lt;/span&gt;&lt;span class="269385115-16062008"&gt;Don't rely on others for critical functions. Don't assume the vendors, distributors or suppliers have deployed sanitized systems for your POS processing, but verify it for yourself. It may be packaged for convenience but always&amp;nbsp;apply a second cleansing&amp;nbsp;to ensure safety.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="269385115-16062008"&gt;&lt;/span&gt;&lt;span class="269385115-16062008"&gt;Deploy technology that provides true protection -&amp;nbsp;not just tracking and monitoring. PCI DSS is a guide for providing a baseline for operating practices, it is not a security method. Look for technology that goes beyond the PCI requirements and provides protection from future threats. My recommendation for POS security is Solidcore's &lt;a title="Solidcore S3 Conrol Embedded Web page" href="http://www.solidcore.com/products/s3control_embedded.html" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;S3 Control Embedded&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; for&amp;nbsp;lock-down.&lt;/span&gt;&lt;span class="269385115-16062008"&gt;&lt;span class="269385115-16062008"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="269385115-16062008"&gt;My recommendation for tomatoes is a &lt;a href="http://www.amazon.com/Portable-Disinfector-Home-Scanner-Sterilizer/dp/B001AHDQSU/ref=sr_1_3?ie=UTF8&amp;s=miscellaneous&amp;qid=1213635558&amp;sr=8-3"&gt;&lt;strong&gt;&lt;u&gt;portable UV Disinfector Home Scanner &amp;amp; Sterilizer&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;span class="269385115-16062008"&gt;Eat well!&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="269385115-16062008"&gt;&lt;/span&gt;&lt;strong&gt;Kim Singletary&lt;br /&gt;&lt;/strong&gt;Director of Embedded Solutions&lt;br /&gt;&lt;a href="mailto:ksingletary@solidcore.com"&gt;ksingletary@solidcore.com&lt;/a&gt;&lt;/p&gt;&lt;p /&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.nytimes.com/2008/06/11/washington/11tomato.html?ex=1228795200&amp;en=6660db1c09bcccec&amp;ei=5087&amp;excamp=GGGNtomatoscare&amp;WT.srch=1&amp;WT.mc_ev=click&amp;WT.mc_id=GN-S-E-GG-NA-S-tomato_scare" target=%quot;_blank%quot;&gt;F.D.A. Reports Progress in Tracing Salmonella&lt;/a&gt;&lt;br/&gt;New York Times article about tomato scare&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.solidcore.com/products/s3control_embedded.html" target=%quot;_blank%quot;&gt;Best software for POS security&lt;/a&gt;&lt;br/&gt;Solidcore S3 Control Embedded Web page&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.pcisecuritystandards.org/" target=%quot;_blank%quot;&gt;PCI DSS Compliance&lt;/a&gt;&lt;br/&gt;PCI standard council Web site&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.solidcore.com/public/item/208734</guid><pubDate>Tue, 08 Jul 2008 17:31:22 -0400</pubDate>
        <category>PCI DSS</category><category>point of sale</category><category>POS</category><category>retail</category>
        
        
        
        
       
        
        
        
        
        
       </item>
    </channel></rss>