Bit9

Skip Navigation
 

Enterprise Application Whitelisting

Current Articles | RSS Feed RSS Feed

Data Breach Roundtable: PCI Council, Deloitte and Touche

Posted by Kate Munro on Thu, Aug 13, 2009
  | Share on Twitter Twitter | Buzz This  Google Buzz | Submit to Digg digg it |  Share on LinkedIn LinkedIn 
Tags: ,

We are hosting an online data breach "roundtable" featuring Bob Russo, general manager of the PCI Council; Rich Baich, the former CISO of ChoicePoint who weathered the historic breach in 2004 and is now a partner at Deloitte and Touche; and Tom Murphy, chief strategy officer at Bit9, Inc.

Topics include the recent data breaches in the news and solutions.

To sign up, go the registration page here.

0 Comments Click here to read/write comments

Are You Ready for Enterprise Application Whitelisting? Part 2

Posted by Brian Gladstein on Wed, Feb 20, 2008
  | Share on Twitter Twitter | Buzz This  Google Buzz | Submit to Digg digg it |  Share on LinkedIn LinkedIn 

This is my second posting in a series that is meant to help you determine if you are ready for enterprise application whitelisting. For the uninitiated, application whitelisting is a method of operating a PC environment that only lets authorized software run. That means unless you (as the IT department of a company or an organization) allow an application to run, it is prohibited from executing on a computer.

 

These days solution providers like Bit9 (the leader in Enterprise Application Whitelisting) are paving the way for companies to implement a whitelisting strategy that is easy and effective - and one that can really have an impact in how you secure your desktops and data.

 

But many companies are asking themselves: am I ready for application whitelisting? To help answer this, my previous post asked the question "Is your IT staff stretched too thin?"

 

Here is the second question you can ask yourself to determine if you are ready for enterprise application whitelisting.

 

Question 2: Do you need better auditing, reporting & compliance?

 

There has been a veritable explosion in requirements placed on companies to inventory and audit their software environments. Driving these demands are a number of different activities ranging from regulations to industry guidelines to software vendors. But one thing is for sure - companies can no longer afford to not know what is happening on their corporate desktops and laptops.

 

Let's look at a few specific examples of where compliance is being pushed into IT:

  • PCI Compliance: organizations that accept payment cards including credit cards and debit cards (primarily retail, finance, healthcare, and many more) are subject to these industry requirements to ensure the integrity of any computing system that handles payment card information (credit card numbers, accounts, etc.)
  • Sarbanes-Oxley: Public comapnies in the United States must ensure that their financial systems have not been tampered with and the integrity of the financial reporting data remains in tact.
  • HIPAA: Hospitals, physicians, health insurance companies, and other health-related industries are required by law to protect the privacy of patients' information and history, ensuring that only authorized individuals and systems can access access any specific information.
  • Federal Desktop Core Configuration (FDCC): Federal agencies in the United States are now required by the OMB (Office of Management & Budget) to harden their Windows desktops to a very specific and detailed Windows configuration.
  • Software Vendor Licensing: Large software companies have been stepping up the fight against piracy by conducting large-scale audits of their customers to identify any gap between how many copies of a software product are in use and how many the company had paid for. This often results in an unexpected, but sizeable "true-up."
  • Computer Forensics: With so much data being produced and transmitted throughout organizations, many are finding it in their interest to create a forensics capability. You can hope you don't need it, but in the case of lawsuits, disgruntled employees, and other unpleasant events, it can be very useful to understand who did what and when.
  • Consolidation: As companies merge and acquire, IT departments end up being responsible for multiple redundant systems. Many of them become forgotten - although the company still pays a heavy maintenance stream. So knowing what is actually in use can reap significant savings in software costs.

 

What's happening at many companies is that they are finding themselves under the demands of several of these drivers at once. Take as an example a large, public retailer - they will have to adhere to rules and guidelines put forth by the PCI Council, SOX, and their software vendors... maybe others as well.

 

Precisely because of these overlapping requirements, companies are proceeding along two simultaneous paths:

  1. Simplify the data trail with a single, multi-purpose audit stream.
  2. Enforce more, audit less by putting better controls around the desktop that limit policy violations and vastly reduce the data processing involved in demonstrating compliance.

 

Application whitelisting is a critical activity for both of these because having a rich inventory of the applications in use, and being able to prevent unauthorized software from being used can greatly reduce the cost of getting to compliance and systematically proving it on a regular basis.

 

So if you are under pressure to audit and report on the software in your environment and to prove that your computers are in compliance, you have met criteria #2 for being ready for Enterprise Application Whitelisting.

0 Comments Click here to read/write comments

4 out of 5 cardholder breaches occur at the point of sale

Posted by Kim Ann King on Wed, Jun 13, 2007
  | Share on Twitter Twitter | Buzz This  Google Buzz | Submit to Digg digg it |  Share on LinkedIn LinkedIn 
Did you know that 4 out of 5 cardholder data breaches occur at the point of sale?

As the technology used by merchants and their partners has evolved, card fraud has become more sophisticated, and any business that stores or transmits cardholder account data is a potential target. In response to this evolving threat, the major credit card companies have created a set of security standards, known as the Payment Card Industry Data Security Standards or PCI DSS, to protect their customers from security breaches and identity theft.

Merchants everywhere are under extreme pressure to comply with the PCI Data Security Standards or risk financial penalties and negative press. The key challenge is how to protect cardholder data on a point-of-sale (POS) system without a dedicated network connection or on-site IT staff to patch security vulnerabilities and update antivirus signatures.

A recent webinar hosted by Bit9, entitled “Achieving PCI Compliance at the Point of Sale,” detailed the challenges of securing a POS system, including identifying unauthorized software, locking down systems, auditing files, and preventing data leakage. For more information on achieving PCI compliance at the point of sale, including a free whitepaper, visit the Bit9 web site.

0 Comments Click here to read/write comments

All Posts

Subscribe by Email

Your email: