Security Basics mailing list archives

Re: Security Standards


From: John Morrison <john.morrison101 () googlemail com>
Date: Thu, 7 Jan 2010 12:48:46 +0000

sOhO,

It is quite difficult to be precise about what to do as every business
is different. Other reasons for this might be a) there is a lot of
money to be made, so why give it away and b) anyone who gives bad
advice may be sued for large sums - PCI non-compliance can be costly.

However, the major card issuers and the PCI Standards Organisation do
provide some information. One useful document to help prioritise
resources is "The Prioritized Approach to Pursue PCI DSS Compliance"
(https://www.pcisecuritystandards.org/education/docs/Prioritized_Approach_PCI_DSS_1_2.pdf)

The other places to look are the web sites of the suppliers for the
hardware and software you use. They will have more specific
information. For example, Cisco have built in templates for some
devices (for example,
http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_waf/v61/user/guide/waf_ug_profiles.html#wp1076183).
They also do a guide called "PCI Solution for Retail 2.0 Design and
Implementation Guide"
(http://www.cisco.com/application/pdf/en/us/guest/netsol/ns171/c649/ccmigration_09186a00809464ec.pdf).
Similarly, if you use Microsoft products a good starting point is
their IT Governance and Compliance site
(http://technet.microsoft.com/en-us/regulatorycompliance/default.aspx),
Payment Card Industry Data Security Standard (PCI DSS) Compliance
Planning Guide 
(http://www.microsoft.com/downloads/en/confirmation.aspx?familyId=d8320df1-d0d0-469f-a6fc-b53987bd74c2&displayLang=en&pf=true)
and IT Compliance Management Guide
(http://www.microsoft.com/downloads/details.aspx?FamilyId=BD930882-0D39-4900-9A79-B91F213ED15D&displaylang=en).




2010/1/6  <s0h0us () yahoo com>:
Hi,
As part of a PCI-DSS risk assessment I need to come up with security standards for all of our critical network 
devices, including windows servers. I've been directed to NIST publications and others but I'm finding that they are 
general documents rather than specific ones regarding what settings need to be configured, i guess like a checklist. 
can you recommend a site that might have them? i continue to search as i submit this posting...thanks! any 
information is appreciated. happy new year!!!


sOhO

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, 
how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, 
purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for 
set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital 
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: