Security Basics mailing list archives
Re: Security Standards
From: John Morrison <john.morrison101 () googlemail com>
Date: Thu, 7 Jan 2010 12:48:46 +0000
sOhO, It is quite difficult to be precise about what to do as every business is different. Other reasons for this might be a) there is a lot of money to be made, so why give it away and b) anyone who gives bad advice may be sued for large sums - PCI non-compliance can be costly. However, the major card issuers and the PCI Standards Organisation do provide some information. One useful document to help prioritise resources is "The Prioritized Approach to Pursue PCI DSS Compliance" (https://www.pcisecuritystandards.org/education/docs/Prioritized_Approach_PCI_DSS_1_2.pdf) The other places to look are the web sites of the suppliers for the hardware and software you use. They will have more specific information. For example, Cisco have built in templates for some devices (for example, http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_waf/v61/user/guide/waf_ug_profiles.html#wp1076183). They also do a guide called "PCI Solution for Retail 2.0 Design and Implementation Guide" (http://www.cisco.com/application/pdf/en/us/guest/netsol/ns171/c649/ccmigration_09186a00809464ec.pdf). Similarly, if you use Microsoft products a good starting point is their IT Governance and Compliance site (http://technet.microsoft.com/en-us/regulatorycompliance/default.aspx), Payment Card Industry Data Security Standard (PCI DSS) Compliance Planning Guide (http://www.microsoft.com/downloads/en/confirmation.aspx?familyId=d8320df1-d0d0-469f-a6fc-b53987bd74c2&displayLang=en&pf=true) and IT Compliance Management Guide (http://www.microsoft.com/downloads/details.aspx?FamilyId=BD930882-0D39-4900-9A79-B91F213ED15D&displaylang=en). 2010/1/6 <s0h0us () yahoo com>:
Hi, As part of a PCI-DSS risk assessment I need to come up with security standards for all of our critical network devices, including windows servers. I've been directed to NIST publications and others but I'm finding that they are general documents rather than specific ones regarding what settings need to be configured, i guess like a checklist. can you recommend a site that might have them? i continue to search as i submit this posting...thanks! any information is appreciated. happy new year!!! sOhO ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------
------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------
Current thread:
- Re: Security Standards, (continued)
- Re: Security Standards Phil Derbyshire (Jan 07)
- RE: Security Standards Rivest, Philippe (Jan 07)
- RE: Security Standards Youngquist, Jason R. (Jan 07)
- RE: Security Standards lgpm (Jan 07)
- Re: Security Standards John Morrison (Jan 07)
- RE: Security Standards Andy Tripp (Jan 07)
- Re: Security Standards LAS (Jan 08)
- RE: Security Standards Craig S. Wright (Jan 07)
- USB Vulnerabilities Exploited Phil Derbyshire (Jan 07)
- Re: Security Standards Todd Hughes (Jan 07)
- Re: Security Standards John Morrison (Jan 07)
- Re: Security Standards las (Jan 08)
- Re: Security Standards Cornwell, Kay (NIH/NIGMS) [E] (Jan 08)
- Re: Security Standards stcroix111 (Jan 11)