Security Basics mailing list archives

Re: PCI DSS Compliant Software


From: Ricardo Ferreira <ricardo.ferreira () sotechdatacenter com br>
Date: Sun, 30 Jan 2011 16:11:33 -0300

Em 28/01/2011 16:12, Hung Lee escreveu:
We use Quest ChangeAuditor.  It's a beautiful thing.

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of Kurt M.D. John
Sent: Thursday, January 27, 2011 5:44 PM
To: security-basics () securityfocus com
Subject: PCI DSS Compliant Software

Good evening everyone,

I need some input from the list. A client of ours is looking for a
cheaper alternative to Tripwire in order to meet/manage their PCI DSS
requirements. During our research we've come across AIDE (Advanced
Intrusion Detection Environment) and Change Tracker by NNT. I would like
some feedback on these two pieces of software; as well as any other
software out there that is relatively comparable with Tripwire. Oh and
it cant be open source.

Much appreciated. Thanks so much
--
Kurt M. John, CISA, C|EH, CPT --


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an
SSL certificate.  We look at how SSL works, how it benefits your company
and how your customers can tell if a site is secure. You will find out
how to test, purchase, install and use a thawte Digital Certificate on
your Apache web server. Throughout, best practices for set-up are
highlighted to help you ensure efficient ongoing management of your
encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
f727d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


We have met these specific PCI-DSS requiremenmts using the following combination primarily due to budget restrictions:

Osiris + Splunk... ( agents for Unix, Linux, Windows, etc....)
Pls see the link...
http://osiris.shmoo.com/
http://www.splunk.com


If you want you can integrate splunk with nagios or even Cacti using a syslog plugin...a killer combo application for payment service providers...


These 2 pieces of software if fine tuned do and even exceed what Tripwire is supposed to do. The only drawback is the lack of a good graphical user interface but that will depend on your budget...

--
HTH


Ricardo Ferreira
Telecom, Tecnologia e Segurança da Informação
BSDA, CCDP, CCNP, CCDA, CCNA, MCSE, MCP
-------------------------------------------------------------------
Sotech Soluções Tecnologicas
Rua da Alfazema, 761, 1o. andar - 102/103
41820-710 - Caminho das Árvores - Salvador-BA - Brasil
Tel : 55 71 3472.9400 Cel : 55 71 9138 4630

Email:  ricardo.ferreira () Sotechdatacenter com br
Site:   www.sotechdatacenter.com.br


Esta mensagem é dirigida apenas ao seu destinatário e pode conter
informações confidenciais, não passíveis de divulgação nos termos da
legislação em vigor. Caso tenha recebido esta mensagem por engano,
solicitamos notificar a Sotech Soluções Tecnológicas e excluí-la de sua
caixa postal.

This message, including its attachments, may contain confidential
information. If you have improperly received this message, please delete
it from your system and notify immediately the sender. Any form of
utilization, reproduction, forward, alteration, distribution and/or
disclosure of this content in whole or in part, without the prior written
authorization of the sender, is strictly prohibited. Thanks for your
cooperation.



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------

Current thread: