Firewall Wizards mailing list archives

Re: PCI DSS & Firewalls


From: Chris Blask <chris () blask org>
Date: Thu, 2 Apr 2009 06:35:15 -0700 (PDT)


Paul D. Robertson <paul () compuwar net>,Wednesday, April 1, 2009 9:09:40 PM

Is it just me, or do the PCI DSS "standards" for firewalls look like 

someone played "I have a CISSP" buzzword bingo?


Nope, not just you. ;~)

The DSS (and regulatory tools in total) are not bits-und-bytes technical artifacts, they are human engineering 
technical artifacts.  The idea being to find a way to move people in a desired direction an achievable distance.  The 
funcational DNA in PCI is not what gadgets to use how, it's "if it's done wrong there are legal ramifications at the 
executive level".

One of our folks did PCI for Walmart, and when the CEO sent out a note saying (sic): "Listen to this guy or you're 
fired" it proved that PCI worked.  It reduced the prospect of spending in the future the millions of man-hours we have 
spent in the past arguing with people that maybe they should at least consider changing default passwords.

Now, is PCI enough (or complete)?  Apparently not (go ask Heartland).  But if we can get people doing the things in the 
DSS for starters, at least they'll be evolved beyond gills and flippers when we get there to talk about actual security.

-chris


      
_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: