pci breach scenarios and the cyber threat landscape with brian honan

39

Upload: tripwire

Post on 15-Jul-2015

349 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 2: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

3

2

1

Page 3: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 4: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

“Total Global Impact of CyberCrime US $3 Trillion, making it more profitable

than the global trade in marijuana, cocaine and heroin combined.”-Europol Serious & Organised Threat Assessment 2013

Page 5: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

IT security is no longer a trivial issue and is now becoming

part of a company’s boardroom discussion

Page 6: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 7: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 8: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 9: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 10: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 11: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 12: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 13: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 14: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 15: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 16: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 17: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 18: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 19: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 20: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 21: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

PCI DSS 3.0

Page 22: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

How Secure Is Your Cardholder Data?

Page 23: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

How To Protect

Page 24: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 25: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

Identify & Value Key Assets

Page 26: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 27: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

Recommendation: Have meetings with Application Developers, Networking and Security

teams to understand and document current state and communicate expectations. Use

some type of discovery tool to aid your inventory work.

Page 28: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan
Page 29: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

Recommendation: Vulnerability scanning, and security configuration assessments can validate mitigations. Tripwire’s solutions produce audit-ready reporting, including a special PCI 3.0 Reporting Pak we have available to our Log Center customers.

Page 30: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

Recommendation: Centrally manage (discover, monitor, report,

log) on your wireless infrastructure to get visibility early

for PCI (ASV)

Page 31: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

Monitor & Respond

Page 32: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

Recommendation: Work across development and IT operations to clearly define

access rights based on consistent roles and business purpose. Divide the work

into business units for clearer ownership as well as executive support.

Ponemenon Risk-Based

Security - Only 34% of the

retail sector measure the

reduction in access and

authentication violations to

assess risk management efforts

Verizon’s 2014 PCI

Compliance Report shows that

64.4% of accounts with access

to cardholder data failed to

restrict access to just one user

— limiting traceability and

increasing security risk.

Page 33: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

Security Awareness Training

Page 34: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

95% of Breaches Were Due to “Human Error”- IBM

90% of Malware Requires Human Interaction- Symantec

100% of Successful Attacks Compromised The Human- Mandiant

64% of Orgs See Security Awareness As a Challenge- E&Y 2010

3 times as many breaches are caused by accidental insider activity than malicious intent

- Open Security Foundation

The Human Element

Page 35: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

How Secure Is Your Provider?

Page 36: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

Business Context – connect your

security efforts to what matters

to your business

Security Automation – apply

intelligence and drive automation

for more effective operations

Enterprise Integration – across

our portfolio and also with other

security ecosystem partner solutions

Page 37: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

http://www.tripwire.com/securescan/

Page 38: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

3

2

1

Page 39: PCI Breach Scenarios and the Cyber Threat Landscape with Brian Honan

tripwire.com | @TripwireInc

@BrianHonan