Payment Card Industry Data Standards and Data Loss Prevention
A new article has been added to the Essentials Series: Messaging and Web Security Volume II, this one is entitled Payment Card Industry Data Standards and Data Loss Prevention. There is much debate about best practices for implementation and what policies and techniques are sufficient and what ones are lacking but there are fundamental principals that should be followed.
This article describes the basics of minimizing application exposure, network based data loss prevention, and the use of database encryption. As the article concludes:
Satisfying the requirements of data confidentiality regulations like PCI DSS requires a multi-layer approach that includes DLP technologies. And even within DLP, a combination of complementary techniques will further reduce risks.



Email This!
Digg it!
Del.icio.us
Reddit!
Newsvine
