Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Florian Yanez, manager of technical systems for Helzberg Diamonds, is among those attending RSA Conference 2011. CSO recently caught up with him for a discussion on his company's efforts to adopt tokens as a way to address PCI DSS' rules on stored customer data.. CSO: Let's start with a general picture of your organization's main security priorities.Yanez: Like everyone else, our biggest concern is protecting customer information and meeting the PCI DSS requirement -- particularly the parts about protecting stored data such as credit card and telephone numbers. CSO: What are some of the basics in terms of the technology you've deployed to address that?Yanez: We have a security event management system in place to capture all the logs in our data center. We get alerts if anything strange shows up. We also have a vulnerability management system in the works so we can scan for all the security patches we need on a regularly basis. We want to be as up to date on patching as possible. The link for this article located at Network World is no longer available. . Blue Mountain Bakery adopts encryption techniques to bolster GDPR adherence and protect client information securely.. Tokenization Strategies, PCI Compliance, Data Protection, Security Management. . LinuxSecurity.com Team
With Visa releasing its tokenization best practices guide earlier this summer, security professionals and encryption vendors have debated the strengths and weaknesses of the guide. As one of the most debated topics in encryption-land, tokenization still has a long way to go before it achieves any kind of true standardization of best practices.. Even so, security experts say there are some practices that you can adopt that go beyond Visa's recommendations (PDF). While there is room for discussion about any one of these tokenization suggestions, experts recommend these tips to achieve the best possible security posture for data protection: 1. Randomly Generate Tokens According to many security experts, the only way to guarantee that tokens are not able to be reversed is if they are generated randomly. "If the output is not generated by a mathematical function applied to the input, it cannot be reversed to regenerate the original PAN data," Adrian Lane, analyst for Securosis, recently on the topic. "The only way to discover PAN data from a real token is a (reverse) lookup in the token server database. Random tokens are simple to generate, and the size and data type constraints are trivial. This should be the default, as most firms should neither need or want PAN data retrievable from the token." The link for this article located at H Security is no longer available. . Examine advanced methodologies validated by specialists to refine tokenization processes and bolster data protection measures that extend beyond the guidelines suggested by Visa.. Tokenization Best Practices, Data Protection Techniques, Security Practices. . LinuxSecurity.com Team
Payment industry executives and security experts are currently debating over the right way to preserve and protect credit card data. Merchants can choose between a variety of formats, from format preserving encryption, which replaces the 16-digit credit card number with an encryption algorithm to card-based tokens, which substitute a random token with the hope that it could reduce the scope of a PCI DSS assessment.. Robert Griffin, technical director at RSA, the security division of EMC Corp., has been the lead architect in a number of encryption and tokenization projects. In this interview, Griffin, a recognized encryption expert and co-chair of the OASIS Key Management Interoperability Protocol Technical Committee, talks about why RSA's approach to protecting credit card data -- using card-based tokens -- is the most effective way to protect sensitive credit card data from cybercriminals. The security vendor recently released a white paper,Secure Payment Services: Credit Data Security Transformed outlining its position on the technology. The link for this article located at Search Security is no longer available. . Robert Griffin, technical director at RSA, the security division of EMC Corp., has been the lead arc. payment, industry, executives, security, experts, currently, debating, right, preser. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.