The Oracle Australia and New Zealand Middleware and Technology Blog.
Showing posts sorted by relevance for query pci. Sort by date Show all posts
Showing posts sorted by relevance for query pci. Sort by date Show all posts

Monday, August 18, 2008

Have you ignored PCI


Think about who has your credit card details, when you look at your household dealings they include council, electricity, gas, water, building insurance, car insurance, petrol and it goes on. I am sure all of us have at least 50 relationships with various organisations via consumer spending with credit cards. In fact it would be greater when you factor in frequent purchases like clothing. When you consider the rapid growth of internet espionage, fraud and identity theft what is being done to protect us. PCI is the best example of legislation that is designed to protect the mums and dads.

The PCI Data Security Standard is nothing new; it has been around for a few years and depending on the region it can be front of mind or ignored. In the land of compliance (USA) of course PCI has seen heavy adoption, but in Asia Pacific the adoption has been lagging.

So what is PCI, well to put it simply the card merchants AMEX, Diners, Visa, JCB and Mastercard came up with a set of recommendations or best practices for any organisation that deals with credit card data. For example encrypting card numbers or making sure your systems are patched to the current versions so they are less succeptable to hacking are examples of these recomendations. There are 12 in total, and on reviewing them you have to wonder why they wouldn’t be adopted. It just makes good sense.

That’s clearly the problem, when does “good sense” make a good business plan. Rarely if at all is my opinion. With the IT industry unable to propose anything it seems unless tied to an ROI, TCO, SLA or some other acronym, simply put compliance especially in Australia is a tough sell. Where is the pain!

Well the pain is coming, credit vendors currently do fine organisations for failing PCI audits, but the organisation may never suffer the fine. Banks can at their discretion choose to absorb the fine and not pass it onto their customer. If the organisation that has failed the audit has significant financial heft, and hence contributes a large revenue stream the bank would for the sake of the relationship simply eat the fine. But these fines are now becoming more frequent and larger. Plus the smaller Level 2 and 3 merchants are coming under closer scrutiny. So now the banks will be forced through the size and frequency of the fines to start passing more of them onto their customers. This of course is great news for consumers like you and me since we deserve a better deal when it comes to privacy and protection of our financial dealings.

With this changing dynamic of banks pasing down the fines, and the continuous IT mantra of “do more with less” IT automation is coming of age across the board. Most organisations have come to terms with automating employee on boarding or provisioning user accounts, offering self service to change your home address, mobile phone number or a password. So why not automate your compliance regime.

The following deck outlines the 12 guiding principles of PCI and shows how oracle IDM and Database Security solutions can overlay these requirements.

If you would like more information on PCI, and how to start. Give us a call.


Read this document on Scribd: PCI Presentation by Carl Terrantroy

Friday, August 1, 2008

ANZ Technology Kick Off Data Security and PCI DSS

I would like to thank Michael Ryan from Vectra Corp who presented at Oracles Technology Summit in Sydney this week. Mike explained how PCI DSS is impacting organisations in Australia that store credit card details. Mandatory compliance will be introduced later this year around PCI, this means that organisations that have been delaying their complaince run the risk of a fine or multiple fines being issued by MasterCard or Visa. At worst merchants may loose the right to transact with credit cards.

So is technology needed for PCI DSS? well the short answer is not really. In the USA organisations have survived through mosts compliance regimes without implementing technology solutions. But what they are now fining is that complaince is costing a lot of money. So now that organisations are compliant they are now looking at how to reduce the compliance costs. This is where technology has an important play since automation is the key to reducing costs. Some of the requirements of PCI include keeping patching upto date, user access secuirity, encryption and auditing. All of these can be supported by Oracle's security solutions that will lock the database down and manage access and authorisation requests.

Here is Michael's presentation

Here is my introduction slides
Read this document on Scribd: Datasecurity

If you would like more information please contact myself or Vectra
Cheers

Wednesday, December 24, 2008

the red room review for 2008

The red room was founded for several reasons, to communicate with Oracle customers and the general IT community was one. But to make this communication more interesting we wanted to explore how new WEB 2.0 technologies could assist. Could these largely social utilities add any value for Oracle, our readership and our customers?

The answer is a resounding yes. Technologies that worked very well included Twitter with live feeds from Oracle Open World OOW08, Linkedin to participate in group discussions around areas like security and compliance, and the content hosting sites like iTunes, Podbean and Scribd.

Sure these sites would enrich the experience on the red room for our readers. The real bonus is that each of these technologies has their own unique communities to tap into. For example the red room had over 5,000 visits from July this year, scribd which hosts our presentations had over 2,500 views from scribd users. So you see we reached potentially another 2,500 readers by placing the content in multiple sites and 632 people downloaded a podcasts from podbean.

Our readership includes 50% from Australia and New Zealand which validates that people are interested in reading localised content and not just from news from the USA. Other countries include France, Turkey, Japan, Italy and Spain (i need a field trip) with 74 countries in all.

The Oracle news highlights for me this year included the acquisition of BEA and Oracles first hardware appliance The Database Machine.

Our top 5 articles this year

1.       SOA or Not

2.       Unstructured Information Management

3.       Australian Federal Government and WEB2.0

4.       Oracle Role Management

5.       Oracle Universal Archive

Other notable articles include

·         The Clumsy Human PT 1&2

·         Open World Final Day and the Joy of X

·         Oracle and BEA – Full Circle

·         iPhone and its impact on Information Management

·         Have your ignored PCI

In 2009 we will have more contributors including a 10 posts series on SOA Governance. Look our for our new years eve posts from Paul Ricketts for more on this and what the future will hold for the red room in 2009.

Its time i bid you farewell, presents to wrap and no doubt a cold beer also. Have a joyous holiday with your friends and family, try and avoid the news so you can rest and recharge for what will be an interesting 2009.

Cheers

Carl