So Many Logs, So Little Time
Written by Walter ConwaySeptember 15th, 2010
PCI's logging requirements present a particular challenge for retailers, especially those with multiple store locations. How does a retailer with a large number—even thousands—of remote devices efficiently log, harvest those logs and review them daily? Reaching for a vendor suite right away may sound easy, but that is only the beginning of an answer, pens PCI Columnist Walter Conway.
Once that suite is in place, retail CIOs should plan for a risk- and security-based assessment of their log management needs and allocate the resources to make the system work. Otherwise, retailers may centralize their logging but find themselves overwhelmed by the white noise of too much data. Or, IT could distribute log reviews down to the store level only to learn that the individual locations cannot achieve separation of duties, back-ups or daily log reviews conducted by people who know what they are doing.
This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.
Already a Subscriber? Login Here
Pages: 1 2
Leave a Reply
Readers, specifically those who want to comment on a story:
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
I have strong reservations about the 'individual' certification and posting of that information for merchants. Can you imagine the potential employee poaching that might occur? The implications when competitors can look up how many are certified with each of their competitors?
-Christine
