|
GuestView Columnist David Taylor this week argues that one of the hardest parts of extending PCI controls to other confidential data is the application of Identity and Access Management (IAM) that crosses applications and platforms, without encountering the “analysis paralyses” that comes with trying to implement Single Sign-on. Because many organizations create policies specifically to comply with PCI standards, there are some policies that specifically single out cardholder data for special protection. These need to be rewritten to reference a data classification policy. If that doesn’t exist, then it needs to be created, and some examples of data in the “confidential class” other than cardholder data need to be provided. Read more. |