the State of Security

Regulatory Compliance

PCI Compliance — More Than Just a Tick Box Exercise?

PCI Compliance — More Than Just a Tick Box Exercise?

by Cindy Valladares

“Compliance” is sometimes considered a dirty word in the information security world, particularly when companies take a “tick box” or “check box” approach to achieving it before an audit instead of treating continuous compliance as a part of business as usual. Infosec expert and ‘cynic’ Javvad Malik interviews Neira Jones (@NeiraJones on Twitter), Head of [...]

Read More
Good resource on logging and retention practices – a legal perspective

Good resource on logging and retention practices – a legal perspective

by Dwayne Melancon

In the event of a data breach, law enforcement, regulators, payment card auditors, clients and others will ask about your log file management and your alerting protocols. Don’t be caught unaware.

Read More
Wait, Information Security Isn’t Enough?

Wait, Information Security Isn’t Enough?

by Adam Montville

One of the key themes at RSA 2012 this year (yeah, you thought RSA posts were done, huh?) was “risk management.”  Well, before RSA this year, Jeff Lowder posted this article on the Society of Information Risk Analysts blog.  While the post was made by Mr. Lowder, the content is Mr. Hubbard’s.  The idea behind [...]

Read More
Making Compliance Part of Your Daily Routine, Not Just Once a Year

Making Compliance Part of Your Daily Routine, Not Just Once a Year

by David Spark

Monitor continuously so you don’t get stuck finding out about a breach 3-4 months after it happened.

Read More
Explaining Information Security, Risk and Compliance to Your Mom

Explaining Information Security, Risk and Compliance to Your Mom

by Cindy Valladares

I’m sure you’ve been at a social party enjoying a good conversation when someone asks you: “So what do you do?”. It’s frustrating sometimes to explain in layman terms what we do as information security professionals. On top of that, it seems like everyone in the industry has his or her own way of defining [...]

Read More

Using PCI Compliance As a Business Driver

by Cindy Valladares

Here at Tripwire we get many great customer success stories, so I’ve decided to start a series of blog posts that bring those stories to you. This week’s post focuses on a The Logic Group, a large payment processor in the UK. Organization The Logic Group solutions process in excess of three billion credit and [...]

Read More