Top Banner
The Rocky Road to Business As Usual PCI Europe, Amsterdam 27.11.2014 Kim Halavakoski
46

PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Jul 30, 2015

Download

Technology

khalavak
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

The Rocky Road to Business As Usual PCI Europe, Amsterdam 27.11.2014Kim Halavakoski

Page 2: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

def self.info(Kim Halavakoski)• Security Geek / Nerd

• Chief Security Officer

• 3 kids: 3(♀), 6(♂) and 8(♀) years old, 5 cats

• Hobbies: RC-planes, Quadcopters, Robotics, Photography, Running, Weightlifting…

khalavakoski khalavak

G+ Communities:PCI-JedisSecurity De-Obfuscated

Page 3: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

We develop, deliver and manage systems and solutions for the Nordic financial and capital markets.

Our mission is to make it easy and profitable to run a financial businessOur vision is to be our customers most valued partner

We have offices in Mariehamn, Helsinki, Stockholm and Turku

Crosskey Banking Solutions Ab Ltd

We are a PCI-DSS Compliant Level 1 Service Provider

Page 4: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

PCI 101Some background to PCI-DSS.. Statistics. Requirements

Page 5: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

COMPLIANT

EASY CHEAP

Page 6: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Prevention, Detection & Response

Focus from prevention to a detection and response based event management

Page 7: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 8: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

249

Page 9: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Focus from prevention to a detection and response based event management

Page 10: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 11: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 12: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

The 5 stages of PCI maturityAs a Service Provider I don’t have to comply

with these requirements!These requirements

are stupid!

If I do these compensating controls

then I can do what I want!

What have I done wrong to

deserve 10.6.1?

OK, we use payment

cards so we need to do this PCI-DSS

thing!

Page 13: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 14: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 15: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Stakeholder approval

Management approval and buy-in is essential for the success of your PCI efforts

Page 16: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 17: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 18: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

There is no appliance that automagically gets you PCI-DSS compliant

Page 19: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 20: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Get a good QSA

Page 21: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Scoping is vital for PCI-DSS success

Scoping, Scoping, Scoping & Scoping

Page 22: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Collaboration

One key to success is effective collaboration

Page 23: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

#DevOpsSec#DevOps

Page 24: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Automation & Configuration management

Configuration standards, snowflake servers and cattle

Page 25: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

•Cattle are given numbers like vm001.crosskey.fi

•They are almost identical to other cattle•When they get ill, you get another one

•Pets are given names like garfield.crosskey.fi

•They are unique, lovingly hand raised and cared for

•When they get ill, you nurse them back to health

Page 26: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 27: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 28: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 29: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 30: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 31: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Monitoring, Detection & Response

Focus from prevention to a detection and response based event management

Page 32: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Veriz

on D

BIR

201

3

Page 33: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Veriz

on D

BIR

201

3 Compromise

Page 34: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Veriz

on D

BIR

201

3 Compromise

Discovery

Page 35: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

ANTIVIRUSTHE

Page 36: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Log-review

Threat-intelligence

SecurityAnalyst

SIEMLogmanagement

Fraud

monitoring

End-point

protection

Page 37: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Young padawan, don't forget: Lack of focus leads to sloppiness,

sloppiness leads to misconfiguration, and misconfiguration leads to compromise.

— pauldotcom.com security weekly

Business As UsualPCI-DSS has to be integrated into your daily operations in order to succeed

Page 38: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 39: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

Security

Page 40: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

PCI Taskforce

Page 41: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 42: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 43: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

SummaryUNDERSTAND PCI-DSS REQUIREMENTSGet acquainted with the PCI-DSS standard and requirements. Discuss with your ideas and thoughts with your QSA

GET STAKEHOLDER APPROVALPCI-DSS Compliance requires a substantial effort from the organisation in order to succeed. This will require time, money and management sponsorship to reach the whole organisation.

HIRE A GOOD QSAGet a good QSA. There are a lot of QSACs offering their services. Make sure you get a QSA that understands your business and your particular needs. Make sure your QSA is on the same page and that you have respect for each other.

SCOPINGScoping is a hard nut to crack. The standard is “intentionally” not clear on the details on what is in scope and what is not

Page 44: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance

SummaryAUTOMATION & CONFIGURATION MANAGEMENTAutomation is a really good way to create efficiency in your workflows. Automate all the things that take time to do and focus on the tasks and requirements that is cannot be automated The more smart automation you do, the more time you have to improve and make things more efficient and compliant.

COLLABORATE WITH YOUR TEAMSCollaboration is critical for succeeding with fulfilling all requirements. You can’t do it on your own, you’ll need your Operations Team, Development Team, Security Team and Business Team to make it happen.

INVEST IN MONITORINGMonitoring your environment for malicious activity is difficult. Invest in monitoring, get the team and tools you need to monitor your environment. Outsource if you have to, do it in-house if you can.

IMPLEMENT PCI-DSS INTO YOUR DAY-TO-DAY BUSINESS OPERATIONSThere are a multitude of tasks that needs to be done on a daily, weekly, monthly, quarterly, bi-annual and annual basis in order to stay compliant. These tasks have to become second nature for your organisation and your teams to stay compliant.

Page 45: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance
Page 46: PCI Amsterdam: 27.11.2014: Rocky-Road-to-PCI-Compliance