Top Banner
SCL Security Keeping the Bad Guys Out SCL Infrastructure Keeping the Good Guys In
12

SCL Conference 2015: Keeping The Bad Guys Out

Jul 21, 2016

Download

Documents

SCL UK

A look at SCL's security and infrastructure
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: SCL Conference 2015: Keeping The Bad Guys Out

SCL SecurityKeeping the Bad Guys Out

SCL InfrastructureKeeping the Good Guys In

Page 2: SCL Conference 2015: Keeping The Bad Guys Out

SCL CONFERENCE 2015: THE PRICE OF GREATNESS IS RESPONSIBILITY

How do we implement security?

Hardware

Software

Good processes and procedures

Page 3: SCL Conference 2015: Keeping The Bad Guys Out

SCL CONFERENCE 2015: THE PRICE OF GREATNESS IS RESPONSIBILITY

Hardware:Firewalls

App ServerWeb Server

DB Server

Page 4: SCL Conference 2015: Keeping The Bad Guys Out

SCL CONFERENCE 2015: THE PRICE OF GREATNESS IS RESPONSIBILITY

Hardware:Firewalls

App ServerWeb Server

DB Server

Port Scanning

Page 5: SCL Conference 2015: Keeping The Bad Guys Out

SCL CONFERENCE 2015: THE PRICE OF GREATNESS IS RESPONSIBILITY

Hardware:Firewalls

App ServerWeb Server

DB Server

Intrusion detection/prevention & Anti-virus

Page 6: SCL Conference 2015: Keeping The Bad Guys Out

SCL CONFERENCE 2015: THE PRICE OF GREATNESS IS RESPONSIBILITY

Hardware:HSM

Hardware Security Module Dedicated security device

Used for our Apple iPad Application

Data is never transmitted in clear text

Page 7: SCL Conference 2015: Keeping The Bad Guys Out

SCL CONFERENCE 2015: THE PRICE OF GREATNESS IS RESPONSIBILITY

Software

Secure Socket Layers (SSL & HTTPS)

Stored data encrypted

Secure file transfer

Removal of any software that isn’t needed (hardening)

Scanning for stored card numbers

Page 8: SCL Conference 2015: Keeping The Bad Guys Out

SCL CONFERENCE 2015: THE PRICE OF GREATNESS IS RESPONSIBILITY

Good Processes & Procedures

Documented security processes

Security training & reminders for Employees

Separation of duties

Camera and door entry systems

Page 9: SCL Conference 2015: Keeping The Bad Guys Out

SCL CONFERENCE 2015: THE PRICE OF GREATNESS IS RESPONSIBILITY

Who tests us?

PCI-DSS Level 1 Service Provider Annual Audits

Network penetration test (at least annually)

Application penetration tests

Code reviews

Customer Audits Often add to PCI

Have industry focus

Page 10: SCL Conference 2015: Keeping The Bad Guys Out

SCL CONFERENCE 2015: THE PRICE OF GREATNESS IS RESPONSIBILITY

Infrastructure

Fault Tolerance Everything has a backup

Our design fails over automatically

Scalability Easy to add capacity (hardware)

Automatically add capacity on demand (software)

Monitoring

Page 11: SCL Conference 2015: Keeping The Bad Guys Out
Page 12: SCL Conference 2015: Keeping The Bad Guys Out