|
Privileged and external users refer to those who need access to your network to perform their jobs, and who have powerful access tools within their reach that, if abused, can be detrimental to your organization by exposing vulnerabilities to breaches of private data, failed audits and potential fraud. These highly-skilled, well-equipped users include outsourced database administrators (DBA's), hardware/software vendors, off-shore application developers, outsourced IT operations, internal IT staff and managed service providers (MSP's) who work within your mission critical systems. The characteristics of this user group makes delivering a compliance footprint extremely difficult.
Further complicating the satisfaction of compliance regulations is that the infrastructures themselves are likely to have legacy systems in place, such as Point of Sale systems, that require the locking of "back doors" and the encryption of legacy protocols which compromises data-in-transit requirements.
Although there are many solutions in the market that handle PCI compliance for applications users, existing solutions do not ensure PCI compliance and security policy enforcement for the privileged user.
How does a company satisfy PCI compliance in a cost-effective and unobtrusive manner for the privileged and external user group? How can they...