Upcoming Events

A Network Computing Webinar:
Avoiding Downtime: How Virtualization Can Help In Times of Trouble

June 12, 2013
11:00 AM PT / 2:00 PM ET

Are you caught between a desire for the benefits of the cloud and concerns about security and control? Then you should attend this insight-packed webinar to learn how private data networking technologies like MPLS IP-VPNs can address your concerns and allow you to safely and intelligently reap the savings, agility and other benefits associated with cloud computing.

Join us to hear top industry experts discuss the private data network technologies that are best suited for enterprise cloud access requirements. You won't want to miss this opportunity to learn how your organization can best mitigate risk while reaping the full potential benefits of the cloud.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

PCI To Drive IT Budgets In 2011

A new Payment Card Industry (PCI) survey finds that respondents anticipate significantly increased spending on PCI compliance this year, which should drive security-related budgets across numerous IT areas. The survey of 500 IT executives on what's happening as a result of the recent update to the 5-year-old PCI Data Security Standards (PCI DSS 2.0), conducted by InsightExpress on behalf of Cisco, also found that the majority of respondents believe their organizations are more secure than they would be if PCI compliance wasn't required.

The survey was intended to discover where the PCI industry is and what impact it will have on organizations and their IT expenditures, says Fred Kost, director, security solutions, at Cisco. Overall, the PCI Council has been successful in communicating and getting active participation and increased adoption of the PCI standards among stakeholders, he says, but more work is required.

A recent survey by Verizon finds that organizations struggle when they have to engage in continuous security activity, such as daily monitoring of logs, according to the business analysis of its PCI assessment clients. In addition, Verizon finds that organizations that had suffered data breaches of cardholder information performed dismally in terms of compliance with most PCI requirements.

Verizon also reported that about one-fifth of the organizations included in the analysis were found to be fully PCI-compliant in Verizon's Initial Report on Compliance (IROC), issued after the assessors' site visit.

Organizations performed woefully across all aspects of regularly testing security systems and processes, but failure to perform file integrity was the single greatest failure among the 150 or tests required across the PCI standard. The consistent theme across the non-compliance for tracking, monitoring and regular testing was the failure to apply security practices that require continuous activity.


Page:  1 | 2  | Next Page »


Related Reading


More Insights


Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | Please read our commenting policy.
 
Vendor Comparisons
Network Computing’s Vendor Comparisons provide extensive details on products and services, including downloadable feature matrices. Our categories include:

Research and Reports

May 2013
Network Computing: May 2013


TechWeb Careers