This is actually an idea I had started working on, but specifically for PCI requirement 6.2 in conjunction with some kind of automated threat analysis.
If I can list every software used in the card processing environment and get automated alerts fired straight into my ticketing system to create an event, this would be good.
Hmm, interesting. Automated threat analysis, how exactly would that work? Like the configuration OVALs?
If I'm not mistaken Red Hat has quite the support via OVALs to some of the PCI requirements.
Regarding the card processing environment, what does that usually consist of? Linux servers?
You can reply to info@ SecureIT or here. I'm interested in knowing more.
Comments
This is actually an idea I had started working on, but specifically for PCI requirement 6.2 in conjunction with some kind of automated threat analysis.
If I can list every software used in the card processing environment and get automated alerts fired straight into my ticketing system to create an event, this would be good.
Hmm, interesting. Automated threat analysis, how exactly would that work? Like the configuration OVALs? If I'm not mistaken Red Hat has quite the support via OVALs to some of the PCI requirements.
Regarding the card processing environment, what does that usually consist of? Linux servers?
You can reply to info@ SecureIT or here. I'm interested in knowing more.
Cheers