PCI DSS - Payment Card Industry Data Security Standard
PCI was developed by several major credit card companies as a guide to help prevent credit card fraud, hacking, and various other security issues, for organisations that process credit card payments. Companies that store, process, or transmit credit card data, must be PCI compliant, and pass an audit with a PCI DSS qualified security assessor in order to continue to process credit card information.
In general, the broad requirements of PCI DSS are:
Build and Maintain a Secure Network
Protect Cardholder Data
Maintain a Vulnerability Management Program
Implement Strong Access Control Measures
Regularly Monitor and Test Networks
Maintain an Information Security Policy
The Snare Server and agents, in combination, provide the capability to monitor user and system activity on your networks, and validate your access controls. In addition, network vulnerability assessment components can assist in the process of regularly testing your systems and networks for vulnerabilities which may affect PCI compliance.
On installation, the Snare Server runs a configuration wizard, which allows an administrator to install and configure objectives which are specifically targeted to address PCI Data Security Standard requirements.