January 2010
January: Cyber breaches, Web 2.0 at Work, Scams, and 2010 is just beginning  
SpartanTec, Inc.
Blame the auditors: What a concept!

I have never thought of this.  After a breach, just blame the auditors.  Wait.  The reason I hadn’t thought of it is because passing a compliance audit IS NOT ASSURANCE OF SECURITY.  But some still don’t get it.

In an interview with CSO’s Bill Brenner, Heartland Payment Systems’ CEO, Robert Carr, blamed his QSA auditors for a recent (huge) breach.  Because they said his organization was PCI compliant, he felt secure.  Wow.  Security by checklist once again.

Rich Mogull, in an open letter to Carr, makes several excellent points about reliance on compliance instead of solid security practices.  He concludes his letter with,

But, based on your prior public statements and this interview, you appear to be shifting the blame to the card companies, your QSA, and the PCI Council. From what’s been released, your organization was breached using known attack techniques that were preventable using well-understood security controls.

As the senior corporate officer for Heartland, that responsibility was yours.

Source: An Open Letter to Robert Carr, CEO or Heartland Payment Systems, Rich Mogull, 12 August 2009

Rich’s letter is a good read, and it should be circulated widely among security professionals and senior executives. 

Among other things, this is another case where an organization is falling back on a completed checklist representing compliance with the PCI standard, a bare minimum set of security requirements.  But whether you are HIPAA, GLBA, or PCI compliant, checking off on recommended practices doesn’t equal security.

Each of us is responsible for placing compliance activities within the proper context: guidelines within a broader security program.  No regulatory or industry standards can protect our critical infrastructure or sensitive data.  Only an aware, thinking human who actually cares about security—and understands how standards apply within his or her unique environment—can do that.

Original URL: http://olzak.wordpress.com/2009/08/13/blame-the-auditors/


 PRINTER FRIENDLY VERSION
Learn More
home
Learn More
Request a Meeting
Tell a Friend
About Us
Start the Year with Some Extra Cash!
Customer Appreciation
We announced a customer appreciation giveaway at the beginning of October.

SpartanTec, Inc. is planning a great Gift Card Giveaway for our customers. Have you entered for your chance to win?

Contact your Sales Representative today or email us at Sales@SpartanTec.com or visit our website and request information.

SpartanTec, Inc.'s Firewall Service

SpartanTec, Inc.’s Managed Firewall Service provides proactive administration of your firewall infrastructure. SpartanTec, Inc.’s certified security experts will perform all activities necessary to keep these devices operating at peak performance including....

more»

We Guard Your Assets!
http://www.SpartanTec.com

SpartanTec, Inc. provides IT security solutions across all industries, including Educational, State Government and Commercial organizations.

We welcome your inquires. Contact us via:


Are the budgets shrinking? Has the staff been reduced? Let SpartanTec, Inc. be your partner! With our strategic vendor relationships, we will work hard so that you won’t have to. As your partner, you can expect a reply to your support requests within minutes rather than hours through our monitored email: support@SpartanTec.com.

Expect results from the team at SpartanTec, Inc. as we help ‘Guard Your Assets’.



Powered by IMN