...
首页> 外文期刊>International journal of information security and privacy >An Integrated SecurityGovernance Frameworkfor Effective PCI DSSImplementation
【24h】

An Integrated SecurityGovernance Frameworkfor Effective PCI DSSImplementation

机译:有效实施PCI DSS的集成安全管理框架

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

This paper analyses relevant IT governance and security frameworks/standards used in IT assurance and security to propose an integrated framework for ensuring effective PCI DSS implementation. Merchants dealing with credit cards have to comply with the Payment Card Industry Data Security Standards (PCI DSS) or face penalties for non-compliance. With more transactions based on credit cards, merchants are finding it costly and increasingly difficult to implement and interpret the PCI standard. One of the top reasons cited for merchants to fail PCI audit, and a leading factor in data theft, is the failure to adequately protect stored cardholder data. Although implementation of the PCI DSS is not a guarantee for perfect protection, effective implementation of the PCI standards can be ensured through the divergence of the PCI standard into wider information security governance to provide a comprehensive overview of information security based not only on security but also security audit and control. The contribution of this paper is the development of an integrated comprehensive security governance framework for 'information security' (rather than data protection) incorporating Control Objectives for Information and related Technology (COBIT), Information Technology Infrastructure Library (ITIL) and ISO 27002.
机译:本文分析了在IT保证和安全中使用的相关IT治理和安全框架/标准,以提出一个集成框架,以确保有效实施PCI DSS。使用信用卡的商家必须遵守《支付卡行业数据安全标准》(PCI DSS),否则将面临罚款。随着越来越多的基于信用卡的交易,商家发现实施和解释PCI标准的成本越来越高,并且越来越困难。商户未能通过PCI审核的主要原因之一,也是数据盗窃的主要原因,是未能充分保护存储的持卡人数据。尽管实施PCI DSS并不能保证获得完美的保护,但可以通过将PCI标准分散到更广泛的信息安全治理中来确保PCI标准的有效实施,以不仅基于安全性而且还基于信息安全性提供全面的概述。安全审核和控制。本文的贡献是针对“信息安全”(而非数据保护)的集成综合安全治理框架的开发,该框架整合了信息和相关技术的控制目标(COBIT),信息技术基础设施库(ITIL)和ISO 27002。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号