PCI Compliance and over 360,000 other books are available for Amazon Kindle – Amazon’s new wireless reading device. Learn more

 

or
Sign in to turn on 1-Click ordering.
 
 
Express Checkout with PayPhrase
What's this? | Create PayPhrase
Sorry!
More Buying Choices
25 used & new from $45.94

Have one to sell? Sell yours here
 
   
PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance
 
 
Start reading PCI Compliance on your Kindle in under a minute.

Don’t have a Kindle? Get your Kindle here.
 
  

PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance (Paperback)

~ (Author), Anton Chuvakin Ph.D. Stony Brook University Stony Brook NY. (Author), Tony Bradley (Editor)
Key Phrases: logging access, protect cardholder data, data security standard, You're Compliant, Secure Network, Strong Access Control (more...)
4.0 out of 5 stars  See all reviews (3 customer reviews)

List Price: $59.95
Price: $53.95 & this item ships for FREE with Super Saver Shipping. Details
You Save: $6.00 (10%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Want it delivered Tuesday, November 10? Choose One-Day Shipping at checkout. Details
17 new from $49.79 8 used from $45.94

Formats

Amazon Price New from Used from
  Kindle Edition, June 1, 2007 $33.57 -- --
  Paperback, July 5, 2007 $53.95 $49.79 $45.94

Frequently Bought Together

PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance + Payment Card Industry Data Security Standard Handbook + PCI DSS: A practical guide to implementation
Price For All Three: $175.90

Show availability and shipping details

  • This item: PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance by Branden R. Williams

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • Payment Card Industry Data Security Standard Handbook by Timothy M. Virtue

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • PCI DSS: A practical guide to implementation by Steve Wright

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details


Customers Who Bought This Item Also Bought

Achieving PCI Compliance: Understanding And Complying With The Data Security Standard For Merchant Levels 2, 3 And 4

Achieving PCI Compliance: Understanding And Complying With The Data Security Standard For Merchant Levels 2, 3 And 4

by James M. Barrow
$24.66
PCI DSS: A practical guide to implementation

PCI DSS: A practical guide to implementation

by Steve Wright
$69.95
Security Metrics: Replacing Fear, Uncertainty, and Doubt

Security Metrics: Replacing Fear, Uncertainty, and Doubt

by Andrew Jaquith
4.6 out of 5 stars (20)  $31.49
IT Compliance and Controls: Best Practices for Implementation

IT Compliance and Controls: Best Practices for Implementation

by James J. DeLuccia IV
5.0 out of 5 stars (1)  $40.00
The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws

The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws

by Dafydd Stuttard
4.9 out of 5 stars (15)  $31.50
Explore similar items

Editorial Reviews

Review

"Finally we have a  solid and comprehensive reference for PCI. This book explains in great detail not only how to apply PCI in a practical and cost-effective way, but more importantly why."--Joel Weise, Information Systems Security Association (ISSA) founder and chairman of the ISSA Journal Editorial Advisory Board

--This text refers to an alternate Paperback edition.


Product Description

Identity theft has been steadily rising in recent years, and credit card data is one of the number one targets for identity theft. With a few pieces of key information. Organized crime has made malware development and computer networking attacks more professional and better defenses are necessary to protect against attack. The credit card industry established the PCI Data Security standards to provide a baseline expectancy for how vendors, or any entity that handles credit card transactions or data, should protect data to ensure it is not stolen or compromised. This book will provide the information that you need to understand the PCI Data Security standards and how to effectively implement security on the network infrastructure in order to be compliant with the credit card industry guidelines and protect sensitive and personally identifiable information.

*PCI Data Security standards apply to every company globally that processes or transmits credit card transaction data
*Information with helps to develop and implement an effective security strategy to keep their infrastructure compliant
*The authors are well known and each has an extensive information security background, making them ideal for conveying the information the reader needs

Product Details

  • Paperback: 352 pages
  • Publisher: Syngress (July 6, 2007)
  • Language: English
  • ISBN-10: 1597491659
  • ISBN-13: 978-1597491655
  • Product Dimensions: 9.1 x 7.4 x 1 inches
  • Shipping Weight: 1.3 pounds (View shipping rates and policies)
  • Average Customer Review: 4.0 out of 5 stars  See all reviews (3 customer reviews)
  • Amazon.com Sales Rank: #576,642 in Books (See Bestsellers in Books)

    Popular in this category: (What's this?)

    #8 in  Books > Computers & Internet > Programming > APIs & Operating Environments > PCI Architecture

More About the Authors

Discover books, learn about writers, read author blogs, and more.

Inside This Book (learn more)

What Do Customers Ultimately Buy After Viewing This Item?

PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance
78% buy the item featured on this page:
PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance 4.0 out of 5 stars (3)
$53.95
Payment Card Industry Data Security Standard Handbook
11% buy
Payment Card Industry Data Security Standard Handbook 4.0 out of 5 stars (2)
$52.00
Achieving PCI Compliance: Understanding And Complying With The Data Security Standard For Merchant Levels 2, 3 And 4
4% buy
Achieving PCI Compliance: Understanding And Complying With The Data Security Standard For Merchant Levels 2, 3 And 4
$24.66
PCI DSS: A practical guide to implementation
3% buy
PCI DSS: A practical guide to implementation
$69.95

Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
 
(1)
(1)
(1)

Your tags: Add your first tag
 

 

Customer Reviews

3 Reviews
5 star:
 (2)
4 star:    (0)
3 star:    (0)
2 star:
 (1)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.0 out of 5 stars (3 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
22 of 22 people found the following review helpful:
5.0 out of 5 stars Book Review: PCI Compliance: Implementing Effective PCI Data Security Standards, August 22, 2007
By Andrew Hay "RHCE, Security+, GSEC, GCIA, GCIH... (Fredericton, New Brunswick, Canada) - See all my reviews
(REAL NAME)   
When I first received this book from Syngress I was very excited. I knew nothing about PCI compliance -- other than it was big ticket item and everyone processing Visa transactions was affected in some way because of it. I can honestly say that I tore through this book and didn't put it down until I reached chapter 13. I was completely wrapped up in it as it was something I knew nothing about and wanted to know more!

Chapters 1 through 3 introduce you to the concepts behind PCI compliance including what it is and who needs to comply. These chapters really set the stage for what the rest of the book has to offer the reader.

Chapter 4 provides a technology overview of firewalls, intrusion systems, antivirus solutions, and common system default settings. Personally I felt that Chapter 4 was filler content just to add a chapter. It may, however, serve as a good reference for those in management roles who do not have "hands-on" interaction with the architecture of their environment.

Chapter 5 explains how to go about protecting your cardholder data as dictated by PCI requirements 3 & 4. This is a great chapter for anyone new to securing infrastructure to meet the requirements of a PCI audit. The authors also provide a fantastic section entitled "The Absolute Essentials" which offers suggestions on the minimum protection you can employ to protect your cardholder data.

Chapter 6 was by far my most favorite chapter and Syngress has offered it as a free download from their website. Many of you know what I do for a living and know how important understanding logging and requirements for logging is for my day-to-day duties. This chapter focuses around PCI Requirement 10 which details how you must handle the log data collected in your PCI environment. As soon as I started reading this chapter I knew that Dr. Anton Chuvakin had written this section of the book, or at least had a heavy insight into its direction. This chapter alone makes the book worth its weight in gold.

Chapter 7 details the importance of access control in your PCI environment. For obvious reasons, access to your cardholder data must be recorded and checked with a fine tooth comb. User privileges, authentication, authorization, and user education is also covered in this chapter. This chapter goes further to provide examples of ensuring your Windows, Unix/Linux, and Cisco infrastructure meet PCI requirements.

Chapter 8 explains how to leverage vulnerability management solutions to meet the requirements outlined in sections 5, 6, and 11 of the PCI requirement. The authors also provide two very good case studies to help the reader put things into perspective.

Chapter 9 focusses on the monitoring and testing of your environment. The authors are quick to point out that monitoring and testing must continue even after the audit in order to ensure you remain compliant.

Chapter 10 details how to drive your PCI project from the business side in order to ensure you accomplish your objectives. Suggestions are provided on budgeting time and resources, keeping staff in the loop, and justifying the business case to your executive team. The authors also offer a step-by-step "checklist" for ensuring your project runs smoothly and that all of your bases are covered.

Chapter 11 explains the various responsibilities within the organization for ensuring the PCI project succeeds. One of the key things to take away from this chapter is the role of the Incident Response team and its need to understand the requirements of PCI compliance.

Chapter 12 is a really good "eye-opener" that prepares you for the failure of your first audit. The key thing to take away from this is chapter is to not blame the auditor the same way you shouldn't blame a referee in sports. They're simply there to do their job to the best of their ability. If you have a problem with the way they are doing their job, bring it up with their superior. Perhaps their decision will get overturned?

Chapter 13 brings you into a "OK, now what?" phase. This chapter provides a detailed overview of the various requirements and breaks each requirement into "Policy Checks" and "Hands-on Assessments" sections. The policy checks discuss policies that should be reviewed to verify that they are up-to-date and the hands-on assessments sections give ideas on testing these policies. The beauty part is that the authors suggest open source solutions to help you protect your PCI compliant investment.

I give this book 5 stars as it is the best PCI reference I have found on the market. Everything I found in this book will allow me to understand the compliance requirements of my existing customers, their process, and their overall goals. Hats off to the entire team of authors.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
7 of 7 people found the following review helpful:
5.0 out of 5 stars Great book for one of the most sensible security standards ever, August 27, 2007
It has long been rumored that manufacturers of items such as razors and batteries specifically produce their products an inferior level in order to ensure repeat business. A similar paradox is occurring in the information security space where many are complaining that the PCI Data Security Standard (PCI DSS) is too complex and costly. What is most troubling is that such opinions are being written in periodicals and by people that should know better.

PCI came to life when Visa, MasterCard, American Express, Diner's Club, Discover, and JCB collaborated to create a new set of standards to deal with credit card fraud. PCI requires that all merchants and service providers that handle, transmit, store or process information concerning any of these cards, or related card data, be required to be compliant with the PCI DSS. If they are not compliant, they can face monetary penalties and/or have their card processing privileges terminated by the credit card issuers.

The primary purpose of PCI is to force organizations to embrace common security controls to protect credit card data and reduce fraud and theft. The following are the six primary control areas and 12 specific requirements of the PCI DSS:
Build and maintain a secure network
1. Install and maintain firewall configurations
2. Do not use vendor-supplied or default passwords

Protect cardholder data
3. Protect stored data
4. Encrypt transmissions of cardholder data across public networks

Maintain a vulnerability management program
5. Use and regularly update anti-virus software
6. Develop and maintain secure systems and applications


Implement Strong Access Control Measures
7. Restrict access to need-to-know
8. Assign unique IDs to each person with computer access
9. Restrict physical access to cardholder data

Regularly monitor and test networks
10. Monitor and track all access to network resources and cardholder data
11. Regularly test security systems and processes

Maintain an information security policy
12. Maintain a policy that addresses information security

A quick review of these 12 items shows that PCI is a textbook example of the fundamentals of information security. With that, PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance is an excellent resource that provides the reader with all of the fundamental information needed to understand and implement PCI DSS.

The books 13 chapters provide the reader with a comprehensive overview of all of the details and requirements of PCI. The first three chapters provide an overview of the basics about PCI and the basic requirements of the standard. The following six chapters go into detail about each of the primary control areas.

In particular, chapter 6 provides a good overview of the PCI logging requirements. This requirement can be time-consuming to put into place. The author notes that a commonly overlooked but essential requirement, namely that of accurate and synchronized time on network devices. Enterprise information network and security infrastructure devices are highly dependent on synchronized time and PCI recognizes that correct time is critical for transactions across a network.

In a further discussion about synchronized time in chapter 9, the author unfortunately makes an error when he states that local hardware is considered a stratum 1 time source since it gets its time from its own CMOS. From an NTP perspective, only a device that is directly linked to a stratum-0 device is called a stratum-1. CMOS clocks are notoriously inaccurate and can't be relied upon.

The title of chapter 12 is both amusing and accurate `Planning to fail your first Audit'. The irony is that so many organizations lack a CISO or formal business security program in place designed to protect corporate information assets. They don't focus on information security as a process, rather as a set of products or regulatory items to be checked-off. Yet, these same organizations are surprised when they fail an audit.

The book concludes in chapter 13 with the well-known observation that security is a process, not an event. The book astutely notes that it is impossible to be PCI compliant without approaching security as a process. Trying to achieve compliance without integrating the various aspects in an integrated fashion is bound to fail.

Overall, PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance is a great book for one of the most sensible security standards ever. Anyone who has PCI responsibilities or wants to gain a quick understanding of the PCI DSS requirements will find the book to be quite valuable.


Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
0 of 3 people found the following review helpful:
2.0 out of 5 stars Don't waste your time, August 5, 2008
By Joshua Davies (Dallas, TX United States) - See all my reviews
(REAL NAME)      
I can't decide if this book was more of a waste of time, or a waste of money - but either way, I wish I hadn't spent either. For the most part, it just rehashes the publicly available PCI specification. Although there are a few tidbits of wisdom tucked away in there (for example, raise security alerts both through e-mail as well as a pager system in case an attacker has also compromised e-mail), the other 99% of the book was just space filler. Some of the advice included such earth-shattering suggestions as "use Microsoft project to track a project" and "have team meetings". It looks to me as though what should have been somebody's one-page blog entry was turned into a 300+ page book.
Comment Comment (1) | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Only search this product's reviews



Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   



So You'd Like to...


Product Information from the Amapedia Community

Beta (What's this?)


Look for Similar Items by Category


Look for Similar Items by Subject

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Your Recent History

 (What's this?)

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.