The Texas thing with PCI....

Tuesday, July 24, 2007 1:27:46 AM UTC
by Ray Zadjmool
So it seems that alot of the Accessors are excited about the fact that compulsory compliance is being considered in Texas.

Network Scanning with NMAP

Sunday, July 15, 2007 3:12:23 PM UTC
by Jason Pieters
A brief look at nmap and how to get the most out of it.

Logging - Meaningful or Meaningless?

Saturday, July 14, 2007 2:45:31 PM UTC
by Jason Pittman
Section 10.2 of PCI DSS requires “…implementation of audit trails for all system components”. Sections 10.2.1 through 10.2.7 detail what specific actions need to be covered in the audit trail. Naturally, the first thing that caught my attention here are the System Object requirements, being specifically “creation and deletion of system level objects”. My reaction during both reviewing these specifications and also during implementation of the necessary technical controls has been: how does require logging in this fashion actually help detect an intrusion? Is the PCI DSS approach sound from a business perspective? Is it sound from an applied science perspective?