Close
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Applications
    • Applications
    • Cybersecurity
    • IT Management
    • Networking

    Voyence Helps Network Managers Cope with PCI Compliance

    By
    Paula Musich
    -
    September 14, 2007
    Share
    Facebook
    Twitter
    Linkedin

      For merchants and financial institutions, figuring out how to comply with Payment Card Industry Data Security Standard requirements can be a real guessing game.

      Network change and configuration management provider Voyence on Sept. 17 hopes to take the guesswork out of PCI compliance for network operators with its new VoyenceControl PCI Advisor.

      Because the PCI standard gives general guidelines on how to protect customer account data at various points during the payment process, rather than explicit instructions on compliance, its up to network operators to interpret how to apply the standard to their network.

      “There are 12 different areas of the PCI mandate. Ten are related to the network,” said Darren Orzechowski, vice president of worldwide marketing for the Richardson, Texas, company.

      PCI Advisor, the first product in the planned Compliance Advisory Series, takes advantage of VoyenceControls central repository of network equipment configuration data that tracks changes as they are made. The repository includes a built-in compliance engine.

      Read more here about VoyenceControl.

      Embedded in the tool are the actual PCI DSS mandates, which are mapped to relevant network security data. The tool also links associated policies, their definitions and results.

      The PCI Advisor, which is built on top of VoyenceControl, provides, for example, a sample of how to write and apply an access control list for a network device that is compliant with the standard. “[Users] can take our templates, fill in their own variables for their network and add it. Now they have compliance,” said Matt Clark, director of reporting at Voyence.

      To help network engineers maintain compliance with the PCI standard on a day-to-day basis, Voyence built in dashboards and reporting specific to PCI to see what changes have happened and whether and where those changes introduced compliance problems.

      “One thing that PCI is big on is that process has to be written down; the auditor needs to see that and evidence that youre following that process. They want to see as youre doing changes on a daily basis that youre following PCI-compliant processes, and they want documented evidence of that,” said Clark.

      Toward that end VoyenceControl PCI Advisor provides an audit trail of the change control process. “As they go through the quarterly review they can see who submitted a change job, who approved it, when it was approved and so on,” added Clark. It includes check boxes and time stamps for those quarterly reviews.

      But perhaps the biggest time and cost savings element of the PCI Advisor is the Auditors Report, which supplies documentation to the auditor on compliance policies, processes and results.

      “It cuts down the time dramatically that it takes an organization to go out and collect the information to prove they are meeting the requirements. With the Voyence tool its all right there in front of me,” said auditor Barry Johnson, director of risk mitigation at IGX Global, an information security firm in Rocky Hill, Conn.

      Without the Voyence tool, Johnson said he has “had to go to as many as 15 different tools or areas to pull that information together. If all the information is there, then potentially they arent paying for me to be there as long.”

      The PCI Auditor Reports walk the auditor “through the processes, what compliance policies are in place down to the actual line [and] what the actual configurations are on the network devices, and they include reports showing on specific dates what the compliance status of the network was,” said Clark.

      “It spells out which requirements youre meeting and it shows a history so you can [be sure] that youre continuing your compliance efforts during the year. As an auditor, thats something I like to see,” echoed Johnson.

      Voyence also plans to add additional products to the Compliance Advisory Series that focus on such regulations as the Sarbanes-Oxley Act and HIPAA (Health Insurance Portability and Accountability Act).

      The VoyenceControl PCI Advisor is due in November and will start at $30,000.

      Check out eWEEK.coms for the latest news, views and analysis on servers, switches and networking protocols for the enterprise and small businesses.

      Paula Musich
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.

      MOST POPULAR ARTICLES

      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Applications

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      IT Management

      Intuit’s Nhung Ho on AI for the...

      James Maguire - May 13, 2022 0
      I spoke with Nhung Ho, Vice President of AI at Intuit, about adoption of AI in the small and medium-sized business market, and how...
      Read more
      Applications

      Kyndryl’s Nicolas Sekkaki on Handling AI and...

      James Maguire - November 9, 2022 0
      I spoke with Nicolas Sekkaki, Group Practice Leader for Applications, Data and AI at Kyndryl, about how companies can boost both their AI and...
      Read more
      Cloud

      IGEL CEO Jed Ayres on Edge and...

      James Maguire - June 14, 2022 0
      I spoke with Jed Ayres, CEO of IGEL, about the endpoint sector, and an open source OS for the cloud; we also spoke about...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2022 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×