ITIL Certified Products are No Magic Bullet

July 21, 2009 by ADMIN · 1 Comment

By Michael Lohr, Sales Engineering Team Manager for Tripwire

Companies buy these so called certified products thinking they have the magic bullet to solve their ITIL project, and they’ll skip the hard part, which is designing the processes for their organization. So instead of a magic bullet they’ll just shoot themselves in the foot with a real bullet.

Who’s to Blame When PCI Security Fails?

July 14, 2009 by ADMIN · 2 Comments

By Ed Rarick, PCI Evangelist at Tripwire

Auditors definitely need to be more exacting and tougher when evaluating a company’s adherence to the specification. But an audit is a point-in-time event that says “as of today” your security level and change and control processes are at an acceptable state.

PCI DSS Legitimizes Conflicts of Interest

July 11, 2009 by ADMIN · Leave a Comment

By Rachel James, Author and Cybercrime Authority at ID Experts

The rules and requirements for auditors reveal a number of potential conflicts of interest that could arise between an auditor and the entity it’s assessing. For example, many security auditors also make security products. The rules state that a security company will not use its status as auditor to market its products to companies it audits, but if the auditor should happen to find that the client would benefit from its product, it must also tell the client about competing products.