Solidcore Systems, Inc., a leading provider of real-time change control software, has introduced the S3 Control PCI Pro and PCI Starter Editions designed to help merchants of all sizes easily and cost-effectively address the file integrity monitoring and audit trail requirements outlined in sections 10 and 11 of the Payment Card Industry Data Security Standard (PCI-DSS). In addition, the world's leading qualified security assessors (QSAs) are certifying and recommending the new solutions as an essential element of a comprehensive PCI compliance strategy.
Achieving PCI-DSS compliance requires merchants and service providers to address approximately 180 individual requirements in 12 categories. However, categories 10 and 11 of the PCI-DSS, which specify the use of file integrity monitoring and change detection software, have proven to be the most difficult to fulfill and least satisfied, according to recent research. These requirements have been difficult to satisfy because existing tools have merely provided "periodic" file integrity monitoring capabilities that would detect changes through resource-intensive system scans. The Solidcore S3 Control PCI Pro and PCI Starter Editions solve this for customers with "continuous" file integrity monitoring capabilities that have a minimal impact on system resources, and eliminate the need to perform repeated scan after scan.
"Adhering to the PCI standard is a priority for protecting our business and customer data," said Bobby Wen, manager of IT operations for Restoration Hardware. "Working with our QSA helped us get Solidcore approved as one of our key controls for PCI compliance. Solidcore is now helping free us from our old file-scanning and manual reporting procedures to help us meet the file monitoring and change control requirements of PCI."
"We had multiple people from different groups manipulating and changing files on 10 to 15 critical servers, and our lack of detailed visibility of this could have compromised the integrity and compliance of our entire IT environment," said Keith Spahn, systems administrator for the Clerk of the Circuit Court in Sarasota, Florida. "Solidcore's PCI Pro gives us a quick and simple way to audit our critical systems and files and allows me to quickly identify exceptions and violations on specific servers, or those across our entire IT environment."
PCI Pro Edition for Enterprises and Service Providers
The Solidcore S3 Control PCI Pro Edition is designed to help enterprises and service providers quickly, easily and cost-effectively address the database and network device audit trail requirements specified by PCI-DSS category 10, as well as the continuous file integrity monitoring requirements specified by PCI-DSS category 11. The PCI Pro Edition captures all changes to files, allowing administrators to quickly see where compliance policies are being challenged. The solution identifies and alerts on transient violations, such as when a file is changed inappropriately and then changed back, and also captures specific details about every change including the exact time of the change. The product provides out-of-the-box PCI reports to demonstrate compliance to auditors with minimal effort, thus reducing the cost of PCI compliance verification.
PCI Starter Edition for Small and Medium Businesses
The Solidcore S3 Control PCI Starter Edition is a stand-alone, continuous file integrity monitoring solution for small and medium businesses (SMB). The PCI Starter Edition captures all changes to files on Windows servers in real-time, allowing administrators to quickly see where compliance policies are being challenged. Similar to the PCI Pro Edition, the PCI Starter Edition identifies and alerts on transient violations, captures all of the specific details about each change, and provides out-of-the-box PCI reports that demonstrate compliance to auditors with minimal effort.
"Addressing the file integrity monitoring requirements of PCI is a starting point on the path to better IT operations," said Ronni Colville, research vice president for Gartner. "An investment in robust change and configuration auditing can yield benefits across the IT environment by ensuring appropriate changes are implemented, while also concurrently addressing the monitoring and audit trail requirements specified by regulatory standards such as PCI and SOX."
"We are pleased to be certified by leading qualified security assessors for providing continuous file integrity monitoring," said Rosen Sharma, president and CEO of Solidcore. "These new PCI offerings will enable more merchants worldwide to quickly and easily meet the file integrity monitoring requirements of the PCI standard, and ultimately provide them an path for achieving greater long-term IT control benefits."
Pricing and Availability
PCI Pro Edition--The Solidcore S3 Control PCI Pro Edition is available today through Solidcore via an annual subscription that minimizes first-year compliance costs. Yearly subscription pricing starts at $50 per-server, plus $5,000 for the accompanying central console. The product supports an unlimited number of Windows, Linux, Unix, and AS/400/iSeries/System i servers, most common database platforms and more than 300 network devices. Phone-assisted installation, Web-based support and ongoing product updates are included, and the product is upgradeable to Solidcore's S3 Control Enterprise Edition product for more comprehensive change control and IT operational benefits.
PCI Starter Edition--The Solidcore S3 Control PCI Starter Edition is also available today through Solidcore via an annual subscription. The yearly subscription pricing is $25 per-server, plus $2,500 for the accompanying central console. The PCI Starter Edition supports up to 50 Windows servers, and the product includes Web-based support and ongoing product updates.
About Solidcore Systems
Solidcore is a leading provider of real-time change control software. Organizations worldwide trust Solidcore to assure compliance with the Payment Card Industry (PCI) and Sarbanes-Oxley (SOX) standards, to improve service availability, and achieve faster returns on ITIL and IT service management initiatives. Solidcore's S3 Control software helps organizations by tracking changes to their critical infrastructure in real-time, determining if the changes are authorized, and enforcing change policy by selectively preventing unauthorized change. Solidcore is headquartered in Cupertino, California. For more information, visit http://www.solidcore.com/.
LATEST COMMENTS
MC Press Online