Novell announced a significant enhancement to its security and information event management solution, Novell Sentinel, that will help retailers meet the detailed requirements of the Payment Card Industry Data Security Standard (PCI-DSS). Millions of cases of identity theft and data breaches, including high-profile cases with large amounts of payment card data stolen or compromised, have fueled an urgent industry-wide movement to tighten payment card data security. In response, the leading payment card companies worked together to develop PCI-DSS.
The Novell PCI Solution enables retailers to easily demonstrate compliance with PCI-DSS and is the industry's most effective solution for automation, validation and end-to-end management of the PCI process. Developed specifically to address the needs of merchants challenged with meeting PCI-DSS requirements, the Novell Sentinel PCI Solution contains powerful collection and monitoring tools to implement and enforce compliance programs quickly and cost-effectively.
"Proving compliance with the more than 160 specific requirements of PCI-DSS creates obvious new challenges for IT departments," stated Sally Hudson, research director, Security Products and Services of IDC. "Few organizations have the infrastructure and resources in place to achieve compliance with these far-reaching requirements quickly. And with continual deadlines and increasing enforcement, it makes sense for enterprises to adopt a carefully planned strategic approach to data security that addresses compliance issues, automates PCI-DSS requirements and enhances other IT and end-user operations."
This standard requires any retailer that handles, transmits or stores payment card data to meet a stringent set of data security requirements to stay in compliance with their payment card company contracts. Millions of cases of identity theft have fueled an urgent movement to tighten payment card data security standards, and the payment card industry has responded. To address this issue, the leading payment card companies have worked together to develop a strict new Payment Card Industry Data Security Standard (PCI-DSS).
The Novell Sentinel PCI Solution features the real-time information and monitoring capabilities of Novell Sentinel, as well as robust collectors, connectors, reports, correlation rules and workflows engineered specifically to help enterprises meet the requirements of the standard, automate the PCI process, and demonstrate the enforcement of PCI controls to auditors.
The Novell Sentinel PCI Solution is the most recent addition to Novell's portfolio of identity and security management solutions. A significant enhancement to Novell Sentinel, the PCI Solution integrates with Novell Identity Manager and Novell Access Manager, giving enterprises a holistic view of the policies, people and processes in their compliance environment.
The PCI Solution features:
- Technology to ensure PCI-DSS control objectives are being met - The Novell PCI Solution is the only solution to ensure automated controls are tied back to specific relevant regulations and manual processes are documented to prove those regulations are tested and implemented.
- Advanced content to streamline the compliance process - The offering includes all content required to implement an end-to-end PCI compliance solution, including more than 25 reports, 15 correlations rules and other features of Novell Sentinel, such as iTRAC graphical workflows, in-memory correlations with dynamic lists, and data enrichment with business relevance.
- Automated reports - Management of the complete solution is simple, graphical, and fully audited to allow easy demonstration of compliance reports.
- Customization for PCI evolution - New tools help enterprises adapt and quickly implement new controls and processes to meet the continually evolving PCI-DSS standards. The Sentinel Solution Manager is a new interface designed to install and manage the Novell Sentinel PCI Solution.
- Partner tools for easy implementation - A separate interface allows partners to design customized solutions that focus on repeatability, thus minimizing the amount of consulting work needed to implement the solution.