An Integrated Security Governance Framework for Effective PCI DSS Implementation

نویسندگان

  • Mathew Nicho
  • Hussein Fakhry
  • Charles Haiber
چکیده

This paper analyses relevant IT governance and security frameworks/standards used in IT assurance and security to propose an integrated framework for ensuring effective PCI DSS implementation. Merchants dealing with credit cards have to comply with the Payment Card Industry Data Security Standards (PCI DSS) or face penalties for non-compliance. With more transactions based on credit cards, merchants are finding it costly and increasingly difficult to implement and interpret the PCI standard. One of the top reasons cited for merchants to fail PCI audit, and a leading factor in data theft, is the failure to adequately protect stored cardholder data. Although implementation of the PCI DSS is not a guarantee for perfect protection, effective implementation of the PCI standards can be ensured through the divergence of the PCI standard into wider information security governance to provide a comprehensive overview of information security based not only on security but also security audit and control. The contribution of this paper is the development of an integrated comprehensive security governance framework for ‘information security’ (rather than data protection) incorporating Control Objectives for Information and related Technology (COBIT), Information Technology Infrastructure Library (ITIL) and ISO 27002.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Critical Success Factors in implementing information security governance (Case study: Iranian Central Oil Fields Company)

The oil industry, as one of the main industries of the country, has always faced cyber attacks and security threats. Therefore, the integration of information security in corporate governance is essential and a governance challenge. The integration of information security and corporate governance is called information security governance. In this research, we identified "critical success factor...

متن کامل

Designing an E-Government Model in the Ethical Framework of Good Governance

Background: Good governance within the framework of ethics is active and constructive cooperation between government and citizens, and the key to its success lies in the ethical behavior of the participating powers in political management. The success of e-government requires elements of good governance based on ethics. To realize e-government, we need good ethical governance indicators. Theref...

متن کامل

Meta-analysis of the Supervisory Tasks of the GIO and its Conceptualization in the Framework of the Good Governance

According to the Iranian Legal System, the duty of the GIO is to monitor “the proper conduct of the affairs” and “the proper implementation of Rules” in the administrative agencies of the country. In spite of this legal clarity, ambiguity in the sense of "proper conduct of the affairs" makes ambiguity in the definition of supervisory duties of the GIO. In order to resolve this ambiguity, in thi...

متن کامل

An Optimized Dynamic Process Model of IS Security Governance Implementation

The year 2011 has witnessed a lot of high profiles data breaches despite the availability of IS security and governance controls, frameworks, standards and models for organisations to choose from; and the technical advances made in intrusion prevention and detection. Taking this issue into account the objective of this paper is to identify and analyse the weaknesses in the IS security defences ...

متن کامل

Development of a framework to evaluate service-oriented architecture governance using COBIT approach

Nowadays organizations require an effective governance framework for their service-oriented architecture (SOA) in order to enable them to use a framework to evaluate their current state governance and determine the governance requirements, and then to offer a suitable model for their governance. Various frameworks have been developed to evaluate the SOA governance. In this paper, a brief introd...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • IJISP

دوره 5  شماره 

صفحات  -

تاریخ انتشار 2011