Commenting on the aftermath of the data breach at an Atlanta-based card transaction process, Avecto says that the possibility that the breach was caused by a compromised administrative account that was insufficiently protected shows that governance is a central requirement of modern IT security.
Paul Kenyon, chief operating officer with the Windows privilege management specialist, says that financial services companies have a duty of care – and in many cases a firm legal obligation – to meet minimum security standards laid down by legislation and several governance organisations. With 1.5 million sets of card credentials going walkabout from the transaction processor’s computers, these standards have not been met, especially on the PCI DSS front.
- Published: 12 April 2012
- Written by NStinchcombe