BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

3 Reasons POS Should Give A DAM

Posted August 1, 2011    Peter McCalister

Just when you thought we exceeded our TLA (three letter acronym) quota for the year, up pops this idea for a blog based on a recent discussion with a national retailer, and I couldn’t resist the play on acronyms and the potential for multiple interpretations. But don’t let the TLAs scare you. This is actually a serious topic that does effect any of you who are responsible for compliance across remote sales locations.
If you haven’t figured out the TLAs for todays’s discussion, then don’t feel lost, as I can think of about five variations on each. For today’s purpose though:
POS stands for Point of Sale and refers to systems that handle local sales transactions and report back to corporate for accounting and audit purposes

DAM stands for Database Activity Monitoring and refers to the security software responsible for monitoring those transactions to ensure compliance as well as assist with security
Most POS projects involve backoffice applications specific to the type of retail organization you are (i.e. grocery vs clothing, vs consumer goods, vs whatever you sell in a physically remote location). These apps typically run on SQL Server or some other database like Oracle or IBM DB2. If you only have one or two stores, then DAM may be overkill but if you have 50+ stores then you will find it is mandatory for compliance purposes.

Any good DAM solution is going to be able to configure audit sources and set up notifications for events. Audit policies and rules define conditions for activity and exceptions. Collection and publishing schedules facilitate processes to monitor activity and status. A strong console administration and various report packs also facilitate easier and faster deployment for immediate discovery and reporting of compliance issues especially with exporting and scheduling report distribution.

So, back to the title of today’s blog; What are the 3 reasons POS should give a DAM?
PCI DSS compliance or for those of you tired of acronyms, Payment Card Industry Data Security Standards compliance. This is the primary regulation all retailers need to be most mindful of as it sets the requirements for transaction data integrity and privacy.

Remediation for any security breach that may inadvertently occur at the database level of your POS. Know exactly who did what, when and where will allow your security teams to handle the situations that present themselves.

Business intelligence on what types of database admin activities are occuring at specific POS sites relative to other locations.

Leave a Reply

Additional articles

Integrating Least Privilege and Password Management to Solve Account Security Challenges

Integrating Least Privilege and Password Management to Solve Account Security Challenges

Posted July 24, 2014    Morey Haber

There is a reason all BeyondTrust Privileged Account Management (PAM) solutions share the PowerBroker name: They all inherently enable you to reduce user-based risk and can be integrated under a centralized IT risk management platform. Here’s one common use case that demonstrates how this integration changes the playing field. Consider the challenge of privileged access:…

Tags:
, , , , ,
PowerBroker Password Safe Password Age Report

Reshaping Privileged Password Management with Password Safe 5.2

Posted July 21, 2014    Martin Cannard

Today, we’re pleased to unveil the latest edition of our privileged password management solution, PowerBroker Password Safe. I’ll start with a brief intro of what’s new and then tell you a little about the driving factors behind Password Safe development. New features for mitigating password risk and ensuring accountability enterprise-wide Here’s the 10,000-foot overview of…

Tags:
, , ,
PowerBroker for Windows tamper protection

PowerBroker for Windows 6.6 Tamper Protection

Posted July 18, 2014    Morey Haber

I have a bone to pick: Stopping an administrator from performing an action on a system is futile endeavor. As an administrator, there is always a way to circumvent a solution’s from tampered protection. Really! By default, Windows administrators have unrestricted access to the system – and even though an application, hardened configuration, or group policy…

Tags:
, ,