Re: PCI Compliance - Encryption of all non-console administrative access.
- From: pauls2272@xxxxxxxxx
- Date: Tue, 31 Jul 2007 10:14:20 -0700
Excuse me, what company encrypts "anything on disk" ???
Lots of them. I was in a meeting a couple weeks ago about the
security people wanting just that - encrypt "data at rest" in
databases that are already protected by RACF. The fun part is that
many of the fields they want encrypted are keys on the databases...
IMHO "encrypt everything" is kind of euphemism (fiction if you want).
The new mantra of the security folks.
It is simply impossible.
It is also too expensive and not needed, but this is another story.
Well, the big problem comes after you encrypt everything then lose the
key to decrypt. Your backups are useless. I can see companies going
belly up from the new "encrypt everything" philosophy.
.
- References:
- Prev by Date: RE: EMC DMX3-1500 and REFORMAT VTOC
- Next by Date: Re: AutoTune Catalog Messages
- Previous by thread: Re: PCI Compliance - Encryption of all non-console administrative access.
- Next by thread: RE: PCI Compliance - Encryption of all non-console administrative access.
- Index(es):
Relevant Pages
|
|