PDA

View Full Version : PCI DSS Antivirus Replacement


PCI_TheOtherWhiteMeat
03-09-2009, 12:46 PM
Is this a true statement for a compensating control? I talked to solid core today and they stated this could also be a compensating control for antivirus and patching all together. I have 200 stores that need to be patched every month would this product or another product from their lineup take care for the need for the patching requirement all together? This question has been receiving some grey area responses I just want a clear answer.
Thanks

http://solidcore.com/solutions/security/windows-nt.html
Reduced costs
No need to test or deploy patches
Elimination of need for system Anti-Virus
Reduced breakage of devices due to bad or poorly tested patches

http://solidcore.com/solutions/compliance/pci-dss-antivirus.html
PCI DSS Antivirus Replacement
with Whitelisting
The Solidcore POS Check and Control solution provides dynamic whitelisting capabilities that deliver comprehensive endpoint security with low overhead, eliminating the need for anti-virus. The dynamic whitelisting capabilities of POS Check and Control ensures only good software and code can run on POS systems while permitting software updates from authorized sources. Solidcore accommodates authorized updates without relying on access to a centralized inventory - making it ideal for retail store environments.

Solidcore prevents disk tampering and provides advanced memory protection to authorized software to defend against buffer overflow vulnerability attacks and zero-day exploits. Merchants can also use Solidcore's POS Check and Control to quickly validate field-deployed POS images against a gold image standard.

Solidcore is a recommended solution by leading Qualified Security Assessors (QSAs).

partpricer
03-09-2009, 02:20 PM
I have no idea. It sounds like snakeoil, but I'm willing to listen to arguments.

Here is a link to their whitepaper on this that was written by a QSA.
http://www.solidcore.com/assets/PCI-DSS-Antivirus-PSC.pdf

derra
03-10-2009, 01:26 AM
There are some similar products for that kind of whitelistening and ofc if it is done right with the whitelistening this will fulfil as a compensatind control for
antivirus.

For the patch am not that convinced since there is always some memory-type attack that could be possible even though the theproducts "say" they protects against it.

Another great tool I have tried and used with great success in PCI DSS compliance work on specific systems is CIS from SE46, www.se46.com.

PCI_TheOtherWhiteMeat
03-11-2009, 12:15 PM
I just submited our request to IBM (our auditors) about solidcore for patching and antivirus. Guess ill find out thanks for the suggestions.