Talk With an Expert

Home Field Advantage - Using Indicators of Compromise to Hunt down the Advanced Persistent Threat

Home Field Advantage - Using Indicators of Compromise to Hunt down the Advanced Persistent Threat (PDF, 2.83MB)Published: 25 Sep, 2014
Created by
SANS Institute
SANS Institute

The PCI Data Security Standard requires organizations to determine the scope of their compliance obligation accurately. A critical aspect of PCI DSS scope definition is identifying all the locations where cardholder data is stored. During the course of an assessment, PCI Assessors must validate that the perceived compliance scope is in fact accurately defined and documented. Automated discovery tools, while effective to find cardholder data, sometimes are not an option due to the negative impact they may have in a production environment. In this paper, the author discusses audit techniques and tips on how to find cardholder data without using automated tools.

Meet the expert

SANS Institute
SANS Institute

SANS Institute

Launched in 1989 as a cooperative for information security thought leadership, it is SANS’ ongoing mission to empower cyber security professionals with the practical skills and knowledge they need to make our world a safer place.

Read more about SANS Institute