• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • SkyView Adds PCI Checks to Risk Assessment Tool

    April 14, 2009 Alex Woodie

    SkyView Partners this week will begin delivery of a new release of its SkyView Risk Assessor product that includes new checks for the Payment Cardholder Industry Data Security Standard (PCI DSS) requirements. By comparing a System i shop’s security settings against the PCI standards, the tool can make the difference between the company passing a PCI audit and continuing to process credit card transactions, or failing an audit and paying thousands of dollars in fees–or worse.

    It’s been almost four years since the PCI standards went into effect. Since then, several high-profile cases of mass identify theft, such as the one at TJX, have rocked the retail world and given retailers newfound incentive to get off their duffs and make sure their IT security systems are up to snuff. While some people question whether PCI DSS is the best path to security–several PCI-compliant retailers have been hacked, for example–it remains as the industry’s current best hope for ensuring the security of cardholder data. (Without it, consumers may start to worry about using their credit cards, which would just make the recession even worse.)

    With a decent following among retailers, the System i server has come head to head with PCI requirements at a number of locations. But because the PCI requirements were written from the point of view of a Windows or Unix administrator, it can take a System i administrator some time to get used to the different terminologies. A tool or automated guide can make it easier to get on the road to PCI compliance, and this is what SkyView is aiming to do with the new version of Risk Assessor that ships April 17.

    “A large percentage of our customer base is dealing with PCI requirements,” Carol Woodbury, president of SkyView Partners and the i OS platform’s former security architect while working at IBM, says in a press release. “With this new release of Risk Assessor we’re including PCI ‘considerations’ when we make recommendations on the various security settings.”

    One of the PCI DSS requirements calls for a company to “assure the confidentiality of data,” Woodbury says. This could have an impact in several areas of i OS security, including what security level you have set the QSECURITY setting to, or the use of encryption. After analyzing system settings, Risk Assessor will explain the ramifications of this PCI requirement, and make recommendations on what settings to change to comply with that particular requirement.

    “This sort of documentation will help auditors better understand the IBM i and system administrators to better explain details to the auditors,” Woodbury says. “All in all this will help save everyone’s time in the risk assessment portion of a security audit.”

    SkyView first shipped Risk Assessor back in 2003 as a way to provide iSeries shops with the same kind of security expertise and insight they would obtain with an on-sight assessment by Woodbury, but without incurring the expense of flying, housing, and feeding the renown i OS security expert. Some jokingly called it “Carol in a box.”

    Today, Risk Assessor analyzes more than 100 “risk points” on the i OS system, including object authorities, user profiles, system values, authorization lists, exit programs, and other security settings. Once the information is gathered, the tool generates an analysis (called an “assessment guide”) that tells the user why an issue it found was raised as a security concern, what things should be considered before making any changes, and how a user could approach “fixing” the issues that are found, the company says. These recommendations can be tailored for several “best practice” levels, such as PCI, SOX, or a more stringent custom security policy adopted by a customer.

    The new release of Risk Assessor also brings the capability to e-mail reports and “assessment guides” directly from the System i server. This feature was requested from existing customers, SkyView says.

    “Our goal is to continually improve our products to help our customers cut down the amount of time spent on all the duties that fall under compliance,” Woodbury says. “Performing regular risk assessments is just one of those duties and Risk Assessor is the right tool for that job.”

    RELATED STORIES

    SkyView Updates Policy Minder for i5/OS

    Risk Assessor Aims at Security Audit Survival

    SkyView Taps Mycom to Resell OS/400 Security and Compliance Software

    New SkyView Security Tool Assists with Regulatory Compliance

    SkyView Addresses Compliance with New OS/400 Security Service

    New SkyView Software Assesses OS/400 Security Risks



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    MKS:  FREE white paper: What Do IBM i Developers Want Out of Their ALM Software?
    S4i Systems:  Say YES to DASD-Plus. Disk management starting at $350
    COMMON:  Join us at the 2009 annual meeting and expo, April 26-30, Reno, Nevada

    IT Jungle Store Top Book Picks

    Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
    The iSeries Express Web Implementer's Guide: List Price, $49.95
    The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
    The System i Pocket RPG & RPG IV Guide: List Price, $69.95
    The iSeries Pocket Database Guide: List Price, $59.00
    The iSeries Pocket SQL Guide: List Price, $59.00
    The iSeries Pocket Query Guide: List Price, $49.00
    The iSeries Pocket WebFacing Primer: List Price, $39.00
    Migrating to WebSphere Express for iSeries: List Price, $49.00
    Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
    Getting Started with WebSphere Express for iSeries: List Price, $49.00
    Can the AS/400 Survive IBM?: List Price, $49.00
    Chip Wars: List Price, $29.95

    Vision Solutions Starts Independent User Group in Russia A Bevy of BIFs: Dealing with a Bad Date

    Leave a Reply Cancel reply

Volume 9, Number 15 -- April 14, 2009
THIS ISSUE SPONSORED BY:

Maximum Availability
Help/Systems
Seagull Software
Computer Keyes
Key Information Systems

Table of Contents

  • Fujitsu Introduces RPG to .NET Application Modernization Service
  • LANSA Adds Refinements to BPI Product
  • SkyView Adds PCI Checks to Risk Assessment Tool
  • SPSS Changes Data Miner’s Name, Drops System i Support
  • So Long ASNA–It’s BluePhoenix System i Division From Now On
  • InfoPrint Spreads the Eco-Love with New Laser Printers
  • Ethel Austin’s i OS Implementation Goes Au Naturale
  • PFSweb to Provide Logistics Services for Military Exchange
  • CPU MMS Teams with Gateway EDI for Data Interchange
  • Global Goes After Infor ERP Visual Customers with New Partner

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Big Blue Raises IBM i License Transfer Fees, Other Prices
  • Keep The IBM i Youth Movement Going With More Training, Better Tools
  • Remain Begins Migrating DevOps Tools To VS Code
  • IBM Readies LTO-10 Tape Drives And Libraries
  • IBM i PTF Guide, Volume 27, Number 23
  • SEU’s Fate, An IBM i V8, And The Odds Of A Power13
  • Tandberg Bankruptcy Leaves A Hole In IBM Power Storage
  • RPG Code Generation And The Agentic Future Of IBM i
  • A Bunch Of IBM i-Power Systems Things To Be Aware Of
  • IBM i PTF Guide, Volume 27, Numbers 21 And 22

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle