Skipton Building Society branch office
Skipton deploys LogLogic devices for PCI DSS compliance

Skipton deploys log management kit to ease PCI compliance

Skipton Building Society deploys LogLogic appliances to achieve PCI compliance and improve system security

Written by Dave Bailey

Like many organisations dealing with financial transactions, Skipton Building Society has had to take on board the requirements of the Payment Card Industry Data Security Standards (PCI DSS).

Skipton assistant system security manager Andrew Whitton said that although the building society was already doing some basic log management, the PCI DSS directive pushed it to examine the process in more detail.

“It was a good time to find a solution to meet compliance requirements, as well as to achieve the security our complex IT environment needs,” said Whitton.

As part of that re-evaluation of its IT systems, Skipton decided to implement a new log management system, LogLogic, to improve its oversight of activity across its IT infrastructure – thereby meeting some of the PCI requirements.

After an onsite demo and proof-of-concept initiative, Skipton bought a LogLogic LX1010 appliance to collect events and a LogLogic ST3010 appliance for archiving and storing the log data.

The ST3010 appliance tracks windows events, developer team events and network devices. Skipton's security service provider, Integralis, helped to design and implement about 30 daily PCI DSS compliance reports, and had the system up and running to complete the first audit within one month.

“The ST3010 had about 35TB of storage, more than enough for our needs over 12 months,” said Whitton.

The LX3010 was used to take logs from Skipton’s servers, and since LogLogic is an agent-less system, a major benefit was that Skipton’s IT department did not need to install agents on each server throughout the organisation.

“There are some servers in branch offices, but most are in a single central datacentre,” said Whitton.

The LX3010 was also able to cover Skipton’s network infrastructure without additional development work. “We could interface with Terminal Access Controller Access Control System authentication, and also get LogLogic to talk to our firewalls and pull log data off them,” explained Whitton.

The benefits are easy, fast access to the PCI reports. “It’s difficult to quantify the time we’ve saved, other than to say we simply couldn't do what we’re doing now without LogLogic - there just aren't enough man hours available,” said Whitton.

Additionally, LogLogic’s PCI Compliance Suite has provided Skipton with a variety of automated reports and alerts for monitoring PCI compliance, enabling it to easily implement and enforce PCI best practices and processes society-wide.

The increased visibility into system events gives Skipton the ability to see unusual windows event activity easily – such as unauthorised user logons. This has improved insight into its own systems, and increased its ability to act on these insights.

For the future, Skipton can now focus on setting up and running the system to look at its internal systems security. Although it is currently only running PCI reports, it is looking at expanding reporting to other areas of the business in the future.

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

Co-op branchHardware

Co-op Financial Services upgrades mainframe infrastructure

New equipment will underpin £500m IT change programme 09 Jun 2009

 

National Theatre strengthens its payment security

Theatre company deploys on-demand security system to meet payment card compliance rules 21 Jul 2009

RSA 2009: PCI Security Standards Council

Council's tech chief speaks on current and future online payment programmes 21 Apr 2009

Poor IT forced government hand in Northern Rock takeover

Winding down Northern Rock ruled out because of inadequate IT 20 Mar 2009

PCI Council gives helping hand to merchants

Prioritized Approach framework to help attain PCI DSS compliance 04 Mar 2009

IT overhaul delivers Wellcome benefits

The Wellcome Trust’s Mark Bramwell talks about his efforts to introduce a more business-minded approach to IT management at the UK’s largest charity 12 Feb 2009

Principality Building Society upgrades voice systems

IP-based platform was introduced to better manage customer call volumes 11 Feb 2009

EMC updates Data Domain duplication systems

New offerings aimed at mid-sized enterprises 21 Oct 2009

MobileIron aims to overhaul smartphone management

Virtual Smartphone Platform lowers costs through greater visibility of handsets 18 Mar 2010

related whitepapers

today's top stories

Face facts: social media is the future

No organisation can afford to ignore the way business communications are changing 18 Mar 2010

Is the data watchdog about to pounce?

Experts believe the Information Commissioner’s Office is itching to use its new power to impose hefty fines for data breaches. Martin Courtney reports 18 Mar 2010

Lloyd’s of London gears up for regulation

CIO Peter Hambling tells Angelica Mari about how the insurance market has updated its IT infrastructure to comply with new regulations 18 Mar 2010

Protests greet new Digital Economy Bill amendment

ISPs, digital rights groups and Liberal Democrat supporters cry foul 05 Mar 2010

IT Leaders' Forum in association with IBM

A unique opportunity to hear from expert speakers and engage in a debate about the future of the CIO job function 29 Jan 2010

Advertisement

Keys to successful Service‐Oriented Architecture implementation

This white paper explores best practices and general design patterns for service oriented architecture (SOA).

The Roadmap to IT Maturity — Matching Strategy to Infrastructure for Business Success

This paper defines a roadmap for matching infrastructure strategy to business success.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

NHS centralised data

NHS centralised data

Do you think the NHS can be trusted to safely look after personal data electronically?

View poll results

Latest audio and video articles

Video

HP unveils S Series notebooks

'Prosumer' line overhauled 01 Mar 2010

Web Seminar Listings

Preparing for enterprise-scale Windows 7 migration

The web seminar on 18 Feb will discuss how Windows 7 migration can increase IT efficiency in large enterprises, freeing up budgetary and personnel resources to focus on business innovation. Our panel of experts will examine the strategies, tools and services IT leaders can use to migrate successfully and reap the rewards of increased efficiency. 19 Feb 2010

Latest in-depth articles

Smiths Group CIO Brian JonesAnalysis

Q&A: Brian Jones, CIO, Smiths Group

How should conglomerates be looking at the new IT technologies coming through? Brian Jones explains. 19 Mar 2010

Analysis

What security strategy should enterprises adopt after the recession?

Act now to put your your firm on higher growth path advise CISOs 19 Mar 2010

Primary Navigation