SlideShare a Scribd company logo
Executive Alliance, Inc.
October 16, 2008
New York, New York
ISE UK and Ireland
Summit and Awards
NOMINEE SHOWCASE
PRESENTATION
October 22, 2008
London, United Kingdom
by
ISE Northeast 2008 Executive Alliance, Inc.ISE UK and Ireland 2008 Executive Alliance, Inc. 2
Vladimir Jirasek
Information Security & Compliance manage
DSG International plc
Vulnerability scanning for PCI
DSS compliance and risk
management
ISE Northeast 2008 Executive Alliance, Inc.
Today’s Discussion Points
• About DSG International
• PCI DSS programme and beyond compliance
• Vulnerability scanning project
• Lessons learned
ISE UK and Ireland 2008 Executive Alliance, Inc. 3
ISE Northeast 2008ISE UK and Ireland 2008 Executive Alliance, Inc. 4
DSG International plc
• Major electrical and computing retailer in Europe with
both traditional stores and Web store
• We own brads like Currys, PC World, Pixmania, The
TechGuys, PC City, Electroworld, Elkjop
• No 1 in the UK
• Head office in Hemel Hempsted, UK
• 40,000 employees in the Group
• Annual revenue over £6b
• Processes large amounts of customer data
ISE Northeast 2008 Executive Alliance, Inc.
PCI DSS is good but ...
• Why good? The first standard that retailers take
seriously
• But scope is/can be limited
• DSGi started work on PCI DSS in 2007 with
most of the projects kicked off
• Requirement 11.2 handled by this project
• Limited budget
• Although the scope is limited the approach was
to take risk based approach
ISE UK and Ireland 2008 Executive Alliance, Inc. 5
ISE Northeast 2008 Executive Alliance, Inc.
Requirements
• Compliant with 11.2, i.e. ASV
• Whole group in the scope (regardless of the PCI
DSS scope)
• Minimal operational overhead
• Potential to satisfy other requirements
• Easy to use
• Fit for distributed IT teams in the Group
ISE UK and Ireland 2008 Executive Alliance, Inc. 6
ISE Northeast 2008 Executive Alliance, Inc.
Goals
• Develop patching and vulnerability scanning
policy
• Quick win - find the state of DSGi network
(external then internal)
• Deliver first “PASS” PCI DSS scans
• Make this activity BAU for IT teams
ISE UK and Ireland 2008 Executive Alliance, Inc. 7
ISE Northeast 2008 Executive Alliance, Inc.ISE UK and Ireland 2008 Executive Alliance, Inc. 8
Challenges
• Distributed IT teams
• No standardised patching policy
• Limited budget and overstretched IT resources
in most countries
• Missing risk assessment in IT patching
• Scepticism and wary of vulnerability scanning
ISE Northeast 2008 Executive Alliance, Inc.Executive Alliance, Inc. 9
Project team
ISE UK and Ireland 2008
Accountable and project lead:
Vladimir Jirasek - DSGi Information security manager
Team members:
Matt Leggett - Security project manager (UK)
Stelios Kavalaris - Security admin (Greece)
Samy Elmalki - Network admin (France)
Ana Maria Munoz Ponce - System admin (Spain)
Lars-Andre Johannessen - System manager (Nordic group)
Oyvind Gulikstad - Security manager (Nordic group)
Paolo Asioli - Security manager (Italy)
Ed Brown - Systems manager (UK, Techguys)
Michael Braid - Systems admins (UK, DSGi Business)
ISE Northeast 2008 Executive Alliance, Inc.ISE UK and Ireland 2008 Executive Alliance, Inc. 10
Overcoming challenges
• Responsibility for “clean” scans transferred to
business units IT managers
• Group wide standardised patching policy agreed
• Limited budget addressed by using Software as a
service model
• Qualys service is easy to use and understood by IT
teams. Virtually no training required
• Business units in Qualys made group wide rollout
easy to manage
• Testing of impact of scanning to existing IT systems
ISE Northeast 2008 Executive Alliance, Inc.
Risk based approach
Internet
Internal network
Head office
DMZ
mainframe
eBusiness VPN GW
acquirer
setlement
Store network
ISE Northeast 2008 Executive Alliance, Inc.
Risk based approach (cont)
ISE UK and Ireland 2008 Executive Alliance, Inc. 14
Critical
Important
High
Medium
Low
5 24 hours 5 days 14 days 20 days 40 days
4 5 days 10 days 20 days 1 month 2 months
3 10 days 20 days 1 month 2 months 3 months
2 6 months* Next
release*
Next
release
Next
release
No fix
1 no fix* no fix* no fix no fix No fix
ISE Northeast 2008 Executive Alliance, Inc.
Project results
Patching policy agreed buy IT teams
Weekly vulnerability scans carried on all external
and critical internal assets - 14 internal
appliances in 7 business units
80% of security issues fixed across the group
within first 3 months
Qualys accepted by IT teams as a “good” tool for
highlighting security issues
Scanning is now BAU activity
13
ISE Northeast 2008 Executive Alliance, Inc.
Conclusion
• Looked beyond PCI DSS and adopted risk
based approach (now compliant with v 1.2)
• Each IT team is a separate business unit
• Responsibility for scanning and fixing transferred
to IT managers
ISE UK and Ireland 2008 Executive Alliance, Inc. 15
ISE Northeast 2008 Executive Alliance, Inc.
Thank You!
• Questions?
• Contact Info:
• Vladimir.jirasek@dgiplc.com or Vladimir@Jirasek.eu
• +447959040187
ISE UK and Ireland 2008 Executive Alliance, Inc. 16

More Related Content

PPT
Qualys Webex 24 June 2008
PPTX
Alert Logic - Corporate Overview
PPTX
David Slater G-Cloud Meet Up
PPTX
Jack Nichelson - Information Security Metrics - Practical Security Metrics
PDF
Ofer Maor - Security Automation in the SDLC - Real World Cases
PDF
collateral_datasheet_sungard
PPTX
Building an AppSec Team Extended Cut
PPTX
Sam Herath - Six Critical Criteria for Cloud Workload Security
Qualys Webex 24 June 2008
Alert Logic - Corporate Overview
David Slater G-Cloud Meet Up
Jack Nichelson - Information Security Metrics - Practical Security Metrics
Ofer Maor - Security Automation in the SDLC - Real World Cases
collateral_datasheet_sungard
Building an AppSec Team Extended Cut
Sam Herath - Six Critical Criteria for Cloud Workload Security

What's hot (20)

PPTX
Timothy Wright & Stephen Halwes - Finding the Needle in the Hardware – Identi...
PPTX
21.06.2017 - KYOS Breakfast Event
PDF
Ken Czekaj & Robert Wright - Leveraging APM NPM Solutions to Compliment Cyber...
PPTX
Making Smart Telecom & Network Choices: 8 Reasons Business Customers Partner ...
PDF
Benefits of an Managed Service Provider
PPTX
Solutions For PCI Compliance
PDF
Cybersecurity - Simple, Sustainable, Secure
PPSX
Robert Brzezinski - Office 365 Security & Compliance: Cloudy Collaboration......
PPTX
Time Traveling: Adapting Techniques from the Future to Improve Reliability, J...
PPTX
Introduction Sebyde BV | Security Testing | Security Awareness | Secure Devel...
PPTX
Computer Forensics – What You Don’t Know Can Cost You
PPSX
PPT
Security Outsourcing - Couples Counseling - Atif Ghauri
PPT
Managed Services Presentation
PDF
Hotels, Hookups and Video Conferencing: A Top 10 Countdown to 2020's Worst Da...
PPTX
Simplifying Security Management in the Virtual Data Center
PDF
Invea - Jiri Tobola
PPTX
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
PPTX
Managed Services Presentation
PDF
Security Risks: The Threat is Real
Timothy Wright & Stephen Halwes - Finding the Needle in the Hardware – Identi...
21.06.2017 - KYOS Breakfast Event
Ken Czekaj & Robert Wright - Leveraging APM NPM Solutions to Compliment Cyber...
Making Smart Telecom & Network Choices: 8 Reasons Business Customers Partner ...
Benefits of an Managed Service Provider
Solutions For PCI Compliance
Cybersecurity - Simple, Sustainable, Secure
Robert Brzezinski - Office 365 Security & Compliance: Cloudy Collaboration......
Time Traveling: Adapting Techniques from the Future to Improve Reliability, J...
Introduction Sebyde BV | Security Testing | Security Awareness | Secure Devel...
Computer Forensics – What You Don’t Know Can Cost You
Security Outsourcing - Couples Counseling - Atif Ghauri
Managed Services Presentation
Hotels, Hookups and Video Conferencing: A Top 10 Countdown to 2020's Worst Da...
Simplifying Security Management in the Virtual Data Center
Invea - Jiri Tobola
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
Managed Services Presentation
Security Risks: The Threat is Real
Ad

Similar to ISE UK&Ireland 2008 Showcase Nominee Presentation Vladimir Jirasek (20)

PDF
Max IT4IT webinar powerpoint
PPTX
Cisco systems architecture
PPTX
Real-Time Visibility into High Speed Networks
PDF
Enabling Digital Transformation with Alcatel-Lucent Enterprise’s Network-as-a...
DOC
Adarsh Resume ISO27001
PDF
IoT Security Assessment - IEEE PAR Proposal
PPT
Organization Wide Performance Methodology (ITIL)
PPTX
GadellNet Company Overview
PDF
Helping SME’S to face cybersecurity threats
PDF
easySERVICE Data Solutions Company Capabilities
PDF
Revolutionising Testing with the Power of AI - Deepa Mamtani, Pillay Almira &...
PDF
How Facility Controls Systems Present Cybersecurity Challenges - OSIsoft
PPTX
Anti Hack Solution
PPTX
It assessment case study
PPTX
Bill curtis Beyond process - a challenge for SEPGs
PPTX
Cloud Computing Gets Put to the Test
PPTX
Who are Data Edge?
PPTX
Systems Management 2.0: How to Gain Control of Unruly & Distributed Networks
PDF
Making AIOps-Driven Network Performance Management a Reality
PPTX
What is the UK Cyber Essentials scheme?
Max IT4IT webinar powerpoint
Cisco systems architecture
Real-Time Visibility into High Speed Networks
Enabling Digital Transformation with Alcatel-Lucent Enterprise’s Network-as-a...
Adarsh Resume ISO27001
IoT Security Assessment - IEEE PAR Proposal
Organization Wide Performance Methodology (ITIL)
GadellNet Company Overview
Helping SME’S to face cybersecurity threats
easySERVICE Data Solutions Company Capabilities
Revolutionising Testing with the Power of AI - Deepa Mamtani, Pillay Almira &...
How Facility Controls Systems Present Cybersecurity Challenges - OSIsoft
Anti Hack Solution
It assessment case study
Bill curtis Beyond process - a challenge for SEPGs
Cloud Computing Gets Put to the Test
Who are Data Edge?
Systems Management 2.0: How to Gain Control of Unruly & Distributed Networks
Making AIOps-Driven Network Performance Management a Reality
What is the UK Cyber Essentials scheme?
Ad

More from Vladimir Jirasek (16)

PDF
Vulnerability management - beyond scanning
PPTX
Vulnerability Management @ DevSecOps London Gathering
PPTX
C-Level tools for Cloud security
PPTX
Secure your cloud applications by building solid foundations with enterprise ...
PPTX
Cloud security and security architecture
PPTX
2012 10 cloud security architecture
PPT
Mobile phone as Trusted identity assistant
KEY
Security architecture for LSE 2009
PPTX
Mobile security summit - 10 mobile risks
PDF
Information Risk Security model and metrics
PPTX
Integrating Qualys into the patch and vulnerability management processes
PPTX
Securing mobile population for White Hats
PPTX
Security models for security architecture
PPTX
Meaningfull security metrics
PPTX
CAMM presentation for Cyber Security Gas and Oil june 2011
PPTX
Federation For The Cloud Opportunities For A Single Identity
Vulnerability management - beyond scanning
Vulnerability Management @ DevSecOps London Gathering
C-Level tools for Cloud security
Secure your cloud applications by building solid foundations with enterprise ...
Cloud security and security architecture
2012 10 cloud security architecture
Mobile phone as Trusted identity assistant
Security architecture for LSE 2009
Mobile security summit - 10 mobile risks
Information Risk Security model and metrics
Integrating Qualys into the patch and vulnerability management processes
Securing mobile population for White Hats
Security models for security architecture
Meaningfull security metrics
CAMM presentation for Cyber Security Gas and Oil june 2011
Federation For The Cloud Opportunities For A Single Identity

Recently uploaded (20)

PDF
cuic standard and advanced reporting.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
madgavkar20181017ppt McKinsey Presentation.pdf
PPTX
Cloud computing and distributed systems.
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
How Onsite IT Support Drives Business Efficiency, Security, and Growth.pdf
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
PDF
AI And Its Effect On The Evolving IT Sector In Australia - Elevate
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
PDF
Sensors and Actuators in IoT Systems using pdf
PDF
Advanced Soft Computing BINUS July 2025.pdf
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
CIFDAQ's Market Wrap: Ethereum Leads, Bitcoin Lags, Institutions Shift
cuic standard and advanced reporting.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
madgavkar20181017ppt McKinsey Presentation.pdf
Cloud computing and distributed systems.
Chapter 3 Spatial Domain Image Processing.pdf
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
NewMind AI Weekly Chronicles - August'25 Week I
How Onsite IT Support Drives Business Efficiency, Security, and Growth.pdf
Understanding_Digital_Forensics_Presentation.pptx
Dropbox Q2 2025 Financial Results & Investor Presentation
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
AI And Its Effect On The Evolving IT Sector In Australia - Elevate
Reach Out and Touch Someone: Haptics and Empathic Computing
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
Sensors and Actuators in IoT Systems using pdf
Advanced Soft Computing BINUS July 2025.pdf
Advanced methodologies resolving dimensionality complications for autism neur...
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
CIFDAQ's Market Wrap: Ethereum Leads, Bitcoin Lags, Institutions Shift

ISE UK&Ireland 2008 Showcase Nominee Presentation Vladimir Jirasek

  • 1. Executive Alliance, Inc. October 16, 2008 New York, New York ISE UK and Ireland Summit and Awards NOMINEE SHOWCASE PRESENTATION October 22, 2008 London, United Kingdom
  • 2. by ISE Northeast 2008 Executive Alliance, Inc.ISE UK and Ireland 2008 Executive Alliance, Inc. 2 Vladimir Jirasek Information Security & Compliance manage DSG International plc Vulnerability scanning for PCI DSS compliance and risk management
  • 3. ISE Northeast 2008 Executive Alliance, Inc. Today’s Discussion Points • About DSG International • PCI DSS programme and beyond compliance • Vulnerability scanning project • Lessons learned ISE UK and Ireland 2008 Executive Alliance, Inc. 3
  • 4. ISE Northeast 2008ISE UK and Ireland 2008 Executive Alliance, Inc. 4 DSG International plc • Major electrical and computing retailer in Europe with both traditional stores and Web store • We own brads like Currys, PC World, Pixmania, The TechGuys, PC City, Electroworld, Elkjop • No 1 in the UK • Head office in Hemel Hempsted, UK • 40,000 employees in the Group • Annual revenue over £6b • Processes large amounts of customer data
  • 5. ISE Northeast 2008 Executive Alliance, Inc. PCI DSS is good but ... • Why good? The first standard that retailers take seriously • But scope is/can be limited • DSGi started work on PCI DSS in 2007 with most of the projects kicked off • Requirement 11.2 handled by this project • Limited budget • Although the scope is limited the approach was to take risk based approach ISE UK and Ireland 2008 Executive Alliance, Inc. 5
  • 6. ISE Northeast 2008 Executive Alliance, Inc. Requirements • Compliant with 11.2, i.e. ASV • Whole group in the scope (regardless of the PCI DSS scope) • Minimal operational overhead • Potential to satisfy other requirements • Easy to use • Fit for distributed IT teams in the Group ISE UK and Ireland 2008 Executive Alliance, Inc. 6
  • 7. ISE Northeast 2008 Executive Alliance, Inc. Goals • Develop patching and vulnerability scanning policy • Quick win - find the state of DSGi network (external then internal) • Deliver first “PASS” PCI DSS scans • Make this activity BAU for IT teams ISE UK and Ireland 2008 Executive Alliance, Inc. 7
  • 8. ISE Northeast 2008 Executive Alliance, Inc.ISE UK and Ireland 2008 Executive Alliance, Inc. 8 Challenges • Distributed IT teams • No standardised patching policy • Limited budget and overstretched IT resources in most countries • Missing risk assessment in IT patching • Scepticism and wary of vulnerability scanning
  • 9. ISE Northeast 2008 Executive Alliance, Inc.Executive Alliance, Inc. 9 Project team ISE UK and Ireland 2008 Accountable and project lead: Vladimir Jirasek - DSGi Information security manager Team members: Matt Leggett - Security project manager (UK) Stelios Kavalaris - Security admin (Greece) Samy Elmalki - Network admin (France) Ana Maria Munoz Ponce - System admin (Spain) Lars-Andre Johannessen - System manager (Nordic group) Oyvind Gulikstad - Security manager (Nordic group) Paolo Asioli - Security manager (Italy) Ed Brown - Systems manager (UK, Techguys) Michael Braid - Systems admins (UK, DSGi Business)
  • 10. ISE Northeast 2008 Executive Alliance, Inc.ISE UK and Ireland 2008 Executive Alliance, Inc. 10 Overcoming challenges • Responsibility for “clean” scans transferred to business units IT managers • Group wide standardised patching policy agreed • Limited budget addressed by using Software as a service model • Qualys service is easy to use and understood by IT teams. Virtually no training required • Business units in Qualys made group wide rollout easy to manage • Testing of impact of scanning to existing IT systems
  • 11. ISE Northeast 2008 Executive Alliance, Inc. Risk based approach Internet Internal network Head office DMZ mainframe eBusiness VPN GW acquirer setlement Store network
  • 12. ISE Northeast 2008 Executive Alliance, Inc. Risk based approach (cont) ISE UK and Ireland 2008 Executive Alliance, Inc. 14 Critical Important High Medium Low 5 24 hours 5 days 14 days 20 days 40 days 4 5 days 10 days 20 days 1 month 2 months 3 10 days 20 days 1 month 2 months 3 months 2 6 months* Next release* Next release Next release No fix 1 no fix* no fix* no fix no fix No fix
  • 13. ISE Northeast 2008 Executive Alliance, Inc. Project results Patching policy agreed buy IT teams Weekly vulnerability scans carried on all external and critical internal assets - 14 internal appliances in 7 business units 80% of security issues fixed across the group within first 3 months Qualys accepted by IT teams as a “good” tool for highlighting security issues Scanning is now BAU activity 13
  • 14. ISE Northeast 2008 Executive Alliance, Inc. Conclusion • Looked beyond PCI DSS and adopted risk based approach (now compliant with v 1.2) • Each IT team is a separate business unit • Responsibility for scanning and fixing transferred to IT managers ISE UK and Ireland 2008 Executive Alliance, Inc. 15
  • 15. ISE Northeast 2008 Executive Alliance, Inc. Thank You! • Questions? • Contact Info: • [email protected] or [email protected] • +447959040187 ISE UK and Ireland 2008 Executive Alliance, Inc. 16

Editor's Notes