Next webcast:
"Securing Your SharePoint Documents, End to End"
Date: Thursday, March 22, 2012, 10am Pacific
CipherPoint conducts webcasts on SharePoint security and compliance topics, including HITECH compliance and SharePoint, SharePoint Defense in Depth, content security, and others. For links to replays of recent webcasts, please visit our webcasts page.
|
“CipherPoint brings an innovative approach to solving our healthcare clients HITECH compliance and security challenges. " Marie-Michelle Strah, PhD, Planet Technologies Federal Healthcare Practice. |
|
"The focus of SharePoint security concerns appears to be much more focused on protecting sensitive information than on traditional malware" Osterman Research |
Compliance with PCI DSS can be an issue for SharePoint sites to the extent that content and information stored in SharePoint fits the criteria for "cardholder data" as defined by the PCI Security Standards Council. For organizations that process credit card transactions, compliance with the 12 high level requirements contained in the PCI DSS are mandatory.
Three common SharePoint use cases can result in SharePoint sites being judged a part of the cardholder data environment, and thus in scope for PCI compliance. These are:
Failing to provide adequate controls including encryption for cardholder data can have extremely negative impacts on organizations, including falied security assessments, loss of ability to process credit cards, and brand damage in the event of breaches involving credit card data.
To help SharePoint users to understand their compliance obligations for PCI DSS, CipherPoint has created a solution brief, PCI DSS Compliance and SharePoint.