Question
Case One : Fairplay Turns to a Managed Security Service Provider Fairplay Finer Foods is an independent grocery retailer that operates in the greater Chicago
Case One : Fairplay Turns to a Managed Security Service Provider Fairplay Finer Foods is an independent grocery retailer that operates in the greater Chicago area. From its beginning, Fairplays mission has been to provide quality foods at an affordable price along with exceptional customer service. Starting with a single store in 1975, Fairplay has since grown to seven locations. The opening of each new store led to increased sales and attracted new customers; however, expansion also raised new information system needs as well as information security risks. Due to its size, it was not practical for Fairplay to create and run its own information systems organization, so it contracted with KCS Computer Technology, Inc., to provide these services along with the necessary computer hardware and systems. One of KCSs key accomplishments for Fairplay was to implement and manage a corporate network that the grocery chain uses to run applications and communicate across all of its stores. Another important area of focus for KCS involved helping Fairplay manage issues related to the Payment Card Industry Data Security Standard (PCI DSS). Retailers accepting credit cards and other forms of electronic payment are required to comply with the PCI DSS. The PCI DSS standard ensures that businesses follow best practices for protecting their customers payment card information. A strong desire to ensure compliance with the PCI DSS standard and concern over potential network security issues led Fairplay and KCS to seek out a managed security service provider (MSSP). After a thorough investigation, Fairplay and KCS selected Control Scan, an MSSP headquartered in Atlanta, based on its simple pricing model, stable of certified security experts, advanced technology, and solid reputation. As part of its contract with Fairplay, Control Scan agreed to serve as an extension of KCS, delivering cloud-based securitytechnologies and related security support services, including: Installing, configuring, and monitoring a system of next-generation firewalls Investigating, responding to, and reporting on security-related events Providing network usage reports for insights into company resource utilization Upgrading the network on an ongoing basis by implementing the latest security enhancements Providing expertise to reduce network complexity and contain network-related costs Control Scans initial action was to install next-generation firewall appliances to protect each of Fairplays locations. This work was completed overnight in a single night to minimize business disruption. Control Scan then conducted a thorough PCI gap analysis to compare current Fairplay security controls with those required by the PCI DSS. Control Scan developed a detailed set of recommendations and options for eliminating the gaps; thus, giving Fairplay management a roadmap to achieve full PCI DSS compliance. Finally, Control Scan did a full review of all of Fairplays existing information systems and security policies, working with the chains IS staff to tweak and customize policies where necessary. Critical Thinking Questions What advantages does use of an MSSP offer a small retailer like Fairplay? Can you think of any potential drawbacks of this approach? Is there a danger inplacing too much trust in the use of an MSSP? Explain? Submit the assignment to Dropbox. Data breaches at major retailers, such as Neiman Marcus, Target, and others, in recent years have shown that compliance with the Payment Card Industry Data Security Standard (PCI DSS) is no guarantee against an intrusion (see Vijayan, Jaikumar, After Target, Neiman Marcus Breaches, Does PCI Compliance Mean Anything?, Computer World, January 24, 2014). If you were a member of Fairplays management team, what additional actions would you take to ensure your customers credit card data is not stolen? Submit the assignment to Dropbox. Do research on the Web to gain insight into the evolution of the PCI DSS standard. What major changes were made in moving from PCI 2.0 to PCI 3.0? What changes are being suggested for future versions of the PCI standard? Submit the assignment to Dropbox.
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started