<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Do we need any customization in hortonworks to implement PCI compliance? if so could you please share documents related to it in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114026#M16561</link>
    <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2411/sureshwillsmith.html" nodeid="2411"&gt;@suresh  kumar&lt;/A&gt;  You can download the document. See &lt;A href="http://hortonworks.com/info/pci-dss-compliance-for-hadoop/"&gt;this&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you are looking for technical doc then I am afraid that I don't have any template or generic as it's always customer driven based on the engagement. &lt;/P&gt;</description>
    <pubDate>Wed, 27 Jan 2016 20:56:52 GMT</pubDate>
    <dc:creator>nsabharwal</dc:creator>
    <dc:date>2016-01-27T20:56:52Z</dc:date>
    <item>
      <title>Do we need any customization in hortonworks to implement PCI compliance? if so could you please share documents related to it</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114021#M16556</link>
      <description />
      <pubDate>Wed, 27 Jan 2016 20:26:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114021#M16556</guid>
      <dc:creator>sureshwillsmith</dc:creator>
      <dc:date>2016-01-27T20:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need any customization in hortonworks to implement PCI compliance? if so could you please share documents related to it</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114022#M16557</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/2411/sureshwillsmith.html" nodeid="2411"&gt;@suresh  kumar &lt;/A&gt;
&lt;P&gt;HDP is a platform and you have to build/implement your own compliance standards around it.&lt;/P&gt;&lt;P&gt;Ranger for Authorization, Auditing , Centralized admin console to manage policies&lt;/P&gt;&lt;P&gt;Kerberos is MUST - Authentication&lt;/P&gt;&lt;P&gt;Data encryption at rest - TDE or your preferred vendor &lt;/P&gt;&lt;P&gt;You have to implement your own scripts to fullfil following requirements. &lt;/P&gt;&lt;P&gt;Password expiration every xx days and that includes service accounts too.&lt;/P&gt;&lt;P&gt;Auditing and more auditing ..anything that touches any part of the stack needs to be audited (Ranger and HDFS audit log is helpful)&lt;/P&gt;&lt;P&gt;Password complexity&lt;/P&gt;&lt;P&gt;Failed login attempts&lt;/P&gt;&lt;P&gt;Data encryption in motion &lt;/P&gt;&lt;P&gt;Data Retention - Data must expire after specific time otherwise you would have to retain the data for longer time (Falcon can help)&lt;/P&gt;&lt;P&gt;You can read this &lt;A href="http://hortonworks.com/blog/hadoop-security-enterprise/" target="_blank"&gt;http://hortonworks.com/blog/hadoop-security-enterprise/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 20:31:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114022#M16557</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-01-27T20:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need any customization in hortonworks to implement PCI compliance? if so could you please share documents related to it</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114023#M16558</link>
      <description>&lt;P&gt;so does Hortonworks by default provides PCI standards security or do we need third party for implementing them &lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 20:45:37 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114023#M16558</guid>
      <dc:creator>sureshwillsmith</dc:creator>
      <dc:date>2016-01-27T20:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need any customization in hortonworks to implement PCI compliance? if so could you please share documents related to it</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114024#M16559</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2411/sureshwillsmith.html" nodeid="2411"&gt;@suresh  kumar&lt;/A&gt;  You have to build/implement your own standards. It's like with any software stack. You have a software install, data is being stored and users accessing it.&lt;/P&gt;&lt;P&gt;HDP is a platform and it comes with security solutions that you can leverage to meet some of security requirements , rest you have to build or rely on 3rd part solutions. &lt;/P&gt;&lt;P&gt;See &lt;A target="_blank" href="http://hortonworks.com/info/pci-dss-compliance-for-hadoop/"&gt;this&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 20:49:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114024#M16559</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-01-27T20:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need any customization in hortonworks to implement PCI compliance? if so could you please share documents related to it</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114025#M16560</link>
      <description>&lt;P&gt;Thank You  , Could you please share any documents  for developing standards in general (for reference)&lt;/P&gt;&lt;P&gt;Appreicate your prompt response&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 20:53:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114025#M16560</guid>
      <dc:creator>sureshwillsmith</dc:creator>
      <dc:date>2016-01-27T20:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need any customization in hortonworks to implement PCI compliance? if so could you please share documents related to it</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114026#M16561</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2411/sureshwillsmith.html" nodeid="2411"&gt;@suresh  kumar&lt;/A&gt;  You can download the document. See &lt;A href="http://hortonworks.com/info/pci-dss-compliance-for-hadoop/"&gt;this&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you are looking for technical doc then I am afraid that I don't have any template or generic as it's always customer driven based on the engagement. &lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 20:56:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114026#M16561</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-01-27T20:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need any customization in hortonworks to implement PCI compliance? if so could you please share documents related to it</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114027#M16562</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2411/sureshwillsmith.html" nodeid="2411"&gt;@suresh  kumar&lt;/A&gt; here is our PCI DSS white paper. Following are some key points:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Organizations require a number of capabilities to fully comply with various aspects of PCI regulations&lt;/LI&gt;&lt;LI&gt;There is no “silver bullet” or a single vendor or product that can address all 12 requirements of PCI compliance&lt;/LI&gt;&lt;LI&gt; A vendor or product can’t be PCI-compliant or PCI-certified; only a project or deployment can be certified to be PCI compliant&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;A href="https://community.cloudera.com/legacyfs/online/attachments/1601-hortonworks-pci-compliance-wp.pdf"&gt;hortonworks-pci-compliance-wp.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 01:45:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114027#M16562</guid>
      <dc:creator>SQLShaw</dc:creator>
      <dc:date>2016-01-28T01:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need any customization in hortonworks to implement PCI compliance? if so could you please share documents related to it</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114028#M16563</link>
      <description>&lt;P&gt;Thank You Scott&lt;/P&gt;&lt;P&gt;So Ranger,knox , kerbos are the products which are out of box of  hortonworks  if not , where does the ‘significant custom code’ start? in hortonworks.&lt;/P&gt;&lt;P&gt;from what extent does hortonworks provides out of box for PCI compliance standards , from there we can start our customization to meet PCI compliance or taking third party partners to meet  PCI compliance&lt;/P&gt;&lt;P&gt;Appreciate your suggestions&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 18:22:48 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114028#M16563</guid>
      <dc:creator>sureshwillsmith</dc:creator>
      <dc:date>2016-01-28T18:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need any customization in hortonworks to implement PCI compliance? if so could you please share documents related to it</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114029#M16564</link>
      <description>&lt;P&gt;We provide all the security and governance components around administration (Ranger), authentication (Kerberos), authorization (Ranger), audit (Ranger), and data protection (TDE). It is up to the customer to configure the environment and implement the PCI compliant solutions (encryption, policies, data masking, auditing, etc.). In addition, Apache Knox provides perimeter security and Apache Atlas provides governance. Hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 22:05:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Do-we-need-any-customization-in-hortonworks-to-implement-PCI/m-p/114029#M16564</guid>
      <dc:creator>SQLShaw</dc:creator>
      <dc:date>2016-01-28T22:05:01Z</dc:date>
    </item>
  </channel>
</rss>

