Skip to main content

Hudson’s Bay Company addresses compliance with industry standards while enhancing its data security using IBM solutions and services.

Published on 11-Sep-2008

"Meeting the PCI DSS regulations was mandatory, but IBM provided us with more than just compliance. Sensitive data is secure, systems are monitored closely for performance issues, and our IT staff can focus on more mission-critical activities." - Kristofer Laxdal, Director IT Service Management & Information Security, Hudson’s Bay Company

Customer:
Hudson’s Bay Company

Industry:
Retail

Deployment country:
Canada

Solution:
Business-to-Business, Managing Business Infrastructure, Security

Overview

Hudson’s Bay Company (Hbc) is Canada’s largest diversified general merchandise retailer, featuring four department store divisions. Through 580 stores and 60,000 associates nationwide, Hbc provides Canadians with stylish, quality merchandise at great value, through retail banners focused on exceptional customer service.

Business need:
All retailers that process credit card transactions are required to comply with the Payment Card Industry Data Security Standard (PCI DSS). Noncompliance can result in significant fines and increase the opportunity for theft or loss of private information, which could cause irreparable damage to a company’s reputation and customer loyalty.

Solution:
Hbc chose to outsource its security management to IBM Global Technology Services and IBM Internet Security Systems™.

Benefits:
- Addresses compliance with PCI DSS while reducing the consumption of internal IT resources - Anticipates, tracks and mitigates security threats before they cause harm to data or the IT infrastructure - Provides professional management of network devices

Case Study

Overview
Hudson’s Bay Company
Toronto, Ontario, Canada
www.hbc.com

Industry
• Retail

Employees
• 70,000

Products and Services
• IBM Global Technology Services
• IBM Internet Security Systems

Hudson’s Bay Company (Hbc) is Canada’s largest diversified general merchandise retailer, featuring four department store divisions. Through 580 stores and 60,000 associates nationwide, Hbc provides Canadians with stylish, quality merchandise at great value, through retail banners focused on exceptional customer service.

Challenge
All retailers that process credit card transactions are required to comply with the Payment Card Industry Data Security Standard (PCI DSS). Noncompliance can result in significant fines and increase the opportunity for theft or loss of private information, which could cause irreparable damage to a company’s reputation and customer loyalty. To meet PCI DSS compliance, Hbc sought a managed security service that could provide full-scale security management for critical credit card holding systems, as well as security alerting and event reporting for less critical devices.

Solution
Hbc chose to outsource its security management to IBM Global Technology Services and IBM Internet Security Systems™. Under the agreement, IBM facilitates security-event log monitoring of 318 network devices and servers within the client’s environment. An aggregator server—managed by IBM Global Technology Services—at the Hbc site collects the log data and forwards it to IBM Internet Security Systems, and the server enables reporting through a customer portal.

IBM provides managed protection services for 134 servers, including the installation of host intrusion prevention software on each server. These servers are monitored by IBM Internet Security Systems via a virtual private network (VPN). In addition, IBM Internet Security Systems provides security monitoring for nine network firewall servers.

Benefits
• Addresses compliance with PCI DSS while reducing the consumption of internal IT resources
• Anticipates, tracks and mitigates security threats before they cause harm to data or the IT infrastructure
• Provides professional management of network devices

Products and services used

Legal Information

© Copyright IBM Corporation 2008 IBM Corporation Software Group Route 100 Somers, NY 10589 U.S.A. Produced in the United States of America September 2008 All Rights Reserved IBM, the IBM logo, ibm.com are trademarks or registered trademarks of International Business Machines Corporation in the United States, other countries, or both. If these and other IBM trademarked terms are marked on their first occurrence in this information with a trademark symbol (® or ™), these symbols indicate U.S. registered or common law trademarks owned by IBM at the time this information was published. Such trademarks may also be registered or common law trademarks in other countries. A current list of IBM trademarks is available on the Web at “Copyright and trademark information” at ibm.com/legal/copytrade.shtml Other company, product and service names may be trademarks or service marks of others. The information contained in this documentation is provided for informational purposes only. While efforts were made to verify the completeness and accuracy of the information contained in this documentation, it is provided “as is” without warranty of any kind, express or implied. In addition, this information is based on IBM’s current product plans and strategy, which are subject to change by IBM without notice. IBM shall not be responsible for any damages arising out of the use of, or otherwise related to, this documentation or any other documentation. Nothing contained in this documentation is intended to, nor shall have the effect of, creating any warranties or representations from IBM (or its suppliers or licensors), or altering the terms and conditions of the applicable license agreement governing the use of IBM software. SEC03006-USEN-00