When I came into this role the company already had Symantec Critical System Protection, now called Data Center Security, already deployed and monitoring various PCI related systems. There was no one who was dedicated to manage this system until I was promoted into this position. Over the past 5 years we have expanded the use of this product to not only help us detect questionable activity within the various monitored systems but on some systems connected to our PCI environment, we have implemented intrusion prevention in terms of network traffic. This product helps us meet and exceed PCI requirements each and every year. It helps us achieve PCI compliance by monitoring what is required of us as well as block unauthorized/malicious activity. An example of this is last year our QSA's were able to successfully map a drive via the standard Microsoft ports and gain access into our retail environment. To close this finding, I created an IP policy to block this traffic at the host. After the policy was deployed to the agent, they were no longer able to gain access through the various tools they had access to. I have also set up various alerts, including when someone tampers with the IPS driver disabling it.