Sunday, March 21, 2010

Bookmark and Share

Archive for the ‘PCI’ Category

PCI DSS Ambiguities and How to Overcome Them

In a video over at the SearchSecurity site, Ed talks about the:

questions that pose the greatest challenge to enterprises as they struggle to interpret the requirements; outlines recent and upcoming clarifications from the PCI Security Standards Council; and discuss strategies used in the field to reduce the complexity.

Does “one function per server” mean that we can’t use virtualization?
Must our penetration testing and/or quarterly scanning cover everything or just the cardholder environment?
If we miss one of our quarterly scans, does that mean we need to wait a full year to be compliant?
The requirements state individuals with a “legitimate business need” can view PANs. What does that mean?

Bookmark and Share

Restaurateurs, SIs, and PCI

Dan Kaplan has a piece in SC Magazine on the lawsuit being filed against SI/resellers Radiant Systems and Computer World by some restaurants in Louisian and Mississippi.

Dan interviewed me for the piece:

Diana Kelley, founder of consultancy Security Curve, said she understands where the restaurants have a case, considering Visa alerted the two defendants in April 2007 that their systems were non-compliant. The eateries claimed they never learned of the warning, but Kelley said they still are required to perform a PCI assessment, which should have caught the vulnerabilities.

“We’re going to have a judge put some case law on where the accountability does lie,” she said. “It really could change the landscape.”

Bookmark and Share

PCI Compliance Summit

BrightTalk is hosting a day-long PCI Compliance Summit on October 27th. Looks like they’ve put together a really solid agenda.

Diana will be presenting “Software Security for Compliance, PCI, and Beyond” at 10a Eastern. Please listen in if you have time!

PCI requirement 6 and sub-requirement 6.6 have caused confusion among retailers and merchants trying to understand how best to secure Web-facing applications. In this session, Diana Kelley explains web-application security, PCI requirement 6 and 6.6, and the PA-DSS and why creating secure code is essential to protecting assets. She provides an explanation of how security can be woven throughout the software development lifecycle and explains some of the most common web application security vulnerabilities.

Bookmark and Share

Tokenization and PCI

Rob Westervelt interviewed Diana for a piece on Tokenization for PCI Compliance

“It’s a great technology overall, but merchants have to make sure there’s no other instances of PAN data around to really get the full benefit,” Kelley said, adding that PAN data can slip into log files and volatile memory.

Bookmark and Share
“So many technologies- but which ones (if any) do you really need?”
Blog Cloud

The Law: Fear It Administrative Cruft (16)
Analysts (31)
Apple (25)
AppSec (12)
Assessments (2)
Auditors (2)
Biometrics (4)
Blogs (13)
Breaches (21)
Buzzwords (2)
By Grabthar's Hammer!! (1)
Certifications (1)
Change Management (1)
Cheezburger Network (1)
Chupacabra (1)
Cloud Computing Security (4)
Collaborative Strategy Guild (2)
Compliance (4)
Copyright (9)
Credit Cards (3)
Crypto (11)
CXO Summit 2010 (1)
Cyberterrorism (2)
Data Protection (2)
DHS (25)
eBay (1)
Emergence (1)
End-to-End Encryption (2)
England (1)
Financial Fraud (1)
FISAP (1)
Forensics (5)
FTC Red Flad Rules (1)
FUD (12)
gnisreveR (2)
Google (2)
Holidays! (3)
Humor (16)
Identity Theft (4)
James Bond Shiz (1)
Legal Shiz (13)
Linux (3)
Malware (35)
Marketing and PR (9)
Messaging Security (1)
Microsoft (26)
Monoculture (3)
Mouth-Frothing (2)
Musings (17)
Open Source (3)
Oracle (21)
Outsourcing (4)
Paris Hilton (1)
Passwords (1)
PCI (4)
Phish-Eye (8)
Phones (5)
Planes (1)
Privacy (1)
Programming (1)
QDSP Blues (15)
Research (30)
Resources (6)
Rhesus Monkeys (2)
Risk Management (18)
RSA 2009 (1)
RSA 2010 (1)
SAML (1)
SAN (1)
SC Mag Blues (1)
SCADA (1)
Security Curve (8)
SecurityCurve Speaking (2)
SIEM and Log Management (5)
Social Networking (1)
SOX (1)
Speaking (2)
Spinach (1)
Spy Stuff (1)
Stealing Stuff (8)
Storage (1)
Symantec (7)
Tarot (1)
Teleological suspension of the ethical (3)
The Great Borack (1)
The Law: Fear It (10)
The Old Man of the Mountain (1)
The Regs (5)
Tokenization (1)
Useless Shizz (13)
Vendors (37)
Virtual Worlds (2)
Voting (2)
Vulnerabilities (40)
Walt Disney (2)
Wi-Fi (16)

WP Cumulus Flash tag cloud by Roy Tanck and Luke Morton requires Flash Player 9 or better.

Archives