PCI Council Advice on Threat Management

December 15, 2009 by ADMIN · 1 Comment

By Robert Siciliano, ID Theft Expert and Security Consultant to Intelius.com

Security professionals intuitively think proactively. Our job is to predict and prevent what the bad guy will do next. My job specifically is to instill this mindset into you, the consumer, SMB or large corporate enterprise. Bob Russo, General Manager and Rockstar of the PCI Security Standards Council reminds us all in this Business Week article that it’s not all about prevention.

Evaluating Corporate Social Media Strategies

November 10, 2009 by ADMIN · 2 Comments

Daniel Wallace, Information Security Consultant at Grow Forward

The notion that social media sites are little more than a trendy consumer oriented technology is misguided. Most business activities have legal ramifications and social media is no exception., and legal issues can arise when an organization does not adequately address social media with company policy.

Making PCI Stand For Coordination & Impact

June 29, 2009 by ADMIN · 1 Comment

Daniel Wallace, Information Security Consultant

It will be no small task in terms of cost and effort for many of the impacted companies to make the transition from self-assessment to onsite 3rd party assessment. However, there are ways to lessen the burden and actually drive business-value from the engagement.

PCI SSC Seeks Input on Security Standards

June 24, 2009 by ADMIN · Leave a Comment

From the PCI Security Standard Council

During phase two of the lifecycle process, between July 1 and November 1, 2009, merchants, processors, financial institutions and other key stakeholders have the opportunity to provide detailed and actionable feedback in an effort to revise future editions of the Council’s standards to improve payment data security.

PCI SSC ANNOUNCES NEW BOARD

May 21, 2009 by ADMIN · 3 Comments

From the PCI Security Standard Council

“Our Participating Organizations came out in force in the recent Council nominations and election process. It is exciting to see such widespread participation,” said Bob Russo, general manager, PCI Security Standards Council. “I would like to congratulate not only our new Board of Advisors but everyone who continues to join the Council in pursuing its mission of securing payment card data, through these collaborative processes. I’m confident our new Board of Advisors will build upon the success of their predecessors in helping the Council to effectively evolve the PCI standards and bring new tools and resources to market to help improve education and implementation of PCI standards.”

ISR News: PCI STANDARDS TRAINING

March 17, 2009 by ADMIN · Leave a Comment

From The PCI Security Standards Council:

The two-day course entitled Standards Training, is designed to help merchants improve preparation for on site assessment, understand what is involved in creating their own internal assessment capability and establish an internal compliance program to help them sustain PCI DSS security practices and compliance when the assessment process is completed.

PCI Security Standards Council Issues Guide

March 11, 2009 by ADMIN · 3 Comments

From the PCI Security Standards Council:

“Securing cardholder data is the ultimate priority and following the PCI DSS is the best way to achieve this. The Prioritized Approach framework will help stakeholders understand where they can act to reduce risk earlier in their journey towards PCI compliance,” said Bob Russo, general manager, PCI Security Standards Council. “The launch of these new guidance and interactive documents are another step by the Council to increase understanding of and education around PCI DSS among merchants, providing them with insight into how they can protect card holder data faster and demonstrate progress and compliance with the PCI DSS.”

ISR News: PCI QSA Penalizes Assessors

March 9, 2009 by ADMIN · Leave a Comment

Excerpts From SearchSecurity.com

San Jose, Calif.-based Payment Software Company LLC (PSC) and Frederick, Md.-based Fortrex Technologies Inc. were placed in remediation status, forcing the two companies to address issues discovered during a review of assessment documents or face losing certification. The PCI Council said qualified security assessor (QSA) organizations placed in remediation have violated QSA Validation Requirements. The requirements describe the qualifications a QSA must have to perform assessments.