PCI Council Advice on Threat Management
By Robert Siciliano, ID Theft Expert and Security Consultant to Intelius.com
Security professionals intuitively think proactively. Our job is to predict and prevent what the bad guy will do next. My job specifically is to instill this mindset into you, the consumer, SMB or large corporate enterprise. Bob Russo, General Manager and Rockstar of the PCI Security Standards Council reminds us all in this Business Week article that it’s not all about prevention.
Evaluating Corporate Social Media Strategies
Daniel Wallace, Information Security Consultant at Grow Forward
The notion that social media sites are little more than a trendy consumer oriented technology is misguided. Most business activities have legal ramifications and social media is no exception., and legal issues can arise when an organization does not adequately address social media with company policy.
Making PCI Stand For Coordination & Impact
Daniel Wallace, Information Security Consultant
It will be no small task in terms of cost and effort for many of the impacted companies to make the transition from self-assessment to onsite 3rd party assessment. However, there are ways to lessen the burden and actually drive business-value from the engagement.
PCI SSC Seeks Input on Security Standards
From the PCI Security Standard Council
During phase two of the lifecycle process, between July 1 and November 1, 2009, merchants, processors, financial institutions and other key stakeholders have the opportunity to provide detailed and actionable feedback in an effort to revise future editions of the Council’s standards to improve payment data security.
PCI SSC ANNOUNCES NEW BOARD
From the PCI Security Standard Council
“Our Participating Organizations came out in force in the recent Council nominations and election process. It is exciting to see such widespread participation,” said Bob Russo, general manager, PCI Security Standards Council. “I would like to congratulate not only our new Board of Advisors but everyone who continues to join the Council in pursuing its mission of securing payment card data, through these collaborative processes. I’m confident our new Board of Advisors will build upon the success of their predecessors in helping the Council to effectively evolve the PCI standards and bring new tools and resources to market to help improve education and implementation of PCI standards.”
ISR News: PCI STANDARDS TRAINING
From The PCI Security Standards Council:
The two-day course entitled Standards Training, is designed to help merchants improve preparation for on site assessment, understand what is involved in creating their own internal assessment capability and establish an internal compliance program to help them sustain PCI DSS security practices and compliance when the assessment process is completed.
PCI Security Standards Council Issues Guide
From the PCI Security Standards Council:
“Securing cardholder data is the ultimate priority and following the PCI DSS is the best way to achieve this. The Prioritized Approach framework will help stakeholders understand where they can act to reduce risk earlier in their journey towards PCI compliance,” said Bob Russo, general manager, PCI Security Standards Council. “The launch of these new guidance and interactive documents are another step by the Council to increase understanding of and education around PCI DSS among merchants, providing them with insight into how they can protect card holder data faster and demonstrate progress and compliance with the PCI DSS.”
ISR News: PCI QSA Penalizes Assessors
Excerpts From SearchSecurity.com
San Jose, Calif.-based Payment Software Company LLC (PSC) and Frederick, Md.-based Fortrex Technologies Inc. were placed in remediation status, forcing the two companies to address issues discovered during a review of assessment documents or face losing certification. The PCI Council said qualified security assessor (QSA) organizations placed in remediation have violated QSA Validation Requirements. The requirements describe the qualifications a QSA must have to perform assessments.


