Categories ArchivesPCI

What the new Service Provider levels mean to you! standard

The following is a guest post by Rob Harvey. Rob is a Consulting Manager inside the PCI practice at VeriSign. ‘Tis the season! Everyone is in the giving mode this time of the year and VISA is no different. VISA announced in the last month a change in the service provider validation levels and reporting. It is also the season for reflecting on the past year and one of the biggest questions we get from our clients is, “Am I a service provider and if so what level do I need to validate against?” Beginning February 2009, VISA will use a modified two level approach for service providers which I hope will add clarity to the question. See the information ...

Continue Reading

PCI 1.2 is taking off! standard

Less than two months after its release, we’ve seen our first announcement from a company that has become compliant! I think that companies will find 1.2 easier to comply with when they examine it in detail. Have you performed a gap analysis yet? If not, maybe the downtime around the holidays (as long as it does not impact holiday lockdown!) would be good to review your last ROC and see what changes you may need to make! Possibly Related Posts: PCI DSS 4.0 Released plus BOOK DETAILS! PCI Council Loses $600K in Revenue, PO Population on the Decline Why PCI DSS 4.0 Needs to be a Complete Rewrite Equifax is only half the problem, your SSN needs a redesign! Orfei ...

Continue Reading

BUSTED! Why passing the blame for a PCI Breach will fail. standard

After the year we had in 2007 with PCI related breaches, who would have thought that 2008 would give us more? I mean, after last year, who would have thought that we would see another major breach given the “lessons” we learned? Um, I did. Fo-sho. Why? Because early in my career I learned that most executives don’t care about problems until they hit close to home. Like right under their nose. We’ve seen two instances this year of companies that had validated compliance with a QSA, but were subsequently breached. Without specifically commenting on either of these cases, we have never conducted an investigation of a compromised entity and learned that they were compliant at the time of the ...

Continue Reading

Where to get good PCI Training standard

Yep, it’s been a PCI heavy week. Want me to discuss other topics? T and suggest one! Last week I sat through the Certified Payment-card Industry Security Manager training here in Dallas. The folks at Aegenis planned it at a hotel that happened to be about 10 minutes from my house, so getting there was easy. There were several bigwigs from the information security and PCI industry there with me in the sold out training, and the industry perspectives were valuable. If you are not an employee of a QSAC and are looking for a GOOD source of training around PCI, data breach laws, and a detailed look into the payment industry, this training is for you. If you opt ...

Continue Reading

International PCI Compliance Dates Set standard

The day has come! I can’t tell you how many merchants have hounded me for compliance dates outside the US and Canada, and then looked at me like I just told them the sky was red when I could not provide them. Visa, Inc. has formally announced global compliance deadlines (thanks JKA!). If you are a global retailer, or a retailer not based in the US or Canada, the pressure is now on to become compliant with the PCI Standard! Feel free to reach out to a VeriSign QSA if you need assistance! Possibly Related Posts: PCI DSS 4.0 Released plus BOOK DETAILS! PCI Council Loses $600K in Revenue, PO Population on the Decline Why PCI DSS 4.0 Needs to ...

Continue Reading

PCI-SSC Releases Data Storage Do’s and Don’ts standard

The PCI Security Standards Council posted a document on Data Storage Do’s and Don’ts this week. This document does an excellent job breaking down the storage piece of PCI for merchants big and small, but especially for the smaller folks out there. Now, for all of you out there, don’t forget that PCI is NOT just a data storage initiative. Just because you don’t store cardholder data does not exempt you from being compliant. That said, locating your data is step one in understanding how you measure up to the PCI Standard. Consequently, it is also step one in VeriSign’s PCI Program Management methodology. How healthy is your compliance program? If it needs work, drop us a line and we’ll ...

Continue Reading

PCI v1.2 saves the travel industry standard

One major change to PCI version 1.2 is the new requirements and testing procedures for Req. 12.8. 12.8 deals with how merchants and service providers should handle their third parties that can affect the security of cardholder data. The card brands have told us in the past that they would not expect a service provider to prevent a merchant from being compliant, but that the merchant must understand that they will carry the liability for a breach at their service provider’s site. We’ve seen 12.8 morph considerably from PCI version 1.0 to 1.2. The intent was to help merchants understand how service providers deal with their data, and make sure that they are protected if there is a breach at ...

Continue Reading

PCI Europe Community Meeting, Q/A (Part 2) standard

Final round of questions from the field! The first question from this session was “Are end of life operating systems able to be used?” The thing that really worries me about retail is that information security does not seem to be built into the price of goods on the shelf. When someone asks if they are expected to replace hundreds or thousands of devices for PCI Compliance because Microsoft will not support them anymore, I worry more about the overall security of the company. This seems like a reactive approach without any forward strategy, which is unfortunately fairly common. I understand the business implications here. If your competitors are not doing this, you could face additional price pressures by trying ...

Continue Reading

PCI Europe Community Meeting, Q/A standard

I always enjoy the Q/A sessions that the Council has at these events. I don’t know how many sessions I will be able to blog about (we only want the interesting ones anyway), but here’s the first bunch of Q/A from this session! The first question was around segmentation and SANs. I’d never heard the question asked that way, but most SANs by nature are segmented from each other. The more interesting point here is what constitutes segmentation? So many assessors only consider firewalls a method of segmentation. According to the documentation provided by the council, segmentation can be accomplished in multiple ways–not just by deploying firewalls. QSAs should be looking at the whole solution, not just fixating on a ...

Continue Reading

October Herding Cats and Off to Brussels! standard

Greetings folks! Couple of updates in this post. October’s Herding Cats is up and ready for you to read! Pretty soon here I will be setting up a URL where you can download all the published versions of this column regardless of your membership status with the ISSA. Need a little time though baby birds. Until then, members of the ISSA can download the most recent version here. As you can tell, I have been reading a lot of James Patterson recently. Sorry about that. Also, if you are going to be at the PCI Europe Community Meeting this week, look me up! I’ll be wheels down in Brussels on Tuesday in time for the networking session. I am looking ...

Continue Reading

This is a unique website which will require a more modern browser to work!

Please upgrade today!