Legal & Regulatory

PCI Security Policies and You – Part 1

January 7th, 2010

 - Imagine this situation: You have been told to create your school’s security policies. You research all the components and compile the requirements for notification (continue reading...)

The Dangerous Out-Of-Scope PCI Charade

November 17th, 2009

 - Dominating many discussions over the last few weeks in payment security circles has been speculation over what the PCI Council, Visa and others will decide about declaring some types of data out-of-scope for PCI (continue reading...)

OWASP Top Ten for 2010 Released

November 13th, 2009

 - Late today (Friday) a preliminary update to the OWASP 10 for 2010 was released (click here). As most of you know, PCI compliance requires (among a bunch of other things...) that all custom (continue reading...)

It’s Not Just For Card Data Any More

November 11th, 2009

 - With all of the recent fuss about PCI requirements and how to protect payment cards, many companies have opted to take a far too narrow view of data protection. The PCI rules are absolutely designed (continue reading...)

Processor Best Practices You Can Use

October 29th, 2009

 - Visa just released its Cardholder Data Security Best Practices for VisaNet Processors. I think there are some things in this document that you as merchants can use, too. Here are a few (continue reading...)

A Personal Note

October 28th, 2009

 - I hope you will allow me this personal blog post, but I learned today that David Taylor of the PCI Knowledge Base passed away suddenly Tuesday. Dave was a friend and colleague. I was (continue reading...)

Is Your Web App Secure? Really?

October 20th, 2009

 - The Web Application Security Consortium (WASC) today announced the findings of its WASC Web Application Security Statistics Project 2008. Their objective was to pool data from a number of sources to assess (continue reading...)

Keeping Informed

October 20th, 2009

 - One of the hardest parts about payments and PCI is keeping informed of new developments, state laws, emerging threat vectors, and ideas about what may be coming. You are already making a start by (continue reading...)

PCI Merchant Levels Cleared or Confused?

October 20th, 2009

 - Branden Williams writes that Visa and MasterCard have pulled the "reciprocity" from their merchant level definitions (see here). For those of you not up on all the details, I'll try and explain (continue reading...)

Operation Phish Phry

October 8th, 2009

 - How full is the "junk" folder in your email account? If you are like me, it gets filled faster each day with junk email. Most of these emails are simply, well, junk. But some are (continue reading...)

Your Campus Hotel and PCI

October 6th, 2009

 - I have been working with and talking to a number of schools recently that operate hotels on campus. These hotel operations face particular PCI compliance challenges due to the nature of the hotel business. (continue reading...)

POS PIN-entry Vulnerabilities

October 5th, 2009

 - Those of you with PIN-entry devices (PEDs) at your point of sale (POS) should take a look at Visa's POS PIN Entry Device Vulnerabilities white paper out today. Visa reports on the (continue reading...)

Purchasing, Travel, and Corporate Cards and PCI Scope – Some Closure!

September 25th, 2009

 - I have blogged here (see here with comments, and here, and here) and elsewhere about whether “corporate cards” used for travel and purchasing should be in the “issuing” school’s own scope for (continue reading...)

PCI Community Meeting – Day 2

September 24th, 2009

 - Day 2 of the PCI Community Meeting is just concluded. We heard from former Representative Tom Davis about the prospects for federal legislation addressing cyber security. My take from the presentation is (continue reading...)

PCI Community Meeting – Day 1 at The Listening Meeting

September 23rd, 2009

 - I'm here in Las Vegas with 650 of my closest PCI friends, including Tom Davis of Indiana Univeristy (For those of you who forgot, we represent NACUBO which is a Participating Organization). The PCI (continue reading...)

Off to the PCI Community Meeting!

September 21st, 2009

 - I'm getting ready to head off to the PCI Community Meeting. Tom Davis of IU and I will be there representing NACUBO and the Treasury Institute -- and therefore, YOU. Thanks to those (continue reading...)

Being the “Bad Guy”

September 15th, 2009

 - Are we in the "no" business?I have to ask that question because of what I sometimes encounter in PCI assessments and even PCI training. I recommend limiting Internet access or restricting access to cardholder data (continue reading...)

UPDATED: More on Choosing A QSA

September 10th, 2009

 - I previously referenced an article on how to select a QSA. Now there is another article (4 Ways to Get the Most From your PCI QSAs) at Computerworld with similarly good advice. (continue reading...)

Real Cost of a Security Breach?

September 7th, 2009

 - There is a standard benchmark used to calculate the cost of a security breach: about $200 per account compromised. But often the compromise is not based on, say, compromised payment cards. Sometimes (continue reading...)

Procurement Cards Can Be Breached, Too

September 3rd, 2009

 - The University of Vermont reported that up to 240 university-funded procurement cards appear to have been compromised/breached. I don't know all the details, but it gives me the opportunity to raise two important (continue reading...)

Copyright © 2012 The Security Blog. All rights reserved.