<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Security Blog &#187; Legal &amp; Regulatory Archives  &#8211; Security Threat Research News</title>
	<atom:link href="http://www.thesecurityblog.com/category/legal-regulatory/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thesecurityblog.com</link>
	<description>Security Threat Research News</description>
	<lastBuildDate>Sat, 11 Feb 2012 01:00:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>PCI Security Policies and You &#8211; Part 1</title>
		<link>http://www.thesecurityblog.com/2010/01/pci-security-policies-and-you-part-1/</link>
		<comments>http://www.thesecurityblog.com/2010/01/pci-security-policies-and-you-part-1/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 17:06:00 +0000</pubDate>
		<dc:creator>Walt Conway</dc:creator>
				<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[[This blog post deals with an article I wrote for the third quarter 2009 issue of Secure Payments Magazine.  I have adapted it here particularly for Higher Education.  --Walt]Imagine this situation:  You have been told to create your school’s securit...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2010/01/pci-security-policies-and-you-part-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Dangerous Out-Of-Scope PCI Charade</title>
		<link>http://www.thesecurityblog.com/2009/11/the-dangerous-out-of-scope-pci-charade/</link>
		<comments>http://www.thesecurityblog.com/2009/11/the-dangerous-out-of-scope-pci-charade/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 01:26:21 +0000</pubDate>
		<dc:creator>Security Blogger</dc:creator>
				<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Risk Compliance]]></category>

		<guid isPermaLink="false">http://siblog.mcafee.com/?p=1500</guid>
		<description><![CDATA[What is out-of-scope related to PCI and who decides?]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/11/the-dangerous-out-of-scope-pci-charade/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OWASP Top Ten for 2010 Released</title>
		<link>http://www.thesecurityblog.com/2009/11/owasp-top-ten-for-2010-released/</link>
		<comments>http://www.thesecurityblog.com/2009/11/owasp-top-ten-for-2010-released/#comments</comments>
		<pubDate>Sat, 14 Nov 2009 02:00:00 +0000</pubDate>
		<dc:creator>Security Blogger</dc:creator>
				<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Late today (Friday) a preliminary update to the OWASP 10 for 2010 was released (click here).  As most of you know, PCI compliance requires (among a bunch of other things...) that all custom code be reviewed so as not to be vulnerable to these exploits....]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/11/owasp-top-ten-for-2010-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>It’s Not Just For Card Data Any More</title>
		<link>http://www.thesecurityblog.com/2009/11/its-not-just-for-card-data-any-more/</link>
		<comments>http://www.thesecurityblog.com/2009/11/its-not-just-for-card-data-any-more/#comments</comments>
		<pubDate>Wed, 11 Nov 2009 23:09:07 +0000</pubDate>
		<dc:creator>Security Blogger</dc:creator>
				<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://siblog.mcafee.com/?p=1433</guid>
		<description><![CDATA[PCI rules are designed for payment cards, but the same common-sense security guidelines will also dramatically help security in other areas.]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/11/its-not-just-for-card-data-any-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Processor Best Practices You Can Use</title>
		<link>http://www.thesecurityblog.com/2009/10/processor-best-practices-you-can-use/</link>
		<comments>http://www.thesecurityblog.com/2009/10/processor-best-practices-you-can-use/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 21:03:00 +0000</pubDate>
		<dc:creator>Walt Conway</dc:creator>
				<category><![CDATA[Carousel]]></category>
		<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Visa just released its Cardholder Data Security Best Practices for VisaNet Processors.  I think there are some things in this document that you as merchants can use, too.  Here are a few examples with my comments/observations:Entities should identify t...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/10/processor-best-practices-you-can-use/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Personal Note</title>
		<link>http://www.thesecurityblog.com/2009/10/a-personal-note/</link>
		<comments>http://www.thesecurityblog.com/2009/10/a-personal-note/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 05:31:00 +0000</pubDate>
		<dc:creator>Walt Conway</dc:creator>
				<category><![CDATA[Legal & Regulatory]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I hope you will allow me this personal blog post, but I learned today that David Taylor of the PCI Knowledge Base passed away suddenly Tuesday.  Dave was a friend and colleague.  I was privileged to know and work with Dave.  He built the PCI Knowledge ...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/10/a-personal-note/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is Your Web App Secure?  Really?</title>
		<link>http://www.thesecurityblog.com/2009/10/is-your-web-app-secure-really/</link>
		<comments>http://www.thesecurityblog.com/2009/10/is-your-web-app-secure-really/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 21:58:00 +0000</pubDate>
		<dc:creator>Walt Conway</dc:creator>
				<category><![CDATA[Carousel]]></category>
		<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[The Web Application Security Consortium (WASC) today announced the findings of its WASC Web Application Security Statistics Project 2008.  Their objective was to pool data from a number of sources to assess the vulnerability of web applications across ...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/10/is-your-web-app-secure-really/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Keeping Informed</title>
		<link>http://www.thesecurityblog.com/2009/10/keeping-informed/</link>
		<comments>http://www.thesecurityblog.com/2009/10/keeping-informed/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 17:32:00 +0000</pubDate>
		<dc:creator>Security Blogger</dc:creator>
				<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[One of the hardest parts about payments and PCI is keeping informed of new developments, state laws, emerging threat vectors, and ideas about what may be coming.  You are already making a start by reading this blog (c'mon...what did you expect me to sa...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/10/keeping-informed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Merchant Levels Cleared or Confused?</title>
		<link>http://www.thesecurityblog.com/2009/10/pci-merchant-levels-cleared-or-confused/</link>
		<comments>http://www.thesecurityblog.com/2009/10/pci-merchant-levels-cleared-or-confused/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 15:45:00 +0000</pubDate>
		<dc:creator>Walt Conway</dc:creator>
				<category><![CDATA[Carousel]]></category>
		<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Branden Williams writes that Visa and MasterCard have pulled the "reciprocity" from their merchant level definitions (see here).  For those of you not up on all the details, I'll try and explain what's going on.Let's say you have 1 million Visa transac...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/10/pci-merchant-levels-cleared-or-confused/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Operation Phish Phry</title>
		<link>http://www.thesecurityblog.com/2009/10/operation-phish-phry/</link>
		<comments>http://www.thesecurityblog.com/2009/10/operation-phish-phry/#comments</comments>
		<pubDate>Thu, 08 Oct 2009 16:11:00 +0000</pubDate>
		<dc:creator>Walt Conway</dc:creator>
				<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[Phish]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[How full is the "junk" folder in your email account?  If you are like me, it gets filled faster each day with junk email.  Most of these emails are simply, well, junk.  But some are phishing emails sent by genuine bad guys trying to get me to divulge a...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/10/operation-phish-phry/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Your Campus Hotel and PCI</title>
		<link>http://www.thesecurityblog.com/2009/10/your-campus-hotel-and-pci/</link>
		<comments>http://www.thesecurityblog.com/2009/10/your-campus-hotel-and-pci/#comments</comments>
		<pubDate>Tue, 06 Oct 2009 15:23:00 +0000</pubDate>
		<dc:creator>Walt Conway</dc:creator>
				<category><![CDATA[Carousel]]></category>
		<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I have been working with and talking to a number of schools recently that operate hotels on campus.  These hotel operations face particular PCI compliance challenges due to the nature of the hotel business.  That is, they hold lots of cardholder data l...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/10/your-campus-hotel-and-pci/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>POS PIN-entry Vulnerabilities</title>
		<link>http://www.thesecurityblog.com/2009/10/pos-pin-entry-vulnerabilities/</link>
		<comments>http://www.thesecurityblog.com/2009/10/pos-pin-entry-vulnerabilities/#comments</comments>
		<pubDate>Mon, 05 Oct 2009 23:08:00 +0000</pubDate>
		<dc:creator>Walt Conway</dc:creator>
				<category><![CDATA[Carousel]]></category>
		<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Those of you with PIN-entry devices (PEDs) at your point of sale (POS) should take a look at Visa's POS PIN Entry Device Vulnerabilities white paper out today. Visa reports on the increasing number of thefts of PEDs from merchant stores.  The theft is ...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/10/pos-pin-entry-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Purchasing, Travel, and Corporate Cards and PCI Scope &#8211; Some Closure!</title>
		<link>http://www.thesecurityblog.com/2009/09/purchasing-travel-and-corporate-cards-and-pci-scope-some-closure/</link>
		<comments>http://www.thesecurityblog.com/2009/09/purchasing-travel-and-corporate-cards-and-pci-scope-some-closure/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 17:17:00 +0000</pubDate>
		<dc:creator>Security Blogger</dc:creator>
				<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I have blogged here (see here with comments, and here, and here) and elsewhere about whether “corporate cards” used for travel and purchasing should be in the “issuing” school’s own scope for PCI.  In other words, if a university (or Megacorp...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/09/purchasing-travel-and-corporate-cards-and-pci-scope-some-closure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Community Meeting &#8211; Day 2</title>
		<link>http://www.thesecurityblog.com/2009/09/pci-community-meeting-day-2/</link>
		<comments>http://www.thesecurityblog.com/2009/09/pci-community-meeting-day-2/#comments</comments>
		<pubDate>Thu, 24 Sep 2009 22:38:00 +0000</pubDate>
		<dc:creator>Walt Conway</dc:creator>
				<category><![CDATA[Carousel]]></category>
		<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Day 2 of the PCI Community Meeting is just concluded. We heard from former Representative Tom Davis about the prospects for federal legislation addressing cyber security.  My take from the presentation is that such legislation is not very likely, and c...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/09/pci-community-meeting-day-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Community Meeting &#8211; Day 1 at The Listening Meeting</title>
		<link>http://www.thesecurityblog.com/2009/09/pci-community-meeting-day-1-at-the-listening-meeting/</link>
		<comments>http://www.thesecurityblog.com/2009/09/pci-community-meeting-day-1-at-the-listening-meeting/#comments</comments>
		<pubDate>Thu, 24 Sep 2009 00:46:00 +0000</pubDate>
		<dc:creator>Walt Conway</dc:creator>
				<category><![CDATA[Carousel]]></category>
		<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I'm here in Las Vegas with 650 of my closest PCI friends, including Tom Davis of Indiana Univeristy (For those of you who forgot, we represent NACUBO which is a Participating Organization).  The PCI Community Meeting - this is the third - seems about t...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/09/pci-community-meeting-day-1-at-the-listening-meeting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Off to the PCI Community Meeting!</title>
		<link>http://www.thesecurityblog.com/2009/09/off-to-the-pci-community-meeting/</link>
		<comments>http://www.thesecurityblog.com/2009/09/off-to-the-pci-community-meeting/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 18:23:00 +0000</pubDate>
		<dc:creator>Security Blogger</dc:creator>
				<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I'm getting ready to head off to the PCI Community Meeting.  Tom Davis of IU and I will be there representing NACUBO and the Treasury Institute -- and therefore, YOU.  Thanks to those who sent in comments/questions.  I have dutifully forwarded them to ...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/09/off-to-the-pci-community-meeting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Being the &#8220;Bad Guy&#8221;</title>
		<link>http://www.thesecurityblog.com/2009/09/being-the-bad-guy/</link>
		<comments>http://www.thesecurityblog.com/2009/09/being-the-bad-guy/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 23:01:00 +0000</pubDate>
		<dc:creator>Walt Conway</dc:creator>
				<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Are we in the "no" business? I have to ask that question because of what I sometimes encounter in PCI assessments and even PCI training.  I recommend limiting Internet access or restricting access to cardholder data or changing a business process, and ...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/09/being-the-bad-guy/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>UPDATED: More on Choosing A QSA</title>
		<link>http://www.thesecurityblog.com/2009/09/updated-more-on-choosing-a-qsa/</link>
		<comments>http://www.thesecurityblog.com/2009/09/updated-more-on-choosing-a-qsa/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 23:43:00 +0000</pubDate>
		<dc:creator>Walt Conway</dc:creator>
				<category><![CDATA[Carousel]]></category>
		<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I previously referenced an article on how to select a QSA.  Now there is another article (4 Ways to Get the Most From your PCI QSAs) at Computerworld with similarly good advice.It all boils down to your taking some time, checking out the actual people ...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/09/updated-more-on-choosing-a-qsa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Real Cost of a Security Breach?</title>
		<link>http://www.thesecurityblog.com/2009/09/real-cost-of-a-security-breach/</link>
		<comments>http://www.thesecurityblog.com/2009/09/real-cost-of-a-security-breach/#comments</comments>
		<pubDate>Tue, 08 Sep 2009 03:57:00 +0000</pubDate>
		<dc:creator>Walt Conway</dc:creator>
				<category><![CDATA[Carousel]]></category>
		<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[There is a standard benchmark used to calculate the cost of a security breach: about $200 per account compromised.  But often the compromise is not based on, say, compromised payment cards.  Sometimes there is a whole lot of other damage that can run u...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/09/real-cost-of-a-security-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Procurement Cards Can Be Breached, Too</title>
		<link>http://www.thesecurityblog.com/2009/09/procurement-cards-can-be-breached-too/</link>
		<comments>http://www.thesecurityblog.com/2009/09/procurement-cards-can-be-breached-too/#comments</comments>
		<pubDate>Fri, 04 Sep 2009 01:00:00 +0000</pubDate>
		<dc:creator>Security Blogger</dc:creator>
				<category><![CDATA[Legal & Regulatory]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[The University of Vermont reported that up to 240 university-funded procurement cards appear to have been compromised/breached.  I don't know all the details, but it gives me the opportunity to raise two important points. The first is that your procure...]]></description>
		<wfw:commentRss>http://www.thesecurityblog.com/2009/09/procurement-cards-can-be-breached-too/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Served from: www.thesecurityblog.com @ 2012-02-10 17:30:58 by W3 Total Cache -->
