November 17, 2009 - Dominating many discussions over the last few weeks in payment security circles has been speculation over what the PCI Council, Visa and others will decide about declaring some types of data out-of-scope for PCI purposes. Getting much less attention (continue reading...) Read more
November 13, 2009 - Late today (Friday) a preliminary update to the OWASP 10 for 2010 was released (click here). As most of you know, PCI compliance requires (among a bunch of other things...) that all custom code be reviewed so as (continue reading...) Read more
November 11, 2009 - With all of the recent fuss about PCI requirements and how to protect payment cards, many companies have opted to take a far too narrow view of data protection. The PCI rules are absolutely designed to only apply to payment (continue reading...) Read more
October 29, 2009 - Visa just released its Cardholder Data Security Best Practices for VisaNet Processors. I think there are some things in this document that you as merchants can use, too. Here are a few examples with my comments/observations:Entities (continue reading...) Read more
October 20, 2009 - The Web Application Security Consortium (WASC) today announced the findings of its WASC Web Application Security Statistics Project 2008. Their objective was to pool data from a number of sources to assess the vulnerability of web applications (continue reading...) Read more
October 20, 2009 - One of the hardest parts about payments and PCI is keeping informed of new developments, state laws, emerging threat vectors, and ideas about what may be coming. You are already making a start by reading this blog (c'mon...what did (continue reading...) Read more
October 20, 2009 - Branden Williams writes that Visa and MasterCard have pulled the "reciprocity" from their merchant level definitions (see here). For those of you not up on all the details, I'll try and explain what's going on.Let's (continue reading...) Read more
October 6, 2009 - I have been working with and talking to a number of schools recently that operate hotels on campus. These hotel operations face particular PCI compliance challenges due to the nature of the hotel business. That is, they hold (continue reading...) Read more
October 5, 2009 - Those of you with PIN-entry devices (PEDs) at your point of sale (POS) should take a look at Visa's POS PIN Entry Device Vulnerabilities white paper out today. Visa reports on the increasing number of thefts of (continue reading...) Read more
October 5, 2009 - Visa has just released a pdf on data field encryption, aka end-to-end encryption. You can download it here.There has been a lot of interest in this technology which was featured as a potentially game-changing technology at (continue reading...) Read more
September 25, 2009 - I have blogged here (see here with comments, and here, and here) and elsewhere about whether “corporate cards” used for travel and purchasing should be in the “issuing” school’s own scope for PCI. In other (continue reading...) Read more
September 24, 2009 - Day 2 of the PCI Community Meeting is just concluded. We heard from former Representative Tom Davis about the prospects for federal legislation addressing cyber security. My take from the presentation is that such legislation is not (continue reading...) Read more
September 23, 2009 - I'm here in Las Vegas with 650 of my closest PCI friends, including Tom Davis of Indiana Univeristy (For those of you who forgot, we represent NACUBO which is a Participating Organization). The PCI Community Meeting - this is (continue reading...) Read more
September 21, 2009 - I'm getting ready to head off to the PCI Community Meeting. Tom Davis of IU and I will be there representing NACUBO and the Treasury Institute -- and therefore, YOU. Thanks to those who sent in comments/questions. (continue reading...) Read more
September 15, 2009 - Are we in the "no" business?I have to ask that question because of what I sometimes encounter in PCI assessments and even PCI training. I recommend limiting Internet access or restricting access to cardholder data or changing a business process, (continue reading...) Read more
September 10, 2009 - I previously referenced an article on how to select a QSA. Now there is another article (4 Ways to Get the Most From your PCI QSAs) at Computerworld with similarly good advice.It all boils down (continue reading...) Read more
September 7, 2009 - There is a standard benchmark used to calculate the cost of a security breach: about $200 per account compromised. But often the compromise is not based on, say, compromised payment cards. Sometimes there is a whole lot (continue reading...) Read more
September 3, 2009 - The University of Vermont reported that up to 240 university-funded procurement cards appear to have been compromised/breached. I don't know all the details, but it gives me the opportunity to raise two important points. The first (continue reading...) Read more
September 1, 2009 - OK, time for a little personal news here... Today it became official: I'm a QSA (Qualified Security Assessor). Until I joined 403 Labs, I could be a PCI consultant, but not a QSA. Now as part (continue reading...) Read more
September 1, 2009 - The recent breaches and indictments have generated a lot of comments about PCI, many of them unfavorable. On one side are those that say they were "certified" as PCI compliant, but got breached anyway; therefore PCI is worthless. (continue reading...) Read more