Keeping It Simple – Part 1
Apparently, I struck a nerve with small business people trying to comply with PCI. In an ideal world, most merchants would be filling out SAQ A, but we do not live in an ideal world. As a result, I...
View ArticleInterested In Business As Usual?
I am encountering more and more organizations that are interested in business as usual or BAU. Organizations are finally realizing that the only way they are ever going to feel secure is to embed...
View ArticleDo Not Jump To Conclusions
A QSA apparently posed a question to the Council regarding the scope of wireless headsets used in a client’s call centers. In this case, the headsets rely on DECT technology. The response from the...
View ArticleLawyer Or Security Professional?
“It depends upon what the meaning of the word ‘is’ is. If ‘is’ means ‘is and never has been’ that’s one thing – if it means ‘there is none’, that was a completely true statement.” –President of The...
View ArticleThe ASV Process Is Broken – Part 3
So what are my ideas on fixing the ASV process? Modify The ASV Program The conditions that drove the ASV process originally made sense. Vulnerability scanning tools were predominately open source and...
View ArticleSecurity Or Checking A Box?
“Better to remain silent and be thought a fool than to speak out and remove all doubt.” Abraham Lincoln What is your organization interested in? Security or checking a box? Not surprisingly, most...
View ArticlePCI Compliance Is Getting More Rigorous
When Visa and MasterCard trotted out their security standards back in 2002 and 2003, the large eCommerce merchants that got to see them complained that they were too much. Fast forward more than a...
View ArticleSSL Is Officially Declared Dead
On January 30, 2015, QSAs received the latest edition of the Council’s Assessor Newsletter. Buried in that edition was the following statement. “Notice: PCI DSS and PA-DSS v3.1 Revisions Coming In...
View ArticleCouncil Surveys QSAs On SSL
This message popped into my inbox late yesterday. The survey in question contains the following questions. All of my clients have gotten rid of SSL on their public facing Web sites. The dilemma we have...
View ArticleThey Are Just Words
QSAs get asked a lot of “what ifs”. If I do ‘A’, will that result in ‘B’? What if I do ‘C’, will that accomplish ‘D’? If I do ‘E’, will that cause ‘F’? Where this really hits hard is when an...
View Article