New PCI Guidance Issued for Call Centers
The PCI Council has published new guidance for Call Centers handling credit cards via telephone, especially when VoIP is used, and also addresses issues surrounding the storage of recorded calls.
The PCI Council has published new guidance for Call Centers handling credit cards via telephone, especially when VoIP is used, and also addresses issues surrounding the storage of recorded calls.
A recent study by Imperva provides some interesting insights into the impact PCI Compliance is having in terms of the likelihood of a security breach.
I’ve heard so many variations on what it means to fill out the self-assessment questionnaire (SAQ) that I wanted to provide some clarification. First off, filling out the SAQ (regardless of which type) does NOT make you PCI compliant. You check boxes on the SAQ and that actually means something. It means that you are […]
QSA stands for Qualified Security Assessor, and they are certified by the PCI Security Standards Council. QSAs are tasked with providing guidance and validation to the DSS. QSAs are special in that they have been certified for their knowledge and ability to advise on the PCI DSS specifically. There are roughly 800 QSA individuals in North America […]
Information Security Management System. You can undergo a point in time audit or assessment and be compliant, but what happens a week later when patches have gone un-applied? Out of compliance again.
I’ve spoken with several people in the past few months that have come right out and said that they believed they were not compliant with the PCI and were simply unsure what to do. Their questions were basically the same; what should we do first, who should we tell, how long will this take, and the […]
The folks at processor.com have published an article with some helpful insights and suggestions for companies working on achieving or maintaining PCI DSS compliance.
A quick note about PCI DSS compliance and scanning vs. penetration testing and PCI DSS 11.2 and 11.3. Often (too often) when I’m talking with organizations about their PCI compliance, they respond that they’re already compliant and they already have someone doing their quarterly scanning for them. That’s great, I say! Then I ask about […]
PCI DSS v2.0 has been released. So what now? Summary of Changes: