PCI Compliance

Q&A with our QSA

The right Qualified Security Assessor (QSA) is crucial to the success of your organization’s security and compliance. HALOCK is fortunate to have a stellar team to support our clients. We are happy to highlight one of our key leaders on PCI, Viviana Wesley, PCI QSA, ISO 27001 Auditor, CISM. Get to know her with our quick Q&A:

(more…)

PCI SSC Resource Guide: Vulnerability Scans and Approved Scanning Vendors

The PCI Security Standards Council (PCI SSC) has published a Resource Guide: Vulnerability Scans and Approved Scanning Vendors

What is a Vulnerability Scan?

A process for identifying security weaknesses and flaws in systems and software. New vulnerabilities, security holes, and bugs are being discovered daily. Test your systems regularly to identify weaknesses and address them as soon as possible.

What is an Approved Scanning Vendor (more…)

Clarification on eCommerce Outsourcing PCI DSS requirements 6.4.3 and 11.6.1

By Viviana Wesley, PCI QSA, ISO 27001 Auditor, CISM
Principal Consultant, Governance, Compliance and Engineering Services

Did you see that version 4.0.1 of the PCI DSS that was recently published?

Within the updated document you will notice that requirements 6.4.3 and 11.6.1 have a new applicability note:

6.4.3 – “This requirement also applies to scripts in the entity’s webpage(s) that includes a TPSP’s/ payment processor’s embedded payment page/form (more…)

PCI SSC North America Community Meeting and Reducing PCI Scope

The PCI SSC North America Community Meetings bring together the brightest minds in payment security. This year’s event took place in Boston, MA on September 10-12. The theme is ‘Shaping the Future of Payment Security‘.

With the release of PCI DSS v4.0, and changing purchase environments, professionals are keen to understand best practices – especially in the area of reducing PCI scope. Toast, Target, and HALOCK (more…)

Guidance Related to PCI Compliance Scope for eCommerce Outsourcing

What is in Scope for eCommerce Outsourcing?

by Viviana Wesley, PCI QSA, ISO 27001 Auditor, CISM

UPDATED GUIDANCE June 2024

When an organization outsources their eCommerce environment to a third-party service provider (TPSP), the integration method used has a drastic impact on that organization’s PCI DSS compliance scope and applicable PCI DSS requirements. However, this was not explained very well before version 4.0 of the PCI DSS (more…)

Go to Top