Tag Archives: PCI DSS

Expecting the Unexpected, Removing Fear From a Security Incident

Once again another company is on the heels of a massive data breach where intellectual property, customer records, private information, you-name-it, has been compromised, a security incident. The recent news of Adobe Systemsi where a malicious entity stole intellectual property and accessed millions of credit card numbers is another case where “if there is a […]

The PCI Security Standards Council has released a new Information supplement for PCI DSS Risk Assessment Guidelines.

The PCI Security Standards Council has released a new Information supplement for PCI DSS Risk Assessment Guidelines. Organizations planning and performing a risk assessment in accordance with PCI DSS 12.1.2 can use the information supplement to help identify threats and the associated vulnerabilities that could jeopardize the security of payment card data.

PCI DSS 11.2 and 11.3

A quick note about PCI DSS compliance and scanning vs. penetration testing and PCI DSS 11.2 and 11.3.  Often (too often) when I’m talking with organizations about their PCI compliance, they respond that they’re already compliant and they already have someone doing their quarterly scanning for them.  That’s great, I say!  Then I ask about […]