<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/wordpress-mu-1.2.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Regulatory Compliance, Governance and Security</title>
	<link>http://itknowledgeexchange.techtarget.com/compliance-governance</link>
	<description></description>
	<pubDate>Sat, 29 Nov 2008 17:31:44 +0000</pubDate>
	<generator>http://wordpress.org/?v=wordpress-mu-1.2.1</generator>
	<language>en</language>
			<item>
		<title>SAS 70 Type II Audits &#124; An Auditor&#8217;s Expert Opinion on Pricing</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audits-an-auditors-expert-opinion-on-pricing/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audits-an-auditors-expert-opinion-on-pricing/#comments</comments>
		<pubDate>Sat, 29 Nov 2008 17:30:27 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
		
		<category><![CDATA[Compliance]]></category>

		<category><![CDATA[SAS 70]]></category>

		<category><![CDATA[SAS 70 readiness questionnaire]]></category>

		<category><![CDATA[sas 70 audit report]]></category>

		<category><![CDATA[sas 70 control objectives]]></category>

		<category><![CDATA[sas 70 type i]]></category>

		<category><![CDATA[sas 70 type ii]]></category>

		<category><![CDATA[sas70]]></category>

		<category><![CDATA[sas70 pricing]]></category>

		<category><![CDATA[sas70 readiness assessment questionnaires]]></category>

		<category><![CDATA[sas70 sample reports]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audits-an-auditors-expert-opinion-on-pricing/</guid>
		<description><![CDATA[People often ask me what the price of a SAS 70 Type I or SAS 70 Type II audit is. My response? That depends, I say, on many, many factors.  Here is what needs to be understood when considering pricing factors for SAS 70 Type I and Type II audits:
1. The CPA firm-Are you [...]]]></description>
			<content:encoded><![CDATA[<p>People often ask me what the price of a <a href="http://www.sas70.us.com">SAS 70</a> Type I or SAS 70 Type II audit is. My response? That depends, I say, on many, many factors.  Here is what needs to be understood when considering pricing factors for SAS 70 Type I and Type II audits:</p>
<p>1. The CPA firm-Are you looking for brand recognition or are you looking for a cost-effective provider which can simply help you &#8220;check the box&#8221; for SAS 70 compliance.</p>
<p>2. Scope-What is being examined and tested from a control perspective for SAS 70 audits? Are you looking for just a general controls audit or an audit that also includes specific business processes?</p>
<p>3. Testing period: For SAS 70 Type II audits, what is the testing period going to be? The longer the test period, the more the audit will cost as auditors have to pull larger samples, do more testing, etc.</p>
<p>4. Location of testing: How many physical areas does your organization have that will fall under the scope of the SAS 70 audit? Having more than one means that auditors will ultimately have to travel to numerous locations to conduct more testing. Again, more locations, more time, money, and expenses out of your pocket for the audit itself.</p>
<p>5. Are you confident you can obtain SAS 70 compliance without conducting a SAS 70 readiness assessment? If not and you need assistance identifying weaknesses and gaps within your control environment, then expect to spend more time, money, and resources on the front end of a SAS 70 audit for preparing in an adequate manner.</p>
<p>As you can see, there is no quick, easy, black and white answer to the cost of a SAS 70 Type I or Type II audit. </p>
<p>To learn more about statement of auditing standards no. 70, <a href="http://www.sas70.us.com">visit the official sas 70 resource guide</a>, where you can obtain a wealth of information on sas 70 audits.</p>
]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audits-an-auditors-expert-opinion-on-pricing/feed/</wfw:commentRss>
		</item>
		<item>
		<title>SAS 70 Audit Reports &#124; Start with a SAS 70 Readiness Assessment</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-reports-start-with-a-sas-70-readiness-assessmnet/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-reports-start-with-a-sas-70-readiness-assessmnet/#comments</comments>
		<pubDate>Fri, 28 Nov 2008 22:43:08 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
		
		<category><![CDATA[audits]]></category>

		<category><![CDATA[SAS 70]]></category>

		<category><![CDATA[SAS 70 readiness questionnaire]]></category>

		<category><![CDATA[sas 70 audit report]]></category>

		<category><![CDATA[sas 70 control objectives]]></category>

		<category><![CDATA[sas 70 sample report]]></category>

		<category><![CDATA[sas 70 type i]]></category>

		<category><![CDATA[sas 70 type ii]]></category>

		<category><![CDATA[sas70]]></category>

		<category><![CDATA[sas70 readiness assessment questionnaires]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-reports-start-with-a-sas-70-readiness-assessmnet/</guid>
		<description><![CDATA[Successful completion of SAS 70 Type I or SAS 70 Type II audit reports should start with undertaking a SAS 70 Readiness Assessment. A readiness assessment is an important part of the audit process in that it helps identify weaknesses, gaps, and deficiencies within your organization&#8217;s control environment.  Many organizations unfortunately rush into a [...]]]></description>
			<content:encoded><![CDATA[<p>Successful completion of SAS 70 Type I or SAS 70 Type II audit reports should start with undertaking a SAS 70 Readiness Assessment. A readiness assessment is an important part of the audit process in that it helps identify weaknesses, gaps, and deficiencies within your organization&#8217;s control environment.  Many organizations unfortunately rush into a SAS 70 Type I or Type II audit, and as a result, suffer the consequences of ill-planning and mismanagement. The result? More time, fees, and man hours are put into the audit, which in all actuality, really shouldn&#8217;t of been if they had started off with a readiness assessment. </p>
<p>Furthermore, some firms even offer <a href="http://www.sas70.us.com">free SAS 70 Readiness Assessment questionnaires</a> for helping your organization prepare and undertake the audit itself.  What&#8217;s more, quality CPA firms can develop templates that are highly customized to your specific industry, thus adding even more value to the SAS 70 Readiness Assessment phase. As the old saying goes, you crawl before you walk, it&#8217;s wise to conduct a SAS 70 Readiness Assessment before embarking on the actual audit process.</p>
<p>To learn more about SAS 70 audits, visit the official <a href="http://www.sas70.us.com">SAS 70 Resource Guide</a>, where you can obtain a  wealth of information on SAS 70 audits.</p>
]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-reports-start-with-a-sas-70-readiness-assessmnet/feed/</wfw:commentRss>
		</item>
		<item>
		<title>SAS 70 Type II Audit Reports &#124; Why SAS 70 is Here to Stay</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audit-reports-why-sas-70-is-here-to-stay/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audit-reports-why-sas-70-is-here-to-stay/#comments</comments>
		<pubDate>Sun, 23 Nov 2008 19:46:09 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
		
		<category><![CDATA[GLBA]]></category>

		<category><![CDATA[HIPAA]]></category>

		<category><![CDATA[regulatory compliance]]></category>

		<category><![CDATA[SAS 70]]></category>

		<category><![CDATA[SOX]]></category>

		<category><![CDATA[What is SAS 70?]]></category>

		<category><![CDATA[sas 70 audit report]]></category>

		<category><![CDATA[sas 70 control objectives]]></category>

		<category><![CDATA[sas 70 type ii]]></category>

		<category><![CDATA[sas70]]></category>

		<category><![CDATA[section 404 sox]]></category>

		<category><![CDATA[Sarbanes-Oxley]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audit-reports-why-sas-70-is-here-to-stay/</guid>
		<description><![CDATA[We live in a world of heightened regulatory compliance and corporate governance. From the passage of the 2002 Sarbanes-Oxley Act to numerous other pieces of legislation (HIPAA, GLBA, just to name a few), &#8220;comply, comply, comply&#8221; is the new mantra being pushed throughout organizations and at all levels. SAS 70 audits, originally introduced as the [...]]]></description>
			<content:encoded><![CDATA[<p>We live in a world of heightened regulatory compliance and corporate governance. From the passage of the 2002 Sarbanes-Oxley Act to numerous other pieces of legislation (HIPAA, GLBA, just to name a few), &#8220;comply, comply, comply&#8221; is the new mantra being pushed throughout organizations and at all levels. <strong><a href="http://www.sas70.us.com">SAS 70 audits</a></strong>, originally introduced as the 70th auditing standard in April of 1992, has stood the test of time as the main &#8220;go to&#8221; compliance audit for many of these regulatory requirements that have ushered from the halls of Congress.  </p>
<p>Okay, so, why is it here to stay? Well, for a number of reasons. First and foremost, it will always be used as an audit tool for evaluating service organization&#8217;s that could have a material impact to a company&#8217;s &#8220;information system&#8221;-This term, &#8220;information system&#8221; is used to describe the user organization&#8217;s &#8220;information system&#8221;, that is, what services are being performed by the service organization that are considered a part of the user organization&#8217;s &#8220;information system&#8221;. Transactions, procedures (be it manual or automated), supporting information, the capturing of events and conditions-are all considered traits and activities that relate to, have an effect, and impact the user organization&#8217;s &#8220;information system&#8221;.</p>
<p>Second, the SAS 70 auditing standard has been quite flexible, adapting to the needs of service organizations that must have their control environment examined.  Witness the numerous times the SAS 70 auditing standard has been amended over the last 16 years to keep &#8220;pace&#8221; with the changes of business.  </p>
<p>Third, the SAS 70 auditing standard has become very quickly recognized as the global de facto audit for internal controls on service organizations. In short, it has built up quite a following that is simply very hard to ignore.</p>
<p>To learn more about SAS 70 audits, visit the official <strong><a href="http://www.sas70.us.com">SAS 70 Resource Guide</a>.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audit-reports-why-sas-70-is-here-to-stay/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Payment Card Industry (PCI DSS) Compliance &#124; Requirement 1.1.2</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-dss-compliance-requirement-112/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-dss-compliance-requirement-112/#comments</comments>
		<pubDate>Sun, 23 Nov 2008 19:24:51 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
		
		<category><![CDATA[pci dss requirement 1.1.2]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[pci compliance]]></category>

		<category><![CDATA[PCI DSS]]></category>

		<category><![CDATA[regulatory compliance]]></category>

		<category><![CDATA[SAS 70]]></category>

		<category><![CDATA[payment card industry]]></category>

		<category><![CDATA[payment card industry data security standards]]></category>

		<category><![CDATA[pci assessment]]></category>

		<category><![CDATA[pci dss qsa]]></category>

		<category><![CDATA[policies and procedures]]></category>

		<category><![CDATA[qsa]]></category>

		<category><![CDATA[sas 70 audit report]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-dss-compliance-requirement-112/</guid>
		<description><![CDATA[Payment Card Industry (PCI) Data Security Standards (DSS) compliance for PCI DSS requirement 1.1.2 calls for &#8220;Current network diagram with all connections to cardholder data, including any wireless networks&#8221; Thus, testing for validating 1.1.2 requires verification &#8220;that a current network diagram (for example, one that shows cardholder data flows over the network) exists and that [...]]]></description>
			<content:encoded><![CDATA[<p>Payment Card Industry (PCI) Data Security Standards (DSS) compliance for <strong><a href="http://www.pciassessment.org">PCI DSS</a></strong> requirement 1.1.2 calls for &#8220;Current network diagram with all connections to cardholder data, including any wireless networks&#8221; Thus, testing for validating 1.1.2 requires verification &#8220;that a current network diagram (for example, one that shows cardholder data flows over the network) exists and that it documents all connections to cardholder data, including any wireless networks.&#8221; </p>
<p>Okay, once again here, the key phrase is &#8220;current network diagrams&#8221;. What does this essentially mean? It means having a subject matter expert within your I.T. department developing a current network diagram and topology documents showing all critical connection points along with a visual of all critical hardware and network components that make up the network topology.  More importantly, these diagrams and network topology documents should be current and updated on a quarterly basis to reflect overall changes in the network layout of the organization.  Keep in mind that these documents will also be valuable for other regulatory compliance mandates, such as a <strong><a href="http://www.sas70.us.com ">SAS 70 Type II audit</a></strong>, which many merchants and service providers have to have at some point in their business lifecycle.  </p>
<p>And though the requirement for PCI DSS 1.1.2 calls for these network diagrams for only &#8220;connections to cardholder data&#8221; its a very good  and wise idea to draw and map out your organization&#8217;s entire network topology. Why? Because it just makes good business sense and again, it helps with other regulatory compliance mandates that your organization may have to endure. </p>
<p>To learn more about SAS 70 audits, visit the official <strong><a href="http://www.sas70.us.com">SAS 70 Resource Guide</a></strong><br />
To learn more about PCI DSS compliance, visit <strong><a href="http://www.pciassessment.org">pciassessment.org </a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-dss-compliance-requirement-112/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Payment Card Industry (PCI DSS) Compliance &#124; Requirement 1.1.1</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-dss-compliance-requirement-111/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-dss-compliance-requirement-111/#comments</comments>
		<pubDate>Sun, 23 Nov 2008 19:14:11 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
		
		<category><![CDATA[pci dss requirement 1.1.1]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[pci compliance]]></category>

		<category><![CDATA[PCI DSS]]></category>

		<category><![CDATA[payment card industry]]></category>

		<category><![CDATA[payment card industry data security standards]]></category>

		<category><![CDATA[pci assessment]]></category>

		<category><![CDATA[pci dss qsa]]></category>

		<category><![CDATA[policies and procedures]]></category>

		<category><![CDATA[qsa]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-dss-compliance-requirement-111/</guid>
		<description><![CDATA[PCI DSS Requirement 1.1.1 calls for &#8220;A formal process for approving and testing all network connections and changes to the firewall and router configurations&#8221;. Thus, the test to validate this, in accordance with PCI DSS 1.2 standards is to &#8220;Verify that there is a formal process for testing and approval of all network connections and [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.pciassessment.org">PCI DSS</a></strong> Requirement 1.1.1 calls for &#8220;A formal process for approving and testing all network connections and changes to the firewall and router configurations&#8221;. Thus, the test to validate this, in accordance with PCI DSS 1.2 standards is to &#8220;Verify that there is a formal process for testing and approval of all network connections and changes to firewall and router configurations&#8221;. Thus, network connections, firewall rulesets/configurations and settings to routers must be placed in a proactive mode for ensuring continuous protection for the organization. As threats become known and as business needs change, this formal process needs to be documented to address this specifically. </p>
<p>The key phrase here my friends is &#8220;formal process&#8221;. What does that really mean? It means having documented policies and procedures in place for approving and testing connections/changes to these critical devices. Easier said than done as most organizations do not have the time or resources to formally write out documented policies and procedures. Beware, as this is a very large part of ensuring PCI DSS compliance. To learn more about PCI DSS and documented policies and procedures for PCI DSS compliance, visit <strong><a href="http://www.pciassessment.org/pci-services.php">pciassessment.org</a></strong>.</p>
]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-dss-compliance-requirement-111/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Payment Card Industry (PCI DSS) Compliance &#124; Requirement 1.1</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-dss-compliance-requirement-11/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-dss-compliance-requirement-11/#comments</comments>
		<pubDate>Sun, 23 Nov 2008 19:03:20 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
		
		<category><![CDATA[configurations]]></category>

		<category><![CDATA[ports]]></category>

		<category><![CDATA[firewalls]]></category>

		<category><![CDATA[requirement 1.1]]></category>

		<category><![CDATA[requirement 1.0]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[pci compliance]]></category>

		<category><![CDATA[PCI DSS]]></category>

		<category><![CDATA[regulatory compliance]]></category>

		<category><![CDATA[payment card industry]]></category>

		<category><![CDATA[pci assessment]]></category>

		<category><![CDATA[pci dss qsa]]></category>

		<category><![CDATA[qsa]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-dss-compliance-requirement-11/</guid>
		<description><![CDATA[Payment Card Industry (PCI) Data Security Standards (DSS) for Requirement 1.1 require organizations to &#8220;Establish firewall and router configuration standards&#8221;. This requirement falls under the functional area of the overall Requirement 1.0, which states that organizations must &#8220;Install and maintain a firewall configuration to protect cardholder data&#8221;. So, what does this requirement 1.1 specifically mean [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.pciassessment.org">Payment Card Industry (PCI) Data Security Standards (DSS)</a></strong> for Requirement 1.1 require organizations to &#8220;Establish firewall and router configuration standards&#8221;. This requirement falls under the functional area of the overall Requirement 1.0, which states that organizations must &#8220;Install and maintain a firewall configuration to protect cardholder data&#8221;. So, what does this requirement 1.1 specifically mean and what do merchants, service providers and other supporting organizations need to be aware of?  In short, PCI DSS requirements for 1.1 call for organizations to &#8220;Obtain and inspect the firewall and router configuration standards and other documentation specified below to verify that standards are complete&#8221;.  In essence, its a rather straightforward testing approach that requires that configuration standards are commensurate and in line with the business needs of the organization for ensuring that no unwanted or malicious traffic is kept out and that only the traffic designated is allowed through.  A PCI QSA can verify this requirement by consulting and inspecting the current firewall settings and configurations.  Take note, as all unnecessary ports and configurations should be closed if they are not suitable or conducive to the cardholder environment.  To learn more about PCI DSS, visit <strong><a href="http://www.pciassessment.org">pciassessment.org </a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-dss-compliance-requirement-11/feed/</wfw:commentRss>
		</item>
		<item>
		<title>PCI DSS Readiness Assessment for Payment Card Industry Compliance</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-readiness-assessment-for-payment-card-industry-compliance/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-readiness-assessment-for-payment-card-industry-compliance/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 03:28:02 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[pci compliance]]></category>

		<category><![CDATA[PCI DSS]]></category>

		<category><![CDATA[merchants]]></category>

		<category><![CDATA[payment card industry]]></category>

		<category><![CDATA[payment card industry data security standards]]></category>

		<category><![CDATA[pci assessment]]></category>

		<category><![CDATA[pci dss qsa]]></category>

		<category><![CDATA[service providers]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-readiness-assessment-for-payment-card-industry-compliance/</guid>
		<description><![CDATA[Are you a merchant or service provider that needs to be Payment Card Industry Data Security Standards (PCI DSS) compliance? Are you an entity directly involved in the processing, storage, or transmission of transaction data or cardholder data? If so, then read on because one of the most important steps for ensuring PCI DSS compliance [...]]]></description>
			<content:encoded><![CDATA[<p>Are you a merchant or service provider that needs to be Payment Card Industry Data Security Standards (PCI DSS) compliance? Are you an entity directly involved in the processing, storage, or transmission of transaction data or cardholder data? If so, then read on because one of the most important steps for ensuring PCI DSS compliance is done in an efficient manner is to start with a PCI DSS Readiness Assessment. Why? Well, you crawl before you walk don&#8217;t you? As with PCI DSS compliance, its not wise to jump right in and obtain an assessment without doing any type of due diligence work on your organization. </p>
<p>One of the main benefits of a PCI DSS Readiness Assessment is the ability to identify gaps, deficiencies, and core weaknesses that will be need to be strengthened and corrected before obtaining any type of PCI DSS assessment from a Qualified Security Assessor Company, commonly known as a QSAC. <strong><a href="http://www.pciassessment.org/pci-dss-readiness-assessment.php">Learn more about a PCI DSS Readiness Assessment</a></strong> at <strong><a href="http://www.pciassessment.org">pciassessment.org</a></strong> </p>
]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-readiness-assessment-for-payment-card-industry-compliance/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Minnesota (MN) Plastic Card Security Act &#124; Payment Card Industry (PCI DSS) Compliance</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/minnesota-mn-plastic-card-security-act-payment-card-industry-pci-dss-compliance/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/minnesota-mn-plastic-card-security-act-payment-card-industry-pci-dss-compliance/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 02:53:15 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
		
		<category><![CDATA[Minnesota (MN) Plastic Card Security Act]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[pci compliance]]></category>

		<category><![CDATA[PCI DSS]]></category>

		<category><![CDATA[payment card industry]]></category>

		<category><![CDATA[payment card industry data security standards]]></category>

		<category><![CDATA[pci assessment]]></category>

		<category><![CDATA[pci dss qsa]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/minnesota-mn-plastic-card-security-act-payment-card-industry-pci-dss-compliance/</guid>
		<description><![CDATA[The state of Minnesota recently codified part of the Payment Card Industry (PCI) Data Security Standards (PCI) framework into actual law.  Thus, Minnesota has essentially become the first state to codify the PCI standards into actual law; an actual watershed decision to say the least, with many states soon to follow in their footsteps. [...]]]></description>
			<content:encoded><![CDATA[<p>The state of Minnesota recently <strong><a href="http://www.pciassessment.org/news/headlines/mn-plastic-card-security-act/">codified part of the Payment Card Industry</a></strong> (PCI) Data Security Standards (PCI) framework into actual law.  Thus, Minnesota has essentially become the first state to codify the PCI standards into actual law; an actual watershed decision to say the least, with many states soon to follow in their footsteps. In fact, Texas and California have taken great interest in PCI, as witnessed by both their respective bodies of legislatures introducing PCI provisions into the Senate and House chambers.  Though TX and CA were unsuccessful in passing any actual law that would of become codified, it does signal the growing strength that the Payment Card Industry Data Security Standards (PCI DSS) initiatives are having around the country.  </p>
<p>It seems likely that many other states will follow in the footsteps of MN, TX, and CA. Thus, merchants and service providers should be aware that they will be soon, if not already, under the compliance radar regarding PCI DSS compliance.</p>
<p>To learn more about Payment Card Industry Data Security Standards (PCI DSS) compliance, visit <strong><a href="http://www.pciassessment.org">pciassessment.org  </a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/minnesota-mn-plastic-card-security-act-payment-card-industry-pci-dss-compliance/feed/</wfw:commentRss>
		</item>
		<item>
		<title>SAS 70 Audit Costs and Pricing &#124; What You Need to Know</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-costs-and-pricing-what-you-need-to-know/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-costs-and-pricing-what-you-need-to-know/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 02:40:37 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
		
		<category><![CDATA[SAS 70]]></category>

		<category><![CDATA[sas 70 audit report]]></category>

		<category><![CDATA[sas 70 type i]]></category>

		<category><![CDATA[sas 70 type ii]]></category>

		<category><![CDATA[sas70]]></category>

		<category><![CDATA[sas70 pricing]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-costs-and-pricing-what-you-need-to-know/</guid>
		<description><![CDATA[If your organization is planning on undertaking a SAS 70 audit, be it a Type I or a Type II, then there are some important points you need to learn about SAS 70 audit pricing. 
First and foremost, make sure to get a &#8220;fixed fee&#8221; for the SAS 70 engagement a fixed fee includes all [...]]]></description>
			<content:encoded><![CDATA[<p>If your organization is planning on undertaking a SAS 70 audit, be it a Type I or a Type II, then there are some important points you need to learn about SAS 70 audit pricing. </p>
<p>First and foremost, make sure to get a &#8220;fixed fee&#8221; for the SAS 70 engagement a fixed fee includes all out of pocket, travel, and other miscellaneous expenses that are incurred by the auditor for purposes of conducting the audit. More and more firms are moving to the fixed fee model, so take advantage of this type of pricing.</p>
<p>Second, scope greatly determines <a href="http://www.sas70.us.com/what-is/sas70-pricing.php">the price of the SAS 70 audit</a>, so be sure to properly scope the audit. That means answering the who, what, when, where and why for the audit. Who needs the report and are there any specific requirements they are looking what. What is the audit test period. When will testing be done. Where will testing be done, such as what facilities will be part of the SAS 70 audit scope. These are all important points to cover when assessing scope for a SAS 70 Type I or SAS 70 Type II audit. </p>
<p>To learn more about SAS 70 audits, what is a SAS 70 and to obtain a wealth of information on the auditing standard itself, then visit the official <a href="http://www.sas70.us.com">SAS 70 Resource Guide</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-costs-and-pricing-what-you-need-to-know/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Payment Card Industry Data Security Standards (PCI DSS) &#124; Tips and Strategies</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-data-security-standards-pci-dss-tips-and-strategies/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-data-security-standards-pci-dss-tips-and-strategies/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 15:55:48 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
		
		<category><![CDATA[service providers]]></category>

		<category><![CDATA[merchants]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[pci compliance]]></category>

		<category><![CDATA[PCI DSS]]></category>

		<category><![CDATA[MN plastic card security act]]></category>

		<category><![CDATA[payment card industry]]></category>

		<category><![CDATA[payment card industry data security standards]]></category>

		<category><![CDATA[pci assessment]]></category>

		<category><![CDATA[policies and procedures]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-data-security-standards-pci-dss-tips-and-strategies/</guid>
		<description><![CDATA[If you are a merchant or service organization and need to be payment card industry (PCI) compliant with the PCI DSS provisions, then there are a number of important points you need to know. First and foremost, you need to identify what level you are in accordance with PCI DSS requirements. You can find this [...]]]></description>
			<content:encoded><![CDATA[<p>If you are a merchant or service organization and need to be payment card industry (PCI) compliant with the PCI DSS provisions, then there are a number of important points you need to know. First and foremost, you need to identify what level you are in accordance with PCI DSS requirements. You can find this information at pciassessment.org.  </p>
<p>Second, you will need to find a qualifed QSAC (Qualified Security Assessor Company) that can assist you with all levels of PCI compliance, regardless of what level you fall under. Third, you will need to have the QSAC conduct a PCI DSS readiness for understanding your cardholder transaction environment and what gaps, holes, and deficiencies you may have that could hinder the overall PCI DSS assessment process. Easier said than done? It sure is, as most companies are good at what they do, but are very weak in having documented policies and procedures in place for PCI DSS compliance. I stress this because it is one of the biggest and most often overlooked areas of PCI DSS compliance. While we all get carried away talking about firewalls, routers, anti-virus, DMZ, etc, many times organizations fail to recognize <a href="http://www.pciassessment.org/pci-policies-and-procedures.php">the importance of documented policies and procedures</a>. </p>
<p>To learn more about PCI DSS compliance, visit <a href="http://www.pciassessment.org">pciassessment.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-data-security-standards-pci-dss-tips-and-strategies/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
