 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Regulatory Compliance, Governance and Security &#187; pci dss compliance</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/compliance-governance/tag/pci-dss-compliance/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/compliance-governance</link>
	<description></description>
	<lastBuildDate>Thu, 10 Mar 2011 15:04:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>PCI DSS Compliance &#124; What&#8217;s New for 2010? &#124; An Auditor&#8217;s Viewpoint</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-whats-new-for-2010-an-auditors-viewpoint/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-whats-new-for-2010-an-auditors-viewpoint/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 22:06:05 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[pci dss compliance]]></category>
		<category><![CDATA[pci qsa]]></category>
		<category><![CDATA[qualified security assessor (QSA)]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-whats-new-for-2010-an-auditors-viewpoint/</guid>
		<description><![CDATA[PCI DSS Compliance will continue to be one of the most talked about regulatory compliance initiatives for 2010, without question. First and foremost, data breaches are still occurring, companies are still losing sensitive cardholder data, and lastly, PCI compliance is finally (yes finally) being taken seriously by merchants and service providers in today&#8217;s business arena. [...]]]></description>
				<content:encoded><![CDATA[<p>PCI DSS Compliance will continue to be one of the most talked about regulatory compliance initiatives for 2010, without question.  First and foremost, data breaches are still occurring, companies are still losing sensitive cardholder data, and lastly, PCI compliance is finally (yes finally) being taken seriously by merchants and service providers in today&#8217;s business arena.</p>
<p>As i&#8217;ve noted many times in previous posts, as a <strong><a href="http://www.pciassessment.org">Payment Card Industry Qualified Security Assessor (PCI QSA)</a></strong>, i&#8217;m seeing more and more organizations having to comply with PCI DSS, specifically with an on-site PCI DSS assessment. This can only be done by a QSA and be quite arduous of an undertaking, to say the least.  As 2010 ramps up and eventually whines itself down, I fully expect many merchants and service providers to undergo an annual on-site PCI assessment, more so than ever before. Technology is here to stay, cardholder data and the use of these small, but powerful pieces of plastic are here to stay my friends!  Let&#8217;s do what we can to protect them</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-whats-new-for-2010-an-auditors-viewpoint/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Readiness Assessments &#124; Hire a Qualified Security Assessor (QSA)</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-readiness-assessments-hire-a-qualified-security-assessor-qsa/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-readiness-assessments-hire-a-qualified-security-assessor-qsa/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 19:42:22 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[pci dss compliance]]></category>
		<category><![CDATA[pci dss readiness assessment]]></category>
		<category><![CDATA[qsa]]></category>
		<category><![CDATA[qualified security assessor]]></category>
		<category><![CDATA[service providers]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-readiness-assessments-hire-a-qualified-security-assessor-qsa/</guid>
		<description><![CDATA[PCI DSS compliance can be an arduous undertaking for many service providers and merchants in today&#8217;s business arena. Add to the fact the many organizations are unsure of the roadmap for PCI DSS compliance, it makes sense to hire a Qualified Security Assessor (QSA) in helping you conduct a PCI DSS Readiness Assessment. The most [...]]]></description>
				<content:encoded><![CDATA[<p>PCI DSS compliance can be an arduous undertaking for many service providers and merchants in today&#8217;s business arena. Add to the fact the many organizations are unsure of the roadmap for PCI DSS compliance, it makes sense to hire a <strong><a href="http://www.pciassessment.org">Qualified Security Assessor</a></strong> (QSA) in helping you conduct a PCI DSS Readiness Assessment.</p>
<p>The most important findings and deliverables out of a PCI DSS Readiness Assessment are that your organization will truly understand what the scope of the assessment process is, that is, what systems, processes, and activities are to be included.</p>
<p>Secondly, your organization will also have identified what gaps or weaknesses are currently in place that will need to be corrected before you can even plausibly think of becoming PCI DSS compliant.  </p>
<p>Additionally, a host of other helpful information can be provided by a Qualified Security Assessor when undertaking a PCI DSS Readiness Assessment. To learn more about PCI compliance, visit the official <strong><a href="http://www.pciassessment.org">PCI DSS Resource Guide</a></strong>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-readiness-assessments-hire-a-qualified-security-assessor-qsa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Compliance &#124; Watch out for the &#8220;Road Blocks&#8221;</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-watch-out-for-the-road-blocks/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-watch-out-for-the-road-blocks/#comments</comments>
		<pubDate>Sat, 29 Aug 2009 13:31:41 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[intrusion detection system]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[pci dss compliance]]></category>
		<category><![CDATA[qsa]]></category>
		<category><![CDATA[qualified security assessor]]></category>
		<category><![CDATA[report on compliance]]></category>
		<category><![CDATA[ROC]]></category>
		<category><![CDATA[service providers]]></category>
		<category><![CDATA[software code review]]></category>
		<category><![CDATA[two factor authentication]]></category>
		<category><![CDATA[web application firewall]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-watch-out-for-the-road-blocks/</guid>
		<description><![CDATA[PCI DSS Compliance, especially on-site reviews conducted by a Qualified Security Assessor (QSA), can take an immense amount of time in completing and receiving one&#8217;s Report on Compliance (ROC). What most merchants and service providers fail to recognize is that there are numerous issues that could potentially cause &#8220;roadblocks&#8221; on the way to achieving PCI [...]]]></description>
				<content:encoded><![CDATA[<p>PCI DSS Compliance, especially on-site reviews conducted by a Qualified Security Assessor (QSA), can take an immense amount of time in completing and receiving one&#8217;s Report on Compliance (ROC).<br />
What most merchants and service providers fail to recognize is that there are numerous issues that could potentially cause &#8220;roadblocks&#8221; on the way to achieving PCI DSS compliance.</p>
<p>As a QSA, I&#8217;ve listed some examples of common items that require remediation prior to achieving compliance. These items are considered major &#8220;roadblocks&#8221; because of either the time, money and investment needed to incorporate them into the cardholder data environment:</p>
<p>1. Two-factor authentication<br />
2. Web application firewall and/or software code reviews.<br />
3. Intrusion Detection Systems (IDS)<br />
4. Documented Policies and Procedures specifically related to PCI DSS compliance.</p>
<p>These four items are typically what catch merchants and service organizations off-guard. Be prepared, be proactive; find a quality, competent <strong><a href="http://www.pciassessment.org">QSA</a> </strong>to help with all your PCI DSS compliance needs.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-watch-out-for-the-road-blocks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Requirements for Service Providers &#124; Expert Advice from a QSA</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-requirements-for-service-providers-expert-advice-froma-qsa/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-requirements-for-service-providers-expert-advice-froma-qsa/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 11:40:01 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[amex]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[data centers]]></category>
		<category><![CDATA[Discover Card]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[jcb]]></category>
		<category><![CDATA[managed service providers]]></category>
		<category><![CDATA[mastercard]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[payment gateways]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[pci dss compliance]]></category>
		<category><![CDATA[pci qsa]]></category>
		<category><![CDATA[qualified security assessor]]></category>
		<category><![CDATA[service providers payment card compliance]]></category>
		<category><![CDATA[transaction processors]]></category>
		<category><![CDATA[visa]]></category>
		<category><![CDATA[web hosting providers]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-requirements-for-service-providers-expert-advice-froma-qsa/</guid>
		<description><![CDATA[PCI DSS compliance is becoming a requirement for many service providers involved in the processing, storage, transmission, and switching of transaction data and cardholder data. In short, a service provider, for purposes of Payment Card Industry Data Security Standards (PCI DSS) compliance includes companies that provide services to merchants, to other &#8220;service providers&#8221; or are [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.pciassessment.org">PCI DSS compliance</a> is becoming a requirement for many service providers involved in the processing, storage, transmission, and switching of transaction data and cardholder data.</p>
<p>In short, a service provider, for purposes of Payment Card Industry Data Security Standards (PCI DSS) compliance includes companies that provide services to merchants, to other &#8220;service providers&#8221; or are other entities that control OR could impact the security of cardholder data.</p>
<p>So, here are some common examples of service providers:</p>
<p>Transaction Processors<br />
Payment Gateways<br />
Customer Service Entities, such as Call Centers<br />
Managed Service Providers<br />
Web Hosting Providers<br />
Data Centers<br />
Independent Sales Organizations (ISO&#8217;s)</p>
<p>And you may also want to know that the major payment brands (VISA, MasterCard, AMEX, Discover Card, and JCB) have different &#8220;terms&#8221; for service providers.</p>
<p>AMEX-They are called a &#8220;Third Party Processor&#8221;<br />
Discover-They are called a &#8220;Third Party Processor&#8221; and a &#8220;Payment Service Provider&#8221;<br />
Mastercard-They are called &#8220;Third Party Processors&#8221; and a &#8220;Data Storage Entity&#8221;<br />
VISA-They can be called a &#8220;VisaNet Processor&#8221;, which is considered everybody that connects to VISA.</p>
<p>And generally speaking (with a noted exception), all Service Providers <a href="http://www.pciassessment.org/service-providers.php">will need an annual on-site Review</a> done by a <a href="http://www.pciassessment.org">Qualified Security Assessor</a>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-requirements-for-service-providers-expert-advice-froma-qsa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Compliance &#124; Getting Started on PCI DSS Compliance for Merchants</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-getting-started-on-pci-dss-compliance-for-merchants/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-getting-started-on-pci-dss-compliance-for-merchants/#comments</comments>
		<pubDate>Thu, 30 Apr 2009 13:46:49 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[pci assessment]]></category>
		<category><![CDATA[pci dss compliance]]></category>
		<category><![CDATA[pci qsa]]></category>
		<category><![CDATA[service levels]]></category>
		<category><![CDATA[transaction volume]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-getting-started-on-pci-dss-compliance-for-merchants/</guid>
		<description><![CDATA[PCI DSS compliance is having a profound impact on businesses today. In short, the Payment Card Industry Data Security Standards (PCI DSS) is mandatory for any business involved in the processing, storage, or transmission of transaction data or cardholder data. As a result, this compliance requirement &#8220;should&#8221; be affecting millions of U.S. businesses. I say [...]]]></description>
				<content:encoded><![CDATA[<p><strong><a href="http://www.pciassessment.org">PCI DSS compliance</a></strong> is having a profound impact on businesses today. In short, the Payment Card Industry Data Security Standards (PCI DSS) is mandatory for any business involved in the processing, storage, or transmission of transaction data or cardholder data. As a result, this compliance requirement &#8220;should&#8221; be affecting millions of U.S. businesses. I say &#8220;should&#8221; because the lack of enforcement is resulting in a large number of organizations not complying with the PCI DSS standards. That could change as merchant processors and payment gateways are forced to  have all their merchants comply with the standards. As a PCI-QSA assessor who conducts PCI DSS assessments, i&#8217;m starting to field many calls from merchants who have been contacted by their third party payment processor telling them they need to be PCI compliant. </p>
<p>I honestly think most merchants want to and will comply with PCI, but the &#8220;who, what, where, and why&#8221; of PCI DSS compliance can be quite vague at times. So, to be fair to merchants, some eduction is needed on this topic. </p>
<p>Thus, first and foremost, you will need to identify your transaction volume, that is, the number of transactions you undertake on a yearly basis for payment cards. This will help you identify what &#8220;level&#8221; of compliance you fall into.  <strong><a href="http://www.pciassessment.org/merchants.php">This handy reference guide</a></strong> for transaction volume will help you with this.</p>
<p>Once you&#8217;ve identified what &#8220;level&#8221; of compliance you fall into, you can then <strong><a href="http://www.pciassessment.org">contact a PCI DSS specialist</a></strong> for helping assist in your compliance matters.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-getting-started-on-pci-dss-compliance-for-merchants/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
