 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Regulatory Compliance, Governance and Security &#187; pci dss policies and procedures</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/compliance-governance/tag/pci-dss-policies-and-procedures/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/compliance-governance</link>
	<description></description>
	<lastBuildDate>Thu, 10 Mar 2011 15:04:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>12 PCI DSS Requirements &#124; Lessons Learned from a PCI QSA</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/12-pci-dss-requirements-lessons-learned-from-a-pci-qsa/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/12-pci-dss-requirements-lessons-learned-from-a-pci-qsa/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 23:39:00 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[12 PCI DSS requirements]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[payment card industry dat]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[pci dss policies and procedures]]></category>
		<category><![CDATA[pci readiness assessment]]></category>
		<category><![CDATA[qualified security assessor (QSA)]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/12-pci-dss-requirements-lessons-learned-from-a-pci-qsa/</guid>
		<description><![CDATA[The 12 PCI DSS Requirements are lengthy and technical indeed. However, organizations need to truly understand the scope of the PCI assessment for gaining greater insight into the efficiencies that can be had for undertaking a Payment Card Industry Data Security Standards (PCI DSS) Assessment. So, what are my lessons learned as a Qualified Security [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.pciassessment.org/12-pci-dss-requirements.php">The 12 PCI DSS Requirements</a> are lengthy and technical indeed. However, organizations need to truly understand the scope of the PCI assessment for gaining greater insight into the efficiencies that can be had for undertaking a Payment Card Industry Data Security Standards (PCI DSS) Assessment.</p>
<p>So, what are my lessons learned as a Qualified Security Assessor (QSA) who conducts PCI assessments?</p>
<p>First and foremost, the assessment is NOT always about technology. Sure there is a host of requirements  surrounding the &#8220;system components&#8221; of the &#8220;cardholder environment&#8221;, but look closer and you will find that developing documented policies and procedures is one of the most time-consuming and arduous processes of the entire assessment? Your kidding, you might say? Not at all, it&#8217;s amazing how much time and effort is needed for developing these documents for ensuring PCI compliance. </p>
<p>Add to the fact that you need to properly &#8220;scope&#8221; the assessment for a number of parameters and I would highly advice a PCI Readiness Assessment for any entity going through a Level 1 PCI engagement. </p>
<p>Properly scope the assessment for what is and is not included in the &#8220;cardholder environment&#8221;, conduct a <a href="http://www.pciassessment.org/pci-dss-readiness-assessment.php">PCI Readiness Assessment</a> and be mindful of the documented policies and procedures that must be in place for compliance. </p>
<p>To learn more about PCI, visit <a href="http://www.pciassessment.org">pciassessment.org</a></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/12-pci-dss-requirements-lessons-learned-from-a-pci-qsa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Payment Card Industry (PCI) Compliance &#124; Much More than just I.T.</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-compliance-much-more-than-just-it/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-compliance-much-more-than-just-it/#comments</comments>
		<pubDate>Sat, 14 Feb 2009 13:52:25 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[pci dss 1.2]]></category>
		<category><![CDATA[pci dss policies and procedures]]></category>
		<category><![CDATA[pci readiness assessment]]></category>
		<category><![CDATA[qualified security assessor (QSA)]]></category>
		<category><![CDATA[requirement 12: Maintain a policy that addresses information security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/?p=113</guid>
		<description><![CDATA[That&#8217;s right. Payment Card Industry (PCI) compliance is much more than just I.T. and all the surrounding hardware and software components that make up the &#8220;system components&#8221; within the cardholder environment. I&#8217;ve just recently finished up a PCI Readiness Assessment for a client on the West Coast and guess what happens to be there most [...]]]></description>
				<content:encoded><![CDATA[<p>That&#8217;s right. Payment Card Industry (PCI) compliance is much more than just I.T. and all the surrounding hardware and software components that make up the &#8220;system components&#8221; within the cardholder environment. I&#8217;ve just recently finished up a PCI Readiness Assessment for a client on the West Coast and guess what happens to be there most significant and time consuming remediation activity? The writing of documented policies and procedures for numerous requirements as set forth and promulgated by the PCI DSS v.1.2 standards. That&#8217;s right, they can be painstaking, arduous, and time consuming. Even worse, most I.T. security professionals really do not like to consume themselves with this daunting task.</p>
<p>So remember, when you are are all caught up in the PCI game and you are so focused on routers, switches, load balancers, and other network and system devices, make sure you focus on the much needed policies and procedures that are sprinkled throughout the PCI DSS requirements. My advice, hire a seasoned <a href="http://www.pciassessment.org">Qualified Security Assessor (QSA) </a>to write them for you, you&#8217;ll be glad you did.  </p>
<p>And if you don&#8217;t believe me, take a look at Requirement 12: Maintain a Policy that Addresses Information Security. </p>
<p>To learn more about Payment Card Industry (PCI) compliance, visit <strong><a href="http://www.pciassessment.org">pciassessment.org </a></strong></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-pci-compliance-much-more-than-just-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
