 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Regulatory Compliance, Governance and Security &#187; pci dss v1.2</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/compliance-governance/tag/pci-dss-v12/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/compliance-governance</link>
	<description></description>
	<lastBuildDate>Thu, 10 Mar 2011 15:04:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>PCI Requirement 1: Install and Maintain a Firewall Configuration to Protect Cardholder Data &#124; What You Need to Know</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-requirement-1-install-and-maintain-a-firewall-configuration-to-protect-cardholder-data-what-you-need-to-know/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-requirement-1-install-and-maintain-a-firewall-configuration-to-protect-cardholder-data-what-you-need-to-know/#comments</comments>
		<pubDate>Sat, 21 Feb 2009 12:57:01 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[cisco]]></category>
		<category><![CDATA[firewalls]]></category>
		<category><![CDATA[juniper]]></category>
		<category><![CDATA[load balancers]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[pci dss v1.2]]></category>
		<category><![CDATA[PCI Requirement #1: Install and maintain a firewall configuration to protect cardholder data]]></category>
		<category><![CDATA[qualified security assessor (QSA)]]></category>
		<category><![CDATA[routers]]></category>
		<category><![CDATA[rulesets]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/?p=119</guid>
		<description><![CDATA[For Payment Card Industry (PCI) compliance, there are twelve (12) core, functional requirements mandated under PCI DSS v1.2. What&#8217;s important to note is that many times you truly need to &#8220;read between the lines&#8221; to interpret, comprehend, and understand what the PCI DSS standards are actually stating, and asking you to validate. Take PCI Requirement [...]]]></description>
				<content:encoded><![CDATA[<p>For Payment Card Industry (PCI) compliance, there are twelve (12) core, functional requirements mandated under PCI DSS v1.2. What&#8217;s important to note is that many times you truly need to &#8220;read between the lines&#8221; to interpret, comprehend, and understand what the PCI DSS standards are actually stating, and asking you to validate.</p>
<p>Take PCI Requirement #1: Install and maintain a firewall configuration to protect cardholder data. If you  read all the requirements and the tests that accompany each requirement, it seems to sound quite straight forward. Well it is and it isn&#8217;t. The &#8220;isn&#8217;t&#8221; part lies in the ability to interpret some testing that really has not been spelled out for you. For example, throughout requirement #1 it tells you to &#8220;examine&#8221; and &#8220;verify&#8221; a whole host of configuration settings for network devices, particularly firewalls and routers. So how should you interpret &#8220;examine&#8221; and &#8220;verify&#8221;. <a href="http://www.pciassessment.org/contact.php">As a Qualified Security Assessor </a>(QSA) for PCI, I can tell you that just simply asking for the rulesets and configuration documents is simply not enough. You have to actually examine, interpret, read, and dissect the rules and configurations settings, match them against the test criteria, along with using the network topology documents (that should be developed) as further evidence. In short, simply printing out rulesets, throwing them in a folder as audit evidence and moving on to the next phase of the PCI is not going to cut it. If you want to brush on truly understanding rulesets and the configuration of network devices (routers, firewalls, load balancers, etc.), CISCO and JUNIPER and other network device providers have a host of free information on the internet. </p>
<p>To learn more about PCI DSS compliance and Requirement 1 and other areas of the PCI DSS v.1.2 standard, then visit <a href="http://www.pciassessment.org">PCIassessment.org</a>. </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-requirement-1-install-and-maintain-a-firewall-configuration-to-protect-cardholder-data-what-you-need-to-know/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Security Standards &#124; Learn How to Become PCI Compliant</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-security-standards-learn-how-to-become-pci-compliant/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-security-standards-learn-how-to-become-pci-compliant/#comments</comments>
		<pubDate>Sun, 08 Feb 2009 15:11:50 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[carhdolder data]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[pci dss v1.2]]></category>
		<category><![CDATA[pci security standards]]></category>
		<category><![CDATA[PCI self assessment questionnaires (SAQ)]]></category>
		<category><![CDATA[qualified security assessor (QSA)]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/?p=106</guid>
		<description><![CDATA[Payment Card Industry (PCI) compliance is becoming a force to reckon with, to say the least. It seems as if every possible and conceivable industry in the country is being affected by PCI compliance, either directly or indirectly. What&#8217;s important to note about PCI compliance is that it primarily affects merchants, service providers, third party [...]]]></description>
				<content:encoded><![CDATA[<p>Payment Card Industry (PCI) compliance is becoming a force to reckon with, to say the least. It seems as if every possible and conceivable industry in the country is being affected by PCI compliance, either directly or indirectly. What&#8217;s important to note about PCI compliance is that it primarily affects merchants, service providers, third party processors, and other third party outsourcing entities that are involved in the storage, transmission, or processing of cardholder and payment data.</p>
<p>Before you jump off a bridge because of the costs and time involved with PCI compliance, take a deep breath and look at it in a practical manner. The PCI security standards, official known as the Payment Card Industry Data Security Standards (PCI DSS v1.2) illustrates exactly what needs to be accomplished and validated for PCI compliance, if you have to have an onsite PCI assessment. If you don&#8217;t and you can essentially &#8220;self assess&#8221;, then you can simply obtain the &#8220;self assessment&#8221; questionnaires. </p>
<p>So how do you know if you need an onsite PCI assessment done by a QSA or a &#8220;self assessment questionnaire&#8221;? Well, <strong><a href="http://www.pciassessment.org/merchants.php#bookmark-1">find your transaction volume for processing credit cards</a></strong>, and that will give you the answer. </p>
<p>Once you&#8217;ve don that, you will be on your way to clearly understanding what needs to be done for purposes of PCI compliance.  </p>
<p>To learn more about PCI compliance, the onsite PCI assessments and the different PCI &#8220;self assessment questionnaires&#8221; <strong><a href="http://www.pciassessment.org/contact.php">contact me directly</a></strong> and i will assist you in any way i can.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-security-standards-learn-how-to-become-pci-compliant/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
