Regulatory Compliance, Governance and Security:

policies and procedures

1

May 31, 2009  3:33 PM

Policies and Procedures | SAS 70 | PCI DSS | An Auditor’s Viewpoint



Posted by: Charles Denyer
Add new tag, change management, charles denyer, Maintain an Information Security Policy, PCI DSS, policies and procedures, requirement 12, SAS 70 Type I, sas 70 type ii

Policies and Procedures-it's such a common theme and phrase in today's regulatory compliance and governance arena, so much so, i think it should have it's own Wikipedia page. It can be an arduous undertaking in developing these documents. Furthermore, policies and procedures are becoming...

May 26, 2009  6:22 PM

PCI DSS Level 1 Compliance | Helpful Tips from a PCI QSA



Posted by: Charles Denyer
charles denyer, payment card industry data security standards, PCI DSS, PCI DSS Level 1 compliance, pci qsa, pciassessment.org, policies and procedures, requirement 12

Payment Card Industry Data Security Standards (PCI DSS) Level 1 compliance can be a very arduous, time-consuming and costly undertaking for any organization. However, there are a number of proactive steps that should be put in place for helping ensure an...


November 23, 2008  7:24 PM

Payment Card Industry (PCI DSS) Compliance | Requirement 1.1.2



Posted by: Charles Denyer
payment card industry, payment card industry data security standards, PCI, pci assessment, pci compliance, PCI DSS, pci dss qsa, pci dss requirement 1.1.2, policies and procedures, qsa, regulatory compliance, SAS 70, sas 70 audit report

Payment Card Industry (PCI) Data Security Standards (DSS) compliance for PCI DSS requirement 1.1.2 calls for "Current network diagram with all connections to cardholder data, including any wireless networks" Thus, testing for validating...


November 23, 2008  7:14 PM

Payment Card Industry (PCI DSS) Compliance | Requirement 1.1.1



Posted by: Charles Denyer
payment card industry, payment card industry data security standards, PCI, pci assessment, pci compliance, PCI DSS, pci dss qsa, pci dss requirement 1.1.1, policies and procedures, qsa

PCI DSS Requirement 1.1.1 calls for "A formal process for approving and testing all network connections and changes to the firewall and router configurations". Thus, the test to validate this, in accordance with PCI DSS 1.2 standards is to...


November 12, 2008  3:55 PM

Payment Card Industry Data Security Standards (PCI DSS) | Tips and Strategies



Posted by: Charles Denyer
merchants, MN plastic card security act, payment card industry, payment card industry data security standards, PCI, pci assessment, pci compliance, PCI DSS, policies and procedures, service providers

If you are a merchant or service organization and need to be payment card industry (PCI) compliant with the PCI DSS provisions, then there are a number of important points you need to know. First and foremost, you need to identify what level you are in accordance with PCI DSS requirements. You can...


October 27, 2008  8:51 PM

PCI DSS Compliance in Today’s Heightened Security World



Posted by: Charles Denyer
payment card industry, pci assessment, pci dss qsa, policies and procedures, qsa

PCI DSS stands for Payment Card Industry Data Security Standards. If you are a merchant or service provider who is directly involved in the processing, storage, or transmission of transaction data or cardholder data, then you should be looked upon as PCI...


October 27, 2008  8:43 PM

PCI DSS | Payment Card Industry Compliance Tips to Use



Posted by: Charles Denyer
payment card industry, pci assessment, pci dss qsa, policies and procedures, qsa

PCI DSS is fast becoming a requirement for many merchants and service providers in todays economy that are directly involved in the processing, storage, or transmission of transaction data or cardholder data. In short, they should be...


October 19, 2008  11:54 PM

PCI DSS | Helpful Tips on Becoming PCI DSS Compliant



Posted by: Charles Denyer
payment card industry, pci assessment, pci dss qsa, policies and procedures

PCI DSS-It's a well-known phrase in today's growing regulatory compliance landscape. Because PCI DSS and it's standards, requirements, and other supporting factors are relatively new, there still seems to be a high degree of uncertainty of who needs to be PCI DSS compliant and why. the who, what,...


October 19, 2008  11:45 PM

PCI DSS Compliance | It Starts with Policies & Procedures



Posted by: Charles Denyer
pci compliance, PCI DSS, policies and procedures

PCI DSS compliance can be considered a costly, time consuming assessment for any merchant or service provider that has to obtain PCI DSS compliance. What many organizations fail to recognize is that within the PCI DSS standards are a slew of requirements for documents policies and procedures on a...


1