Articles in the application security Category
Alerts, PCI News, application security, featured »
Hey look - another lawsuit….
Well - right now it’s just the threat of a suit… The information is a bit thin and I’m not sure (based on the press release) whether or not this is a complaint about the software, the implementation of the software, the hardware system, or all of the above.
What it does look like is a bit of a fishing exercise by the law firms - let’s send out the press release, make it general enough that we include just about anyone that even thought about touching the …
Alerts, Interesting, PCI News, PED / Payment Terminals, Retailers, application security, headline »
The link to the article on StorefrontBacktalk is below (thanks Evan) - this is really interesting. It appears that VISA is providing an extension to ExxonMobil on the July 1st, 2010 PA-DSS deadline…
This implies two things (as far as I can see):
That the deadline everyone was wondering about is legit - why would ExxonMobil feel the need to negotiate an extension with VISA unless the deadline was going to mean something and VISA was going to enforce it at some meaningful level?
If you are big enough, VISA is going to …
NRF, PCI News, PCI Philosophy / Approach, Retailers, Vendors, application security, featured »
As promised, I’m posting this as a follow-up to this year’s NRF show in NYC. It is going to be a short post as there really isn’t a lot to talk about from the show, particularly in terms of security or compliance.
The big news this year is that the show didn’t suck. Someone told me that it was the best attended show (by retailers) in the last 5 years. I’m not sure if that’s an official ruling from the NRF, but I can certainly attest to the fact that traffic …
Interesting, PCI News, Retailers, Vendors, application security, featured »
This one has some significant implications for software security and the role & responsibility of technology vendors. Here’s the link:
Radiant Systems and Computer World responsible for breach affecting restaurants – lawsuit
What’s most interesting to me in all of this is that fact that the restaurants seem to ‘get it’ - they understand the holistic impact of PCI on process, procedures, technology, etc. and, after being smacked around by the card brands for being the merchant where the breach occured, they have taken that holistic understanding and are working to hold …
Vendors, application security, featured »
Image by Wonderlane via Flickr
With the Microsoft SharePoint conference having recently taken place, I have been thinking a lot about SharePoint lately (haven’t you?) and about what a powerful and dangerous tool it can be.
Before I get into what I’ve been thinking about, here are a few things to consider:
A Microsoft employee recently told me that SharePoint has been the most rapidly adopted product in Microsoft’s history. While I haven’t been able to confirm this, it doesn’t really matter - what matters is, it’s everywhere and it …
application security, headline »
OK - maybe not all of them, but the most common that I’m hearing anyway…
After asking you all to give me some questions for PA-DSS, I finally am getting around to posting up some answers. Some of them are also taken directly from numerous conversations that I have had with software vendors over the last several months and, truthfully, I’m glad that I waited to put that post together…It’s not entirely retail focused, as PA-DSS crosses most industries, but I hope it proves useful in answering some common questions…
It’s located …
PCI Philosophy / Approach, application security, featured »
The links are a little messed up, so you might want to wait until about 10AM tomorrow to take a look, but, my newest NetSPI post is up.
Also, if you are interested in understanding a bit more about how PCI impacts industries outside of retail and hospitality or in looking through some more technical posts on penetration testing and the like, I’d tune into the NetSPI blog. The team has really embraced blogging and collectively we are putting out a very good mix of posts (at least I think so.)
Although …
Interesting, application security, featured »
OK - so I’m not very ‘with-it’ apparently and didn’t really know what Squidoo was, but someone explained it to me and then convinced me to put up a PA-DSS compliance ‘lens’ on Squidoo. If you aren’t familiar with the site, it’s a collection of mini websites each of which provides some background, insight, education, whatever on specific topics as defined by the builder. In this case it’s some overview information on basic PA-DSS compliance and a centralized location for PA-DSS feeds and search results that keeps itself up-to-date without …
PCI News, PED / Payment Terminals, application security, featured »
This morning I had an interesting thought - I want to offer up something to anyone that is reading this blog and may have some questions regarding the Payment Application Data Security Standard (PA-DSS.)
This is an invitation to a ‘passive PA-DSS Q&A session’. The reason I am calling this ‘passive’ is that this is not going to be a live session - if you have questions regarding the PA-DSS, what certain requirements mean, or how your particular situation affects it’s applicability to you, post it in the comments and …
PCI Philosophy / Approach, application security »
Much of the time, particularly in the retail / hospitality space, compliance is driving security efforts. I tend to have a problem with security via compliance as it tends to result in an approach that is far too narrow for the overall security of the organization. I understand the importance of PCI compliance and the need to become and remain compliant (obviously), but I also think that the whole cliche, ‘missing the forest for the trees’, applies really well to a security team that is chasing compliance rather than building …

