Articles in the Vendors Category
NRF, PCI News, PCI Philosophy / Approach, Retailers, Vendors, application security, headline »
As promised, I’m posting this as a follow-up to this year’s NRF show in NYC. It is going to be a short post as there really isn’t a lot to talk about from the show, particularly in terms of security or compliance.
The big news this year is that the show didn’t suck. Someone told me that it was the best attended show (by retailers) in the last 5 years. I’m not sure if that’s an official ruling from the NRF, but I can certainly attest to the fact that traffic …
PCI News, Vendors »
IBM continues to quietly buy up both analytics companies and (more importantly for us) security companies… After picking up Ounce Labs earlier, IBM has now acquired Guardium.
Guardium - IBM Acquires Guardium.
Interesting, PCI News, Retailers, Vendors, application security, featured »
This one has some significant implications for software security and the role & responsibility of technology vendors. Here’s the link:
Radiant Systems and Computer World responsible for breach affecting restaurants – lawsuit
What’s most interesting to me in all of this is that fact that the restaurants seem to ‘get it’ - they understand the holistic impact of PCI on process, procedures, technology, etc. and, after being smacked around by the card brands for being the merchant where the breach occured, they have taken that holistic understanding and are working to hold …
Vendors, application security, featured »
Image by Wonderlane via Flickr
With the Microsoft SharePoint conference having recently taken place, I have been thinking a lot about SharePoint lately (haven’t you?) and about what a powerful and dangerous tool it can be.
Before I get into what I’ve been thinking about, here are a few things to consider:
A Microsoft employee recently told me that SharePoint has been the most rapidly adopted product in Microsoft’s history. While I haven’t been able to confirm this, it doesn’t really matter - what matters is, it’s everywhere and it …
Interesting, Vendors »
So everyone knows at this point that AT&T has acquired VeriSign’s global security consulting business. I’m not really sure why AT&T actually bought them although I’m sure that they have some sort of Grand Plan, much the same way that Verizon had when they acquired Cybertrust and all of the other companies that they bought over the years…
What seems to really happen is that these large firms that don’t have a focus on security see an opportunity and spend a bunch of money to acquire well-known brands and, far …
Interesting, PCI News, Vendors »
OK - I’ve got a couple of posts that I’ll be putting up shortly - one on some feedback from the PCI Community Meeting and one on that list of questions on PA-DSS. I’ll try to get them up this weekend (work has been crazy and I just haven’t found/committed the time to get these written), but here’s a link to a post this morning from Deke George on the NetSPI blog regarding acquisitions in the security space.
NetSPI Blog - Mergers & Acquisitions
PCI Philosophy / Approach, Vendors, featured »
I have spoken with a number of companies over the last several weeks that are preparing themselves to go through the PA-DSS assessment process (software providers, not security firms) and they all are trying to understand the level of priority that they need to set. Particularly smaller firms are trying to come to grips with the fact that they are now required to go through an expensive, potentially disruptive assessment process that they didn’t have to address previously.
It only makes sense that they all end up asking the question, ‘are …
Interesting, PCI News, PCI Philosophy / Approach, Vendors »
I have a longer post that I’ve held off on so far regarding the Savvis lawsuit and it’s potential impact on the retail community, but, as I hash through that effort (and try to make it a little less ‘rangey’), I thought I’d put this out…
If you are unfamiliar with the Savvis suit, the details can be found in this article from Kim Zetter (link). It’s an interesting read and does a really good job of summarizing the situation and the potential impacts to the PCI community. For those of …
PCI Philosophy / Approach, Vendors »
For those software vendors out there that are digging into PA-DSS and what it means for their organization, please read on. This is not an in-depth discussion of PA-DSS, just a couple of things that have been popping up repeatedly for me in conversations with your peers - things that sometimes need clarification or that should be mentioned. Stuff You Probably Should Know About PA-DSS
It’s not PABP - this may sound obvious, but I’m going to repeat it - PA-DSS is not PABP. Accept this fact - if your assessment …


