Home » Archive

Articles in the Vendors Category

NRF, PCI News, PCI Philosophy / Approach, Retailers, Vendors, application security, headline »

[18 Jan 2010 | | ]
NRF 2010 Follow-Up (it didn’t suck)

As promised, I’m posting this as a follow-up to this year’s NRF show in NYC.  It is going to be a short post as there really isn’t a lot to talk about from the show, particularly in terms of security or compliance.
The big news this year is that the show didn’t suck.  Someone told me that it was the best attended show (by retailers) in the last 5 years.  I’m not sure if that’s an official ruling from the NRF, but I can certainly attest to the fact that traffic …

PCI News, Vendors »

[1 Dec 2009 | | ]

IBM continues to quietly buy up both analytics companies and (more importantly for us) security companies…  After picking up Ounce Labs earlier, IBM has now acquired Guardium.
Guardium - IBM Acquires Guardium.

Interesting, PCI News, Retailers, Vendors, application security, featured »

[25 Nov 2009 | | ]
Another Interesting Lawsuit

This one has some significant implications for software security and the role & responsibility of technology vendors.  Here’s the link:
Radiant Systems and Computer World responsible for breach affecting restaurants – lawsuit
What’s most interesting to me in all of this is that fact that the restaurants seem to ‘get it’ - they understand the holistic impact of PCI on process, procedures, technology, etc. and, after being smacked around by the card brands for being the merchant where the breach occured, they have taken that holistic understanding and are working to hold …

Vendors, application security, featured »

[10 Nov 2009 | | ]
SharePoint and Security

Image by Wonderlane via Flickr

With the Microsoft SharePoint conference having recently taken place, I have been thinking a lot about SharePoint lately (haven’t you?) and about what a powerful and dangerous tool it can be.

Before I get into what I’ve been thinking about, here are a few things to consider:

A Microsoft employee recently told me that SharePoint has been the most rapidly adopted product in Microsoft’s history. While I haven’t been able to confirm this, it doesn’t really matter - what matters is, it’s everywhere and it …

Interesting, Vendors »

[4 Nov 2009 | | ]

So everyone knows at this point that AT&T has acquired VeriSign’s global security consulting business.  I’m not really sure why AT&T actually bought them although I’m sure that they have some sort of Grand Plan, much the same way that Verizon had when they acquired Cybertrust and all of the other companies that they bought over the years… 
What seems to really happen is that these large firms that don’t have a focus on security see an opportunity and spend a bunch of money to acquire well-known brands and, far …

Interesting, PCI News, Vendors »

[2 Oct 2009 | | ]

OK - I’ve got a couple of posts that I’ll be putting up shortly - one on some feedback from the PCI Community Meeting and one on that list of questions on PA-DSS.  I’ll try to get them up this weekend (work has been crazy and I just haven’t found/committed the time to get these written), but here’s a link to a post this morning from Deke George on the NetSPI blog regarding acquisitions in the security space.
NetSPI Blog - Mergers & Acquisitions

PCI Philosophy / Approach, Vendors, featured »

[15 Jun 2009 | | ]
PA-DSS and ‘Enforcement’

I have spoken with a number of companies over the last several weeks that are preparing themselves to go through the PA-DSS assessment process (software providers, not security firms) and they all are trying to understand the level of priority that they need to set.  Particularly smaller firms are trying to come to grips with the fact that they are now required to go through an expensive, potentially disruptive assessment process that they didn’t have to address previously.
It only makes sense that they all end up asking the question, ‘are …

Interesting, PCI News, PCI Philosophy / Approach, Vendors »

[10 Jun 2009 | | ]

I have a longer post that I’ve held off on so far regarding the Savvis lawsuit and it’s potential impact on the retail community, but, as I hash through that effort (and try to make it a little less ‘rangey’), I thought I’d put this out…
If you are unfamiliar with the Savvis suit, the details can be found in this article from Kim Zetter (link).  It’s an interesting read and does a really good job of summarizing the situation and the potential impacts to the PCI community.  For those of …

PCI Philosophy / Approach, Vendors »

[5 Jun 2009 | | ]

For those software vendors out there that are digging into PA-DSS and what it means for their organization, please read on.  This is not an in-depth discussion of PA-DSS, just a couple of things that have been popping up repeatedly for me in conversations with your peers - things that sometimes need clarification or that should be mentioned.  Stuff You Probably Should Know About PA-DSS

It’s not PABP - this may sound obvious, but I’m going to repeat it - PA-DSS is not PABP.  Accept this fact - if your assessment …