Home » Archive

Articles tagged with: PA-DSS

PCI News, PED / Payment Terminals, application security, featured »

[9 Sep 2009 | | ]
PA-DSS Question & Answer

This morning I had an interesting thought - I want to offer up something to anyone that is reading this blog and may have some questions regarding the Payment Application Data Security Standard (PA-DSS.) 
This is an invitation to a ‘passive PA-DSS Q&A session’.  The reason I am calling this ‘passive’ is that this is not going to be a live session - if you have questions regarding the PA-DSS, what certain requirements mean, or how your particular situation affects it’s applicability to you, post it in the comments and …

Conferences / Webinars, PCI Philosophy / Approach, featured »

[9 Sep 2009 | | ]
Video of NetSPI’s Presentation on PCI and PA-DSS and Development

Here’s a video of Seth Peter, NetSPI’s CTO, presenting to the Minnesota OWASP chapter’s annual half-day conference…

Seth Peter: The Developers Guide to PCI DSS and PA-DSS Requirements from David Bryan on Vimeo.

PCI Philosophy / Approach »

[6 Aug 2009 | | ]

So my first post for the official NetSPI PCI blog is up there and, true to form, it’s not of a technical nature - merely an observation on how far the impact of PCI reaches.  One of the things that I talk about is how the retail and hospitality communities have gone through something very close to the grieving process in dealing with PCI - now organizations outside of retail and hospitality are starting this process - and it’s just as painful for them as it was for the retail …

PCI Philosophy / Approach, Vendors, featured »

[15 Jun 2009 | | ]
PA-DSS and ‘Enforcement’

I have spoken with a number of companies over the last several weeks that are preparing themselves to go through the PA-DSS assessment process (software providers, not security firms) and they all are trying to understand the level of priority that they need to set.  Particularly smaller firms are trying to come to grips with the fact that they are now required to go through an expensive, potentially disruptive assessment process that they didn’t have to address previously.
It only makes sense that they all end up asking the question, ‘are …

PCI Philosophy / Approach, Vendors »

[5 Jun 2009 | | ]

For those software vendors out there that are digging into PA-DSS and what it means for their organization, please read on.  This is not an in-depth discussion of PA-DSS, just a couple of things that have been popping up repeatedly for me in conversations with your peers - things that sometimes need clarification or that should be mentioned.  Stuff You Probably Should Know About PA-DSS

It’s not PABP - this may sound obvious, but I’m going to repeat it - PA-DSS is not PABP.  Accept this fact - if your assessment …

Alerts, Conferences / Webinars, PED / Payment Terminals, Vendors »

[3 Mar 2009 | | ]

The webinar that NetSPI put on with VeriFone is up on the VeriFone webex repository.  It requires registration, but they have been very careful with the use of the registration information that they have gathered, so I’m not concerned about it.
The webinar was built to answer some questions for merchants in particular, so this isn’t an overly technical presentation, but it should help shed some light on how PA-DSS differs from PABP and why retailers and online merchants should care about the standard.  It also showcases some of VeriFone’s solutions …

Interesting, PCI Philosophy / Approach »

[16 Dec 2008 | | ]

I have to admit that I don’t always see eye-to-eye with the PCI Knowledge Base on their approach to PCI in retail (it’s a philosophical thing - they are very good about accuracy, etc.), but this article was very interesting and, I think, very relevant.
I’m actually involved with a webinar that is going to happen in January that discusses PA-DSS and it’s impact on retail technology strategy and buying decisions over the next 18 months.  In other words, as a retailer, why should I care about PA-DSS….  As it get’s …

Alerts, PCI Philosophy / Approach, PED / Payment Terminals, Vendors »

[18 Nov 2008 | | ]

It’s good to see a ‘vendor’ understanding that providing a secure solution is extremely valuable to the retail community…
VeriFone Takes Lead in Securing Card Payments with PA-DSS
Will Only Provide PA-DSS Audited Payment Applications in Initiative that Supports New Rules Governing PCI Compliance for All Levels of Merchants
VeriFone Takes Lead in Securing Card Payments with PA-DSS - MarketWatch.

Alerts, PCI Philosophy / Approach, PED / Payment Terminals »

[31 Oct 2008 | | ]

This is an article on Storefrontbacktalk that think everyone should see…  PA-DSS is a very misunderstood situation at the moment and has a LARGE number of software vendors suddenly scrambling for certification.
Their scrambling successfully (or unsuccessfully) is going to have real impact on the PCI standing and security posture of the entire retail community.  There are currently only 16 consulting organizations in the US that are performing this work and, as my employer (NetSPI) was one of the first 8 on the list, we are heavily focused on this aspect …

LinkedIn, PCI Philosophy / Approach »

[30 Oct 2008 | | ]

This is an early version of a position paper that I am working on, but I thought it might be interesting to throw out here and see what initial reactions are to the general ideas presented. To summarize very rapidly - in my opinion, investing in security is an extremely efficient way to utilize corporate funds even in a down economy. Here’s the initial draft document. Again, this is a ‘position paper’ not a full white paper, so it’s pretty high level…
Also, there are Return-On-Security-Investment (ROSI) strategies …