Articles tagged with: PCI-DSS
Alerts, Interesting, PCI News, Retailers, Vendors, featured »
After posting about the press release regarding the potential lawsuit (here) I got an email from the PR firm that had sent the release out. He, in turn, connected me to Charles Hoff - the attorney for the retailer that is considering the suit, Brew HaHa!. We had a very interesting conversation and, not being a lawyer, I’m not going to make any comments about the merits of any lawsuit that may or may not come from this episode, but, as I said, the conversation was interesting and this is …
Alerts, Interesting, PCI News, PED / Payment Terminals, Retailers, application security, headline »
The link to the article on StorefrontBacktalk is below (thanks Evan) - this is really interesting. It appears that VISA is providing an extension to ExxonMobil on the July 1st, 2010 PA-DSS deadline…
This implies two things (as far as I can see):
That the deadline everyone was wondering about is legit - why would ExxonMobil feel the need to negotiate an extension with VISA unless the deadline was going to mean something and VISA was going to enforce it at some meaningful level?
If you are big enough, VISA is going to …
Alerts, PCI News, PCI Philosophy / Approach »
Here’s the link to a webinar that NetSPI and CoreTrace are doing on April 8th. So far we have a really good set of attendees and David Gianna, one of NetSPI’s senior consultants and QSAs, is going to be presenting on:
Quick PCI overview, including the role of the PCI Security Standards Council and QSAs; the interrelationship of PCI-DSS, PA-DSS and PED; Merchant-Acquirer-QSA relationship; and the major PCI-DSS requirements
Discussion of PCI compliance versus Information Security and the relationship between each
Baseline view of the operational realities that make …
NRF, PCI News, PCI Philosophy / Approach, Retailers, Vendors, application security, featured »
As promised, I’m posting this as a follow-up to this year’s NRF show in NYC. It is going to be a short post as there really isn’t a lot to talk about from the show, particularly in terms of security or compliance.
The big news this year is that the show didn’t suck. Someone told me that it was the best attended show (by retailers) in the last 5 years. I’m not sure if that’s an official ruling from the NRF, but I can certainly attest to the fact that traffic …
PCI News, featured »
I haven’t posted anything forever!!!
Bad Alex!
Well, I’m heading out to another NRF this weekend and I promise that I’ll post something either from the show or shortly thereafter. It might have something to do with how poorly security is represented at the show (other than at least 25 ‘Instant PCI’ offerings and Trustwave throwing money around…), but we’ll see.
If anyone out there is actually going to be at NRF and is interested in connecting, please let me know - alex.crittenden@yahoo.com - and we’ll figure something out.
Thanks and Happy New Year!
Related …
Alerts, Conferences / Webinars, PCI News, PCI Philosophy / Approach, PED / Payment Terminals »
The Council is hosting a couple of ‘open mic’ webinars for industry stakeholders on the 8th and 9th of December. They are trying to update the industry following the Community Meeting and get some feedback or questions….
These are typically reserved for Participating Organizations, but for this round they are opening it up to the broader industry… Here’s the link:
PCI Council Webinar Release
Interesting, PCI News, Retailers, Vendors, application security, featured »
This one has some significant implications for software security and the role & responsibility of technology vendors. Here’s the link:
Radiant Systems and Computer World responsible for breach affecting restaurants – lawsuit
What’s most interesting to me in all of this is that fact that the restaurants seem to ‘get it’ - they understand the holistic impact of PCI on process, procedures, technology, etc. and, after being smacked around by the card brands for being the merchant where the breach occured, they have taken that holistic understanding and are working to hold …
application security, headline »
OK - maybe not all of them, but the most common that I’m hearing anyway…
After asking you all to give me some questions for PA-DSS, I finally am getting around to posting up some answers. Some of them are also taken directly from numerous conversations that I have had with software vendors over the last several months and, truthfully, I’m glad that I waited to put that post together…It’s not entirely retail focused, as PA-DSS crosses most industries, but I hope it proves useful in answering some common questions…
It’s located …
Conferences / Webinars, PCI Philosophy / Approach, featured »
OK - this is the feedback on the Community Meeting that I had mentioned although it really turned into a philosophical post about what your PCI partners should really be doing for you (hint: being a partner).
This one’s over at the NetSPI blog as well (I swear that I’m still going to be posting over here on a more regular basis, but, since NetSPI’s doing a good job with the blog, I’m going to blend my posts between the two blogs…). Any feedback is going to have to come here, …

