Home » Archive

Articles tagged with: PCI-DSS

PCI Philosophy / Approach »

[21 Sep 2009 | | ]

Just a reference to another NetSPI blog post that just went up…  link

Alerts, PCI News »

[18 Sep 2009 | | ]

I’m posting this up here again - I realize that a lot of people have already seen this, so it’s not new, but since some very detailed questions popped up in a conversation this week regarding wireless and PCI I thought I’d put it out there again…
Information Supplements - PCI Security Standards Council.

Conferences / Webinars, PCI Philosophy / Approach, featured »

[9 Sep 2009 | | ]
Video of NetSPI’s Presentation on PCI and PA-DSS and Development

Here’s a video of Seth Peter, NetSPI’s CTO, presenting to the Minnesota OWASP chapter’s annual half-day conference…

Seth Peter: The Developers Guide to PCI DSS and PA-DSS Requirements from David Bryan on Vimeo.

PCI Philosophy / Approach »

[6 Aug 2009 | | ]

So my first post for the official NetSPI PCI blog is up there and, true to form, it’s not of a technical nature - merely an observation on how far the impact of PCI reaches.  One of the things that I talk about is how the retail and hospitality communities have gone through something very close to the grieving process in dealing with PCI - now organizations outside of retail and hospitality are starting this process - and it’s just as painful for them as it was for the retail …

Conferences / Webinars, Interesting, PCI Philosophy / Approach »

[7 Jul 2009 | | ]

Seth Peter, NetSPI’s CTO participated in a webinar on Preventing Multi-Vector Attacks with Eric Schultze from Shavlik.  When two very technical security CTOs get together there is a concern (a legitimate concern) that things are going to be unmanageably technical, but it actually turned out to be a great event.  It was very conversational and did a very good job of highlighting some of the concerns involved in dealing with sophisticated attacks.
With that said, it might not be the sort of content that you are going to want to ask …

PCI Philosophy / Approach, Vendors, featured »

[15 Jun 2009 | | ]
PA-DSS and ‘Enforcement’

I have spoken with a number of companies over the last several weeks that are preparing themselves to go through the PA-DSS assessment process (software providers, not security firms) and they all are trying to understand the level of priority that they need to set.  Particularly smaller firms are trying to come to grips with the fact that they are now required to go through an expensive, potentially disruptive assessment process that they didn’t have to address previously.
It only makes sense that they all end up asking the question, ‘are …

Interesting, PCI Philosophy / Approach, Vendors »

[15 Jan 2009 | | ]

OK - I should be adding some content here, but this short post on Anton Chuvakin’s blog is too good.  If you are in retail IT and ‘compliance’ has been ‘given’ to you (aren’t you lucky), you need to read this post and follow the links….
Anton Chuvakin Blog - “Security Warrior”: Tales From the “Compliance First” World.