User Blogs

User Blogs

A short description about your blog
Jun 12
2012

Update version of the PCI Compliance Dashboard

Posted by Didier Godart in PCI

Didier Godart

Please feel free to use this “compliance dashboard” spreadsheet to sustain your PCI compliance journey.

Nov 23
2011

Decision is Key!

Posted by Didier Godart in Risk Management , Compliance

Didier Godart

In my previous blog "Something Rotten in my Kingdom" I asked the question: Can we envisage a way to improve security through compliance? 

Nov 15
2011

PCI 30 seconds newsletter #14 – The World Isn't Perfect

Posted by Didier Godart in PCI

Didier Godart
According to the 2011 Verizon Payment Card Industry Compliance Report, requirement 11 - "Regularly test security systems and processes" - is the one least met, so I thought I would dedicate a few newsletters to this subject, starting with the definition and source of vulnerabilities. 

The term "vulnerabilities" is often used in the PCI DSS standard to mean the following (per the definition given by the Council):

Nov 09
2011

Something is rotten in my kingdom

Posted by Didier Godart in Information Security , Compliance

Didier Godart

Ten years ago, self-regulation through the implementation of good security practices was thought to be the way organizations would protect their, and our, sensitive data but the number of reported security incidents demonstrates that self-regulation doesn't actually work. It's like hoping that a kid does his home work only because he fully understands all the benefit for himself. Actually, this kind of self-governing behaviour requires some level of maturity and a deep self-consciousness of the risks faced.

Oct 31
2011

New PCI Compliance Dashboard Available - Nov 2011

Posted by Didier Godart in PCI

Didier Godart

Please feel free to use this “compliance dashboard” spreadsheet to sustain your PCI gap analysis exercise. It encompasses:

Oct 24
2011

PCI 30 seconds newsletter #13 – Compensating controls, Magic or Mirage?

Posted by Didier Godart in PCI

Didier Godart

There are circumstances where companies could face some technical or business impediments preventing them from implementing the requirements as explicitly stated in the standard. Does this mean that these companies could never achieve and maintain compliance?

Oct 10
2011

New PCI Compliance Dashboard - Available

Posted by Didier Godart in PCI

Didier Godart

The PCI Compliance Dashboard is a spreadsheet providing  a single view on all information you need to complete the PCI Compliance process without requiring to open multiple documents on the side.

Oct 03
2011

PCI 30 second newsletter N°5 – What's your “type”?

Posted by Didier Godart in PCI

Didier Godart

Do not mistake “Levels” for “Types”!

In newsletter #4 we saw that the payment brands classify organizations accepting and processing credit cards into “levels.” Levels are related to the number of transaction processed annually on the payment brand networks and are used to indicate what compliance validation procedures and reporting requirements targeted entities are expected to complete.

Oct 03
2011

My thoughts on the 2011 Verizon PCI Compliance Report

Posted by Didier Godart in PCI , Information Security , Compliance

Didier Godart

If you ever endeavour getting data about the compliance rate from PCIco or the Payment Brands you would know how challenging it is, probably more challenging than finding the Holy Grail. So in this context the release of the Verizon 2011 Payment Card Industry Compliance Report is quite enlightening for the security industry and merchant community. It gives us a good sense of reality of the field.

Sep 08
2011

PCI 30 seconds Newsletter N°4 – Merchant levels: What, Who and How.

Posted by Didier Godart in PCI

Didier Godart

What is a level? 

“Levels” is a classification of organizations accepting and processing credit cards.  They are defined and used by the payment brands to indicate what compliance validation procedures and reporting requirements targeted entities are expected to complete.

Sep 02
2011

PCI 30 seconds Newsletter N°3 – Roles distribution for the PCI play.

Posted by Didier Godart in PCI

Didier Godart
In this newsletter we will distribute the roles for the PCI play. 

Regulators (scenarists and directors)

Aug 16
2011

PCI 30 seconds newsletter #2 – Payment processing terminology and workflow

Posted by Didier Godart in PCI

Didier Godart

Hi Everyone,

  • «
  •  Start 
  •  Prev 
  •  1 
  •  2 
  •  Next 
  •  End 
  • »

Subscribe via Email

 Your Email:

Tag Cloud

2012 abduction Aberdeen Group alarm alarms Android Apple Apps ATM Skimming Audit Bank Fraud Banking Security BillGuard botnet BPM breaches BS 25999 burglar burglary Business Continuity BYOD Cloud Cloud Security Cobit Compliance computer failure Consumer IT Tips contactless credit card credit card breaches Credit Card Fraud credit cards credit fraud Cross-Device Security Cyber Security cyberbullying cybercrime cybercriminals cybersecurity cyberwise data Data Backup Data Breaches Data Storage DDOS Device Reputation Digital Forensics Digital Security digitally secure Disaster Recovery DNS download DPI driver's license dumps E-Commerce eBanking Electronic Discovery Electronic ESI electronic passport EMV Endpoint Security Epsilon ERM ESI Ethics Events Facebook FCC FCPA FDIC Federal Government FFIEC Financial Crisis Fraud gaming Gartner Geo-tagging gold farming Governance GPS grc GRC Marketplace Green IT grey charges Hackers Hacktivism home security HP IAM iCloud ID Theft Identity theft Information Management Information Security Information Supply Insider Threat Internal Audit Internal Controls internet safety iovation IP address ISACA ISO 27000 ISO 27001 ISO 31000 IT Alignment it compliance it governance IT GRC Forum Events it risk management IT Security IT Service Management ITIL jailbreaking Jobs laptop security Litigation Malware marathon mCommerce Member Discount Mobile Apps Mobile Banking mobile device Mobile Device Management Mobile Devices Mobile payment mobile phone mobile security Mobile Wallet mSecurity Multi-Regulatory Compliance multifactor authentication myblog Network Security New Years NFC Online Backup Online Banking online dating online gaming online identity online privacy online safety Online Security online shopping Operational Management OSHA Outsourcing P2P Security Panel Partner Offers passwords PCI Performance Management personal data personal device Personal Security pheasting phishing Policy predator Privacy Prize Draw QR Codes ransomeware ransomware Regulation E resume fraud Risk Assessment Risk Management RSA Rules safety tips scam scammer scammers Scams Seasonal Security security apps security tips sext skimming Skimming Fraud small business smartphone smartphones smishing Social Media social network Social Security SOX spammers spokesman Spyware SSDs Standards strangers Strategy tablets tax scams Tech tech support technology Threat Management Tokenization TQM Twitter typosquatting Virus VPN web Webcast Q&A Wi-Fi WIFI wireless
Banner