<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Payment Card Security &#38; IT Controls Explained &#187; audit</title>
	<atom:link href="http://pcidss.wordpress.com/category/audit/feed/" rel="self" type="application/rss+xml" />
	<link>http://pcidss.wordpress.com</link>
	<description>Card security effects everyone.  I will utilize this forum to communicate the ongoing efforts to safeguard this type of data.</description>
	<lastBuildDate>Mon, 30 Nov 2009 23:46:29 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='pcidss.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/dea04d321dd6d73d3835656d2ada6027?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Payment Card Security &#38; IT Controls Explained &#187; audit</title>
		<link>http://pcidss.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://pcidss.wordpress.com/osd.xml" title="Payment Card Security &amp; IT Controls Explained" />
		<item>
		<title>British Security Defense Manual Leaked&#8230;</title>
		<link>http://pcidss.wordpress.com/2009/11/30/british-security-defense-manual-leaked/</link>
		<comments>http://pcidss.wordpress.com/2009/11/30/british-security-defense-manual-leaked/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 23:46:29 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[auditing]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[regulations]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=213</guid>
		<description><![CDATA[The British government had their Defence Manual of Security (2001) leaked to the internet on October 4, 2009.  The press and wikileaks provide a great breakdown of the information within it, and it is fairly accessible to those interested.  What strikes me as interesting is not that it is in the public space now, but [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=213&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2009/11/30/british-security-defense-manual-leaked/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Federal Court fines Payment Processor for poor Business Practices</title>
		<link>http://pcidss.wordpress.com/2009/06/22/federal-court-fines-payment-processor-for-poor-business-practices/</link>
		<comments>http://pcidss.wordpress.com/2009/06/22/federal-court-fines-payment-processor-for-poor-business-practices/#comments</comments>
		<pubDate>Mon, 22 Jun 2009 15:40:35 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[Institute of Internal Auditors]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[fines]]></category>
		<category><![CDATA[ftc]]></category>
		<category><![CDATA[merchant]]></category>
		<category><![CDATA[payment processor]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[sas 70]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=178</guid>
		<description><![CDATA[Proper business practices are a necessity in business, and when dealing with other people&#8217;s money it is paramount.  The FTC, again, has charged a fine against a business for not doing proper due diligence on new accounts within their operations.  ChoicePoint, now owned wholly by Lexis-Nexis, was previously found guilty of such practices in their [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=178&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2009/06/22/federal-court-fines-payment-processor-for-poor-business-practices/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Twitter, PCI DSS posts&#8230;</title>
		<link>http://pcidss.wordpress.com/2009/05/26/twitter-pci-dss-posts/</link>
		<comments>http://pcidss.wordpress.com/2009/05/26/twitter-pci-dss-posts/#comments</comments>
		<pubDate>Tue, 26 May 2009 14:17:42 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=171</guid>
		<description><![CDATA[In preparation for a PCI DSS training seminar I am hosting this month I uncovered a few nuggets within the PCI DSS universe that ALWAYS draws questions and concerns.  Catch my 140 character contributions below.  If you are not using Twitter or another search aggregator to identify updates and vulnerabilities you are working too hard [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=171&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2009/05/26/twitter-pci-dss-posts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>

		<media:content url="http://search.twitter.com/images/search/expanding.gif?1242860246" medium="image" />

		<media:content url="http://search.twitter.com/images/search/expanding.gif?1242860246" medium="image" />

		<media:content url="http://search.twitter.com/images/search/expanding.gif?1242860246" medium="image" />
	</item>
		<item>
		<title>PCI DSS Update 1/16/09:  Discover Validation Levels</title>
		<link>http://pcidss.wordpress.com/2009/01/16/pci-dss-update-11609-discover-validation-levels/</link>
		<comments>http://pcidss.wordpress.com/2009/01/16/pci-dss-update-11609-discover-validation-levels/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 15:40:58 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[audit]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Validation]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=146</guid>
		<description><![CDATA[Discover has updated their validation requirements to be more explicit today.  The press release states:
DISC is Discover Network’s compliance management program and was designed to support the requirements outlined in the PCI DSS. The PCI DSS is an industry security requirement for safeguarding payment cardholder data. It was developed to facilitate the broad adoption of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=146&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2009/01/16/pci-dss-update-11609-discover-validation-levels/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>

		<media:content url="http://pcidss.files.wordpress.com/2009/01/picture-1.png" medium="image">
			<media:title type="html">picture-1</media:title>
		</media:content>
	</item>
		<item>
		<title>MEGA PCI / Payment Card Training, a survivor of CPISA/CPISM Training</title>
		<link>http://pcidss.wordpress.com/2008/11/12/mega-pci-payment-card-training-a-survivor-of-cpisacpism-training/</link>
		<comments>http://pcidss.wordpress.com/2008/11/12/mega-pci-payment-card-training-a-survivor-of-cpisacpism-training/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 14:21:46 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[audit]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=123</guid>
		<description><![CDATA[This week I sat through undoubtedly the best education I have had surrounding the payment industry and specifically PCI DSS.  The training was provided by the Aegenis group for the Society of Payment Security Professionals &#8211; who include note worthies such as Michael Dahn of PCI Answers.com, and Chris Mark.  The training was three very [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=123&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/11/12/mega-pci-payment-card-training-a-survivor-of-cpisacpism-training/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Recap: CSO Executive Seminar on PCI Compliance, by James DeLuccia</title>
		<link>http://pcidss.wordpress.com/2008/09/11/recap-cso-executive-seminar-on-pci-compliance-by-james-deluccia/</link>
		<comments>http://pcidss.wordpress.com/2008/09/11/recap-cso-executive-seminar-on-pci-compliance-by-james-deluccia/#comments</comments>
		<pubDate>Thu, 11 Sep 2008 15:06:35 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>
		<category><![CDATA[audit]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=111</guid>
		<description><![CDATA[On September 10th I spoke at the CSO Conference on the PCI DSS with an impressive group of speakers and representatives from across the industry, including Chris Mark and numerous CIOs.  The discussions focused on the current state of the union within the Payment Transaction vertical.  There was plenty of focus on the usage of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=111&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/09/11/recap-cso-executive-seminar-on-pci-compliance-by-james-deluccia/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>NEW Fraud Survey &#8211; Identify Impactful Internal controls</title>
		<link>http://pcidss.wordpress.com/2008/07/07/new-fraud-survey-identify-impactful-internal-controls/</link>
		<comments>http://pcidss.wordpress.com/2008/07/07/new-fraud-survey-identify-impactful-internal-controls/#comments</comments>
		<pubDate>Mon, 07 Jul 2008 12:54:20 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[ROI]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[regulations]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=101</guid>
		<description><![CDATA[In the mail I received an early copy of the &#8220;2008 Report to the Nation on Occupational Fraud and Abuse&#8221; from the Association of Certified Fraud Examiners.  The 2006 report has represented de facto standard for qualitative fraud calculations and risk mitigation efforts.  While there is no substitute for reading the full report I will [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=101&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/07/07/new-fraud-survey-identify-impactful-internal-controls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Enterprise Risk Managment (ERM) Programs &#8211; Maximizing Risk with Biz Culture</title>
		<link>http://pcidss.wordpress.com/2008/05/19/enterprise-risk-managment-erm-programs-maximizing-risk-with-biz-culture/</link>
		<comments>http://pcidss.wordpress.com/2008/05/19/enterprise-risk-managment-erm-programs-maximizing-risk-with-biz-culture/#comments</comments>
		<pubDate>Mon, 19 May 2008 18:44:00 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[audit]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=88</guid>
		<description><![CDATA[Establishing an IT control environment that is agile and appropriate to an organization is a primary objective of IT Compliance and Controls, a recent book I released based on a global effort.  The Institute of Internal Auditors this month in their regular publication, &#8220;Internal Auditor&#8220;, has a great article &#8220;The Right Fit: Auditing ERM Frameworks&#8221; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=88&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/05/19/enterprise-risk-managment-erm-programs-maximizing-risk-with-biz-culture/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Presentation notes: PCI DSS Networking Key Tenets</title>
		<link>http://pcidss.wordpress.com/2008/04/02/presentation-notes-pci-dss-networking-key-tenets/</link>
		<comments>http://pcidss.wordpress.com/2008/04/02/presentation-notes-pci-dss-networking-key-tenets/#comments</comments>
		<pubDate>Wed, 02 Apr 2008 19:53:01 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[information security]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/2008/04/02/presentation-notes-pci-dss-networking-key-tenets/</guid>
		<description><![CDATA[I recently spoke on the best practices found within the PCI DSS and networking security practices.  The audience represented both providers of payment transactions, retail services, and banking solutions.  The singular focus provided a forum to dive deeper into the security and compliance intents of PCI DSS while not damaging the worth and importance of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=78&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/04/02/presentation-notes-pci-dss-networking-key-tenets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>FTC rules on TJX Data Breach, WSJ</title>
		<link>http://pcidss.wordpress.com/2008/03/28/ftc-rules-on-tjx-data-breach-wsj/</link>
		<comments>http://pcidss.wordpress.com/2008/03/28/ftc-rules-on-tjx-data-breach-wsj/#comments</comments>
		<pubDate>Fri, 28 Mar 2008 17:06:14 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[information security]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=76</guid>
		<description><![CDATA[
I woke up this morning and was encouraged to see the FTC continue on its efforts to monitor the technology safeguards of companies in at least a consistent and security-risk minded approach.  Now, while I am not a fan of unnecessary regulations and always feel a healthy bit of regular evaluation and expiration is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=76&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/03/28/ftc-rules-on-tjx-data-breach-wsj/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>

		<media:content url="http://pcidss.files.wordpress.com/2008/03/picture-2.png" medium="image">
			<media:title type="html">picture-2.png</media:title>
		</media:content>
	</item>
	</channel>
</rss>