<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Payment Card Security &#38; IT Controls Explained &#187; PCI DSS</title>
	<atom:link href="http://pcidss.wordpress.com/category/pci-dss/feed/" rel="self" type="application/rss+xml" />
	<link>http://pcidss.wordpress.com</link>
	<description>Card security effects everyone.  I will utilize this forum to communicate the ongoing efforts to safeguard this type of data.</description>
	<lastBuildDate>Mon, 30 Nov 2009 23:46:29 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='pcidss.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/dea04d321dd6d73d3835656d2ada6027?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Payment Card Security &#38; IT Controls Explained &#187; PCI DSS</title>
		<link>http://pcidss.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://pcidss.wordpress.com/osd.xml" title="Payment Card Security &amp; IT Controls Explained" />
		<item>
		<title>British Security Defense Manual Leaked&#8230;</title>
		<link>http://pcidss.wordpress.com/2009/11/30/british-security-defense-manual-leaked/</link>
		<comments>http://pcidss.wordpress.com/2009/11/30/british-security-defense-manual-leaked/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 23:46:29 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[auditing]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[regulations]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=213</guid>
		<description><![CDATA[The British government had their Defence Manual of Security (2001) leaked to the internet on October 4, 2009.  The press and wikileaks provide a great breakdown of the information within it, and it is fairly accessible to those interested.  What strikes me as interesting is not that it is in the public space now, but [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=213&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2009/11/30/british-security-defense-manual-leaked/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>What advantages / safeguards can businesses gain with Tor and Anonymizer</title>
		<link>http://pcidss.wordpress.com/2008/12/03/what-advantages-safeguards-can-businesses-gain-with-tor-and-anonymizer/</link>
		<comments>http://pcidss.wordpress.com/2008/12/03/what-advantages-safeguards-can-businesses-gain-with-tor-and-anonymizer/#comments</comments>
		<pubDate>Wed, 03 Dec 2008 20:56:46 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[PCI DSS]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=125</guid>
		<description><![CDATA[Inspired by &#8220;How Anonymous Do Businesses Need to be?&#8220;
I recently had the opportunity to lend my thoughts around this topic and was included in the article.  The article is here by Lora Bentley, who writes some interesting articles and I highly recommend reviewing her prior work.  Below is her question and my response:
&#8220;&#8230;when and why [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=125&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/12/03/what-advantages-safeguards-can-businesses-gain-with-tor-and-anonymizer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>MEGA PCI / Payment Card Training, a survivor of CPISA/CPISM Training</title>
		<link>http://pcidss.wordpress.com/2008/11/12/mega-pci-payment-card-training-a-survivor-of-cpisacpism-training/</link>
		<comments>http://pcidss.wordpress.com/2008/11/12/mega-pci-payment-card-training-a-survivor-of-cpisacpism-training/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 14:21:46 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[audit]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=123</guid>
		<description><![CDATA[This week I sat through undoubtedly the best education I have had surrounding the payment industry and specifically PCI DSS.  The training was provided by the Aegenis group for the Society of Payment Security Professionals &#8211; who include note worthies such as Michael Dahn of PCI Answers.com, and Chris Mark.  The training was three very [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=123&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/11/12/mega-pci-payment-card-training-a-survivor-of-cpisacpism-training/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Regulation Effects to the Payment Industry: AMEX is a Bank</title>
		<link>http://pcidss.wordpress.com/2008/11/12/regulation-effects-to-the-payment-industry-amex-is-a-bank/</link>
		<comments>http://pcidss.wordpress.com/2008/11/12/regulation-effects-to-the-payment-industry-amex-is-a-bank/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 14:09:41 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[regulations]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=120</guid>
		<description><![CDATA[So, there are tremendous implications for their business model, but to place the spotlight on one area lets focus on data security and regulations (my favorite).  AMEX is one of the organizations that built the PCI DSS, PCI SSC, and all recent publications.  The intent of PCI was to have industry forced mandates that protect [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=120&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/11/12/regulation-effects-to-the-payment-industry-amex-is-a-bank/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Dear PCI SSC: How I would change ASV program</title>
		<link>http://pcidss.wordpress.com/2008/11/06/dear-pci-ssc-how-i-would-change-asv-program/</link>
		<comments>http://pcidss.wordpress.com/2008/11/06/dear-pci-ssc-how-i-would-change-asv-program/#comments</comments>
		<pubDate>Thu, 06 Nov 2008 02:38:20 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[PCI DSS]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=118</guid>
		<description><![CDATA[Organizations that have to comply with PCI DSS have undergone at one time or another a Automated Remote Vulnerability scan, as required for all Public Internet Facing IP addresses that cater to the payment transaction systems. However most would also agree that the assessments are not thorough and do not indicate a secure website or [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=118&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/11/06/dear-pci-ssc-how-i-would-change-asv-program/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;The Inside Story of PCI: Confessions of a QSA,&#8221; commentary by James DeLuccia</title>
		<link>http://pcidss.wordpress.com/2008/09/19/the-inside-story-of-pci-confessions-of-a-qsa-commentary-by-james-deluccia/</link>
		<comments>http://pcidss.wordpress.com/2008/09/19/the-inside-story-of-pci-confessions-of-a-qsa-commentary-by-james-deluccia/#comments</comments>
		<pubDate>Fri, 19 Sep 2008 13:46:06 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[PCI DSS]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=113</guid>
		<description><![CDATA[In a nice article on Tech Target John Kindervag, a wicked smart guy, provides a recap of his presentation given at the Forrester Security Forum 2008, entitled &#8220;The Inside Story of PCI: Confessions of a QSA.&#8221;  John provides some very pragmatic steps to addressing PCI (and others can equally apply &#8211; SOX, HIPAA, BASEL, IFRS) [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=113&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/09/19/the-inside-story-of-pci-confessions-of-a-qsa-commentary-by-james-deluccia/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Recap: CSO Executive Seminar on PCI Compliance, by James DeLuccia</title>
		<link>http://pcidss.wordpress.com/2008/09/11/recap-cso-executive-seminar-on-pci-compliance-by-james-deluccia/</link>
		<comments>http://pcidss.wordpress.com/2008/09/11/recap-cso-executive-seminar-on-pci-compliance-by-james-deluccia/#comments</comments>
		<pubDate>Thu, 11 Sep 2008 15:06:35 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>
		<category><![CDATA[audit]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=111</guid>
		<description><![CDATA[On September 10th I spoke at the CSO Conference on the PCI DSS with an impressive group of speakers and representatives from across the industry, including Chris Mark and numerous CIOs.  The discussions focused on the current state of the union within the Payment Transaction vertical.  There was plenty of focus on the usage of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=111&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/09/11/recap-cso-executive-seminar-on-pci-compliance-by-james-deluccia/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>PCI DSS Requirement 2.2 &#8211; Primary Functions; comply or be compromised</title>
		<link>http://pcidss.wordpress.com/2008/08/27/pci-dss-requirement-22-primary-functions-comply-or-be-compromised/</link>
		<comments>http://pcidss.wordpress.com/2008/08/27/pci-dss-requirement-22-primary-functions-comply-or-be-compromised/#comments</comments>
		<pubDate>Wed, 27 Aug 2008 08:59:32 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=109</guid>
		<description><![CDATA[A recent engagement and publication reminded me of the criticality of limiting the ability of systems within an organization.  To be specific &#8211; servers should have a limited amount of services operating on them; these systems should have restricted access (inbound and outbound); chaining of servers and services must be avoided.
While this is fairly well [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=109&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/08/27/pci-dss-requirement-22-primary-functions-comply-or-be-compromised/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Extra Extra:  FREE PCI TRAINING</title>
		<link>http://pcidss.wordpress.com/2008/07/11/extra-extra-free-pci-training/</link>
		<comments>http://pcidss.wordpress.com/2008/07/11/extra-extra-free-pci-training/#comments</comments>
		<pubDate>Fri, 11 Jul 2008 08:12:37 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=102</guid>
		<description><![CDATA[I am a strong believer in group &#8220;live&#8221; training experiences where I am in a room with individuals who have different perspectives, challenges, and questions.  Unfortunately, the real world keeps spinning and constant training is not always possible, so the web (yes&#8230; that which gives and takes) has online training.  For those unaware there are [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=102&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/07/11/extra-extra-free-pci-training/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Enterprise Risk Managment (ERM) Programs &#8211; Maximizing Risk with Biz Culture</title>
		<link>http://pcidss.wordpress.com/2008/05/19/enterprise-risk-managment-erm-programs-maximizing-risk-with-biz-culture/</link>
		<comments>http://pcidss.wordpress.com/2008/05/19/enterprise-risk-managment-erm-programs-maximizing-risk-with-biz-culture/#comments</comments>
		<pubDate>Mon, 19 May 2008 18:44:00 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[audit]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=88</guid>
		<description><![CDATA[Establishing an IT control environment that is agile and appropriate to an organization is a primary objective of IT Compliance and Controls, a recent book I released based on a global effort.  The Institute of Internal Auditors this month in their regular publication, &#8220;Internal Auditor&#8220;, has a great article &#8220;The Right Fit: Auditing ERM Frameworks&#8221; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&blog=274743&post=88&subd=pcidss&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2008/05/19/enterprise-risk-managment-erm-programs-maximizing-risk-with-biz-culture/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
	</channel>
</rss>