<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Payment Card Security &#38; IT Controls Explained</title>
	<atom:link href="http://pcidss.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://pcidss.wordpress.com</link>
	<description>Dedicated to exploring the challenging world of sensitive card data, and technology controls</description>
	<lastBuildDate>Sun, 29 Jan 2012 00:34:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='pcidss.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Payment Card Security &#38; IT Controls Explained</title>
		<link>http://pcidss.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://pcidss.wordpress.com/osd.xml" title="Payment Card Security &#38; IT Controls Explained" />
	<atom:link rel='hub' href='http://pcidss.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Release of Symantec source code leads to &#8216;uninstall&#8217; recommendation</title>
		<link>http://pcidss.wordpress.com/2012/01/26/release-of-symantec-source-code-leads-to-uninstall-recommendation/</link>
		<comments>http://pcidss.wordpress.com/2012/01/26/release-of-symantec-source-code-leads-to-uninstall-recommendation/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 14:48:34 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[cyber espionage]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[indian cyber]]></category>
		<category><![CDATA[it compliance and controls]]></category>
		<category><![CDATA[james deluccia]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[symantec]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=398</guid>
		<description><![CDATA[Symantec was the victim of an attack where its source code for most major products protecting consumers and enterprises around the world was breached.  This attack occurred in 2006 and the source code has been available to parties to leverage &#8230; <a href="http://pcidss.wordpress.com/2012/01/26/release-of-symantec-source-code-leads-to-uninstall-recommendation/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&amp;blog=274743&amp;post=398&amp;subd=pcidss&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2012/01/26/release-of-symantec-source-code-leads-to-uninstall-recommendation/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Vendor Proof of Security, GSA Final Rule and how it can help everybody else</title>
		<link>http://pcidss.wordpress.com/2012/01/20/vendor-proof-of-security-gsa-final-rule-and-how-it-can-help-everybody-else/</link>
		<comments>http://pcidss.wordpress.com/2012/01/20/vendor-proof-of-security-gsa-final-rule-and-how-it-can-help-everybody-else/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 08:52:41 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[it compliance and controls]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[james deluccia]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[vendor audit]]></category>
		<category><![CDATA[gsa]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=395</guid>
		<description><![CDATA[The GSA Final Rule got a lot of attention in the government services sector as it solidified the requirements related to security and third parties.  The Final Rule makes it clear that upon winning a contract and to continue the &#8230; <a href="http://pcidss.wordpress.com/2012/01/20/vendor-proof-of-security-gsa-final-rule-and-how-it-can-help-everybody-else/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&amp;blog=274743&amp;post=395&amp;subd=pcidss&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2012/01/20/vendor-proof-of-security-gsa-final-rule-and-how-it-can-help-everybody-else/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Would you be PCI Compliant if there were not fines, fees, damages?  Possible result of court case</title>
		<link>http://pcidss.wordpress.com/2012/01/19/would-you-be-pci-compliant-if-there-were-not-fines-fees-damages-possible-result-of-court-case/</link>
		<comments>http://pcidss.wordpress.com/2012/01/19/would-you-be-pci-compliant-if-there-were-not-fines-fees-damages-possible-result-of-court-case/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 10:06:35 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[it compliance and controls]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[james deluccia]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[u.s. bank]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=392</guid>
		<description><![CDATA[An interesting thought exercise is would businesses be compliant with an industry standard, such as PCI DSS, and regularly evaluate their security posture against this standard if there was NO fines, punishments, or financial liabilities present?  Would organizations secure and &#8230; <a href="http://pcidss.wordpress.com/2012/01/19/would-you-be-pci-compliant-if-there-were-not-fines-fees-damages-possible-result-of-court-case/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&amp;blog=274743&amp;post=392&amp;subd=pcidss&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2012/01/19/would-you-be-pci-compliant-if-there-were-not-fines-fees-damages-possible-result-of-court-case/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>When vendors attack, inspired by India espionage reports of USCC and Symantec</title>
		<link>http://pcidss.wordpress.com/2012/01/18/when-vendors-attack-inspired-by-india-espionage-reports-of-uscc-and-symantec/</link>
		<comments>http://pcidss.wordpress.com/2012/01/18/when-vendors-attack-inspired-by-india-espionage-reports-of-uscc-and-symantec/#comments</comments>
		<pubDate>Wed, 18 Jan 2012 09:43:03 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[it compliance and controls]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Validation]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[james deluccia]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[uscc]]></category>
		<category><![CDATA[yamatough]]></category>
		<category><![CDATA[india]]></category>
		<category><![CDATA[espionage]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=390</guid>
		<description><![CDATA[The attacker victim scenarios we designed are no longer appropriate.  It is amazing that no less than a decade ago I was working with teams to design information security attack scenarios where we were dealing mainly with mafia, ex-intelligence agents, &#8230; <a href="http://pcidss.wordpress.com/2012/01/18/when-vendors-attack-inspired-by-india-espionage-reports-of-uscc-and-symantec/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&amp;blog=274743&amp;post=390&amp;subd=pcidss&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2012/01/18/when-vendors-attack-inspired-by-india-espionage-reports-of-uscc-and-symantec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>When Cryptography is irrelevant, bypassing key card security</title>
		<link>http://pcidss.wordpress.com/2012/01/17/when-cryptography-is-irrelevant-bypassing-key-card-security/</link>
		<comments>http://pcidss.wordpress.com/2012/01/17/when-cryptography-is-irrelevant-bypassing-key-card-security/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 21:32:46 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[it compliance and controls]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[regulation]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[fisma]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[james deluccia]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[smartcards]]></category>
		<category><![CDATA[GSC-IS]]></category>
		<category><![CDATA[sykipot]]></category>
		<category><![CDATA[attack]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=388</guid>
		<description><![CDATA[A malware executed attack was highlighted by ActivClient that provides technology for secure authentication (smart cards to comply with the GSC-IS 2.1).  The attack is described in detail in a number of sites, such as Security Week here, and I &#8230; <a href="http://pcidss.wordpress.com/2012/01/17/when-cryptography-is-irrelevant-bypassing-key-card-security/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&amp;blog=274743&amp;post=388&amp;subd=pcidss&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2012/01/17/when-cryptography-is-irrelevant-bypassing-key-card-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Implications of Data Breaches on OOW, beyond the PCI equation</title>
		<link>http://pcidss.wordpress.com/2012/01/16/implications-of-data-breaches-on-oow-beyond-the-pci-equation/</link>
		<comments>http://pcidss.wordpress.com/2012/01/16/implications-of-data-breaches-on-oow-beyond-the-pci-equation/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 21:15:35 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[information security]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[it compliance and controls]]></category>
		<category><![CDATA[pci]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=385</guid>
		<description><![CDATA[Over the years I have been expressing the implications of out of wallet authentication information and &#8220;personally unique&#8221; data of individuals.  My journey led me to write the book, IT Compliance and Controls, where I sought to humbly draft operational &#8230; <a href="http://pcidss.wordpress.com/2012/01/16/implications-of-data-breaches-on-oow-beyond-the-pci-equation/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&amp;blog=274743&amp;post=385&amp;subd=pcidss&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2012/01/16/implications-of-data-breaches-on-oow-beyond-the-pci-equation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>What does the SCADA water pump attack mean to your business&#8230;</title>
		<link>http://pcidss.wordpress.com/2011/11/19/what-does-the-scada-water-pump-attack-mean-to-your-business/</link>
		<comments>http://pcidss.wordpress.com/2011/11/19/what-does-the-scada-water-pump-attack-mean-to-your-business/#comments</comments>
		<pubDate>Sat, 19 Nov 2011 18:33:32 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[2011]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[europe]]></category>
		<category><![CDATA[it compliance and controls]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[james deluccia]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[scada]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[vendor management]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=378</guid>
		<description><![CDATA[The ability to attack, compromise, and cause damage has existed since the utility industry began connecting these systems on the Internet.  Examples, including the European nation that was attacked 24+ months ago, are easy to locate.  Yesterday an attack (more &#8230; <a href="http://pcidss.wordpress.com/2011/11/19/what-does-the-scada-water-pump-attack-mean-to-your-business/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&amp;blog=274743&amp;post=378&amp;subd=pcidss&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2011/11/19/what-does-the-scada-water-pump-attack-mean-to-your-business/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Convergence Risk:  Google Chrome and Extensions, at BlackHat 2011</title>
		<link>http://pcidss.wordpress.com/2011/08/05/convergence-risk-google-chrome-and-extensions-at-blackhat-2011/</link>
		<comments>http://pcidss.wordpress.com/2011/08/05/convergence-risk-google-chrome-and-extensions-at-blackhat-2011/#comments</comments>
		<pubDate>Fri, 05 Aug 2011 13:27:30 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[information security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[2011]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[it compliance and controls]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=375</guid>
		<description><![CDATA[Interesting quotes from guys that demonstrated attack vectors in Google&#8217;s Chrome during Blackhat 2011: “The software security model we’ve been dealing with for decades now has been reframed,” Johansen said.  “It’s moved into the cloud and if you’re logged into &#8230; <a href="http://pcidss.wordpress.com/2011/08/05/convergence-risk-google-chrome-and-extensions-at-blackhat-2011/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&amp;blog=274743&amp;post=375&amp;subd=pcidss&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2011/08/05/convergence-risk-google-chrome-and-extensions-at-blackhat-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Joseph Black, ex-CIA, spoke on cyberwar and the future at Blackhat</title>
		<link>http://pcidss.wordpress.com/2011/08/04/joseph-black-ex-cia-spoke-on-cyberwar-and-the-future-at-blackhat/</link>
		<comments>http://pcidss.wordpress.com/2011/08/04/joseph-black-ex-cia-spoke-on-cyberwar-and-the-future-at-blackhat/#comments</comments>
		<pubDate>Thu, 04 Aug 2011 19:22:01 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[2011]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[it compliance and controls]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=373</guid>
		<description><![CDATA[Joseph Black a counter-terrorism expert spoke at Blackhat on Cyberwar and the challenges of communicating the threats to leadership.  A few core highlights of that talk: &#8220;&#8230;toughest thing about predicting terrorist attacks was getting people in power to take the &#8230; <a href="http://pcidss.wordpress.com/2011/08/04/joseph-black-ex-cia-spoke-on-cyberwar-and-the-future-at-blackhat/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&amp;blog=274743&amp;post=373&amp;subd=pcidss&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2011/08/04/joseph-black-ex-cia-spoke-on-cyberwar-and-the-future-at-blackhat/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
		<item>
		<title>Analysis of McAfee&#8217;s Operation Shady RAT Report and highlights</title>
		<link>http://pcidss.wordpress.com/2011/08/04/analysis-of-mcafees-operation-shady-rat-report-and-highlights/</link>
		<comments>http://pcidss.wordpress.com/2011/08/04/analysis-of-mcafees-operation-shady-rat-report-and-highlights/#comments</comments>
		<pubDate>Thu, 04 Aug 2011 18:21:42 +0000</pubDate>
		<dc:creator>pcidss</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[2011]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[it compliance and controls]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://pcidss.wordpress.com/?p=370</guid>
		<description><![CDATA[Tis Blackhat &#38; Defcon, so follows are my thoughts … McAfee released yesterday their Operation Shady RAT paper.  It focuses on data captured from a command and control server that had logs over a 6 year period.  They go into &#8230; <a href="http://pcidss.wordpress.com/2011/08/04/analysis-of-mcafees-operation-shady-rat-report-and-highlights/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pcidss.wordpress.com&amp;blog=274743&amp;post=370&amp;subd=pcidss&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://pcidss.wordpress.com/2011/08/04/analysis-of-mcafees-operation-shady-rat-report-and-highlights/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2995ac525e21c6c648e2454d926c073f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pcidss</media:title>
		</media:content>
	</item>
	</channel>
</rss>
