2|SEC Cyber Security Blog

The Cyber Sentinel

Stay on top of the latest news and updates to stay ahead of the latest threats

PCI DSS

The PCI SSC vs the US Congress

The general manager of the PCI SSC, Bob Russo, and CTO Troy Leach were recently invited to present to the US Congress, on the subcommittee “Protecting Consumer Information: Can Data Breaches be Prevented?”. Their statements can be found here: https://www.pcisecuritystandards.org/documents/140202_PCI_SSC.pdf https://www.pcisecuritystandards.org/documents/HMTG-113-IF17-Wstate-RussoB-20140205.pdf Whilst the statements did a good job at supporting the PCI SSC and its […]

The PCI SSC vs the US Congress Read More »

2-sec and ControlScan announce Incident Response Plan Toolkit SIG

ControlScan, Inc. and 2-sec, Ltd. to Present “Incident Response Plan Toolkit” SIG Proposal at North American, European Payment Card Industry Community Meetings PCI Special Interest Group would improve merchants’ risk preparedness, incident handling                                                                                    ATLANTA and LONDON, Sept. 12, 2013 – Payment security and compliance solution provider ControlScan, Inc., and  security testing, QSA, PA-QSA

2-sec and ControlScan announce Incident Response Plan Toolkit SIG Read More »

PCI DSS 3.0 Draft Changes

The PCI SSC announced draft changes for PCI DSS v3.0 and PA-DSS v3.0 this week. Whilst for most QSAs this shouldn’t come as a surprise, what the standard will do is offer improved guidance for those whom are self assessing, to help ensure the intent of the standard is better understood by the merchant community.

PCI DSS 3.0 Draft Changes Read More »

CCTV Monitoring

We’ve been doing a few data centre audits as of late, and most entities seem to think just because they have CCTV at their co-location data centres, they meet the compliance requirements of PCI DSS. You’ll note from wording that access control systems need to be MONITORED.  If you’ve a data centre with a few

CCTV Monitoring Read More »

PCI DSS vs Operating Regulations

I came across an interesting interpretation of PCI DSS recently, whereby a Merchant thought that just because they had been assessed compliant against PCI DSS, then all assessed payment channels also met the security requirements of Visa Operating Regulations. SAQ-C-VT (Virtual Terminal) is a standard that can be used to assess card-not-present and card-present transactions

PCI DSS vs Operating Regulations Read More »

Scroll to Top