« January 2008 | Main | March 2008 »

February 27, 2008

Dude! Will you blog or something?!

Greetings folks! How about a headline wrap-up? Ready? OK!

What a week!

February 19, 2008

From the Dept of Obvious Statements: PCI Not Just for Cardholder Data!

Evan Schuman (Storefront Backtalk) wrote on Valentine's Day that PCI is not just for payments anymore. Hate it or love it, PCI is a great standard for a baseline of security. You can replace Cardholder Data with just about any type of data you want to protect, and you can establish a minimum baseline that will do a reasonable job of keeping that data protected. Security consultants have been pointing this out for a while.

I think the part of this that is the most telling is that the security and IT programs in some companies are so bad and so far gone, that PCI is what is standing it up. Again, I still believe that the PCI-DSS is a good baseline for companies to start with, but PCI is tailored to the protection of cardholder data (duh). Companies should be taking a broader look at their security and IT postures, extending beyond PCI.

PCI can also be an excellent poster child for building a security program. If you can get it right with PCI first, you can use your experience to extend that program into other areas of the company (take it up a level).

February 15, 2008

MasterCard updates compliance dates

In a recent update to their website, MasterCard has altered its merchant levels to match Visa's, and is giving Level 2 merchants until December 31, 2008 to validate compliance. This is another entry in the long standing debate about compliance dates, and what that means for merchants.

Most of these merchants are already being fined in conjunction with the Visa Compliance Acceleration Program if they have not validated, so the extended dates may indicate fines or tougher pressure by MasterCard as the date passes (this is PURE speculation). This should not add any pressure to existing Level 2 merchants that have not validated, though having 2 card associations looking at you is definitely worse than one.

February 08, 2008

See you at eTail 2008!

Greetings out there! If you happen to be at eTail next week, please stop by the VeriSign booth and say "Hi!" I would be happy to discuss the NRF or Tim Callan's EV-SSL.

See you there!

February 06, 2008

New PCI Self Assessment Questionnaire

The PCI Security Standards Council has released the long awaited version 1.1 of the Self Assessment Questionnaire (or should I say questionnaires). The key thing here is that the validation requirements are different depending on the type of merchant you are. There are now 4 versions of the questionnaire as opposed to 1, and they do map to the current PCI 1.1 standards.

I think I assume that the intent is to keep the SAQ mirrored to the current version of the standards from now on, so we should see them updated this year if the standards are updated as planned. In addition, during the webinar call we asked if PA-DSS is still on track, and the response was "Yes," it should still be released this quarter. We're looking forward to that!

February 01, 2008

People Hacking!

Yes, it's true that part of the reason I was not posting very frequently is because I was running out of ideas. It is also true that I've started following Schneier's blog again. Anyway...

He's got an excellent post with 2 examples of how Social Engineering was successful in the theft of significant sums of money. Security is made up of People, Process, and Technology, and people are almost always the weakest link.