Wednesday, 26 May 2010

PCI DSS QSA, ISA and Iron Man 2


Once upon a time, a PCI SSC member sat down watching the Iron Man sequel in cinema called Iron Man 2. Quite impressed by the character Ivan Vanko (played by Mickey Rourke), an idea struck to create a vaguely similar character for the QSA, and name it ISA. Internal employee will go through the PCI SSC ISA training and interpret the standard to create something called the ‘ISA jacket’. At the same time, somewhere in the world or locally, a QSA Company is busy creating a QSA who is working on the ‘QSA jacket’. When being assessed, the internal employee will wear the 'ISA jacket' to protect the assessed environment when QSA comes donning the ‘QSA jacket’. This jacket will also be useful when doing self assessments. There may be sparks when the two jackets meet, but the assessed organisation is intended to benefit. However, this ISA jacket doesn’t come cheap so organisations beware!



Media_http1bpblogspot_cfyax


New questions will be raised, arguments discussed and hopefully clarified and agreed with the intent to improve the security of the organisations – this is exactly what both jackets were created to achieve, stop the bad guys! Having thought of this again, the ISA seems more of the James Rhodes’ character played by Don Cheadle. Ivan Vanko (use Russian accent from here) is more like the Albert Gonzalez’s of the real world. :)

More ISA info here: https://www.pcisecuritystandards.org/education/isa_training.shtml

No comments:

Post a Comment