Tuesday, 14 December 2010
Some recent developments
Tuesday, 9 November 2010
Cloud, virtualisation and PCI DSS v2.0
For readers who keep up-to-date with the industry, virtualisation and cloud technologies need no introduction. PCI DSS v2.0 includes guidance on virtualisation compliance and is well explained and assessed here and here.
Cisco, HyTrust, VMware, Savvis and Coalfire have collaborated to construct a cloud reference architecture (here) that aims to address some of the unique challenges of the PCI DSS.
This certainly is an interesting read. I’ll post my observations in the following post, however it will be useful to know what you think of this development.
Thank you for reading and subscribing to this feed. Your comments are always welcome.
Thursday, 4 November 2010
Approved Scanning Vendors (ASVs - PCI DSS) in the UK
PCI DSS requirement 11.2 mandates organisations to run internal and external vulnerability scans at least quarterly and after any significant change in the network (such as new system component installations, changes in network topology, firewall rule modifications, product upgrades).
Testing Procedure 11.2.1c requires the assessor to validate that the scan was performed by a qualified internal resource(s) or qualified external third party, and if applicable, organizational independence of the tester exists (not required to be a QSA or ASV).
Approved Scanning Vendors (ASVs) are organizations that validate adherence to certain DSS requirements by performing vulnerability scans of Internet facing environments of merchants and service providers. The Council has approved more than 130 ASVs. Complete list of these ASVs can be found here.
I received a request recently to provide some guidance on ASVs that offer their services in the UK. Below are the companies that are listed as ASVs today on PCI SSC website that offer vulnerability scanning service in the UK. To clarify, it is not required for an ASV to be local. There are a number of other ASVs on the website that offer a similar service baselined by PCI SSC.
Again, this listing should only be taken as a reference for organisations seeking to engage an ASV locally. Please feel free to add any ASVs that have been unintentionally missed on this list but offer the service from the UK.
Disclaimer: I do not work for any of the above listed ASVs and do not intend to endorse their ASV services to that of other companies offering such services globally.
Thursday, 9 September 2010
PCI DSS - Ownership and Accountability
Friday, 20 August 2010
Just Check In, we'll sort out the rest!
Often in business, due to competition the end user benefits. With personal data at stake, in this particular case it seems the cost is privacy.
Tuesday, 17 August 2010
Security training - make the message stick!
Friday, 13 August 2010
Blame the game #QSAs
Annual Requalification Fee - $995 USD
This class test is a closed book; the only document you will be allowed to reference during the test is a translation dictionary if needed.
Day 1 Module 1- PCI DSS Program Overview o PCI Security Standards Council o Roles & Responsibilities o Payment Industry Terminology o Payment Transaction Flow o Service Provider Relationships o Payment Brand Compliance Programs o SAQ Overview o PA-DSS Applicability | Module 2- PCI DSS Assessment Scoping o Cardholder Data Discovery o Cardholder Data Flow o Cardholder Data Storage o Network Segmentation o Scoping the Cardholder Data Environment |
Day 2 Module 3- PCI DSS Requirements o PCI DSS v1.2 Overview o PCI DSS v1.2 Requirements o PCI DSS Assessment Preparation o Report of Compliance Documentation o Prioritized Approach for PCI DSS 1.2 | |
Day 3 Module 4 - Compensating Controls o Compensating Controls Definitions o Compensating Controls Worksheet o Compensating Controls Examples Team Case Studies Exam | Module 5 - PCI DSS Compliance Program Development o Ten Common Myths of PCI DSS o PCI Compliance Process o PCI Compliance Recommendations o Information Security Management System Implementation (ISO 27001) |
Tuesday, 10 August 2010
Show me the data
Wednesday, 28 July 2010
Observations from VZDBIR 2010
| VZDBIR Interesting Graphs |
Questions that came to mind following the review
- How can the compliance world take such findings on board and improve the standards?
- How can the regulations/requirements improve to put appropriate weight on critical areas in security instead of an across the board 'old school' playing field?
- Is what is required for compliance enough to protect the business against these threats? (On a second thought, this question isn't worth answering ;))
Certainly, the report shows an ever changing threat landscape. I believe compliance can gain some weight in the security and business world by understanding and incorporating such reports into their standards and requirements.
It is not just in compliance (although it is one of the biggest headaches in the business), but also in Security management that these observations can help teams redesign and re-evaluate their security strategies and invest wisely to address the 'real' threats and improve their ROI.
Thoughts?
Monday, 5 July 2010
Testing and QA Challenges
With the recent failures at Apple and Toyota in this phase of development and/or production, the executives must have surely revisited this and have had discussions on where things can be improved to avoid such mistakes going forward.
- Effective communications between teams
- Plan well and revise those plans as necessary
- Use skilled staff for Testing and QA (don’t get diverted by an incident!)
- Retest after remediation (this is often missed!)