Archive for the 'PCI Compliance' Category



21
Jul
10

Buying Technology Isn’t Compliance

By simply purchasing a “Compliant” piece of technology doesn’t make you compliant.  Some companies even advertise their products as PCI or HIPAA compliant.  This is a dishonest statement as it gives the purchaser a false sense of security.   As with all regulations, the legislation or rules do not dictate specific technologies or practices – rather, it states the desired outcome.

It is true that we need to have key products in place to meet compliance obligations it is actually what we do to those products that make us secure.   For example I could sell you two top of the line WatchGuard firewalls.  As part of the process I explain that they have web blocking and SPAM filtering built right in which meets your needs, great right?  Yes if your IT department configures them correctly. 

And how should they be configured?  They should be based on your company procedures and guidelines.  These procedures need to be laid out clearly and by someone with experience in the industry.  Too often companies write procedures based on the IT departments recommendations and not with the guidance of a security assessor.

Thank you to WatchGuard for reminding us all of this recently in Seattle.

03
Jul
10

Copiers

Think it is safe making copies?  Take a look at this video.  The first thing I though of was those copy businesses.

29
Jun
10

Fraud Stopped

This story from SC Magazine is interesting. What I find most interesting about it is that it appears there are no qualifications or restrictions on someone having the ability to process credit cards. The thieves in this story were able to open up 100 merchant accounts off of the 16 fictitious companies the set up.

http://www.scmagazineus.com/judge-halts-fraud-racket-that-went-undetected-for-years/article/173473/




Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 41 other followers

LinkedIn

Follow me on Twitter

  • Take the time to secure every user. Leave no crack in the foundation. The smallest one will lead to bigger issues. xtmtraining.com 12 hours ago
  • We often see companies wanting to secure a portion of their users while leaving the door open for others. This just doesn't make sense. 12 hours ago

Follow

Get every new post delivered to your Inbox.

Join 41 other followers