• NetSPI Home
  • Our Vision
  • Expert Services
  • Industry Solutions
NetSPI Blog - Risk, Compliance, Sceurity
  • authors
  • archive
  • contact us

Entries by David Gianna

Compliance

Risk-based or Compliance-based? How to Address PCI

David Gianna

October 8th, 2010

The move to a risk-based approach to PCI-DSS rather than a compliance-based approach would enable the transformation of PCI-DSS from a compliance standard to a security standard.
READ POST

NetsPWN: Assessment Services

Multi-Layer Security Revisited

David Gianna

August 23rd, 2010

Many years ago, I consulted with a non-profit agency that needed firewall remediation. They had just purchased an upgrade to the vendor's latest and greatest firewall, and needed to build a policy that met their needs.
READ POST

Security Industry

Pressure Engineering

David Gianna

August 16th, 2010

We think of the call to the help desk in the middle of the night to unlock the executive account, and the psychological pressure exerted by the attacker implying retribution if the task is not carried out immediately.
READ POST

Security Industry

Information, Data, and Holistic Protection

David Gianna

August 2nd, 2010

A dichotomy exists between information and data – and the way that information and data are discussed, stored, protected, and used. Any number of people reading this might identify themselves as working with “Information Systems” in the field of “Information …
READ POST

Compliance

Not so Independent Agents?

David Gianna

July 26th, 2010

In the realm of PCI, the network of independent agents might not be so independent after all.
READ POST

Compliance

What Happens When a Merchant Outsources Their e-Commerce Environment? Part II

David Gianna

April 19th, 2010

Here we continue our discussion of “what happens when a Merchant outsources their e-commerce environment.” In Part I, we touched on the types of e-commerce operators, including those that are purely e-tailers and those that are mixed brick-and-mortar and online …
READ POST

Compliance

What Happens When a Merchant Outsources Their e-Commerce Environment? Part I

David Gianna

April 5th, 2010

Many brick-and-mortar merchants maintain some type of e-commerce environment. For those of you experienced in management of PCI, this has obvious implications: assessment of infrastructure, firewalls, web servers, server administration, access controls, cardholder data encryption, storage, retention and transmission, database …
READ POST

search

Follow Us

Follow us on Linkedin Follow us on Twitter Follow us on Our Blog

Categories

  • Compliance
  • NetsPWN: Assessment Services
  • Sage Advice
  • Security Industry

Resources

pci-audit-mistakes-white-paper

Tags

PCI/PA-DSS Compliance | penetration testing | Database Hacking | healthcare | pci compliance | hacking | NetsPWN: Assessment Services | HIPAA | PCI-DSS | PA-DSS | vulnerability assessment | HITRUST | Application Security Risks | Mobile Device Security | Database Security | HITECH | PCI SSC | CSF | Information Security | code reviews

Solutions

Services

About NetSPI

Contact Us

  • CorrelatedVM™
  • DEA EPCS
  • Financial
  • Healthcare
  • Mobile
  • Retail
  • Technology
  • Strategic Security Services
  • Vulnerability Management
  • Risk Analysis
  • PCI DSS / PA-DSS
  • IT Audit
  • Healthcare / DEA EPCS
  • Application Security
  • Network/Infrastructure Security
  • Penetration Testing
  • Why NetSPI
  • Management
  • Our Approach
  • Certifications
  • Partners
  • Careers

800 Washington Ave. N.
Suite 670
Minneapolis, MN 55401

612.465.8880 Phone
612.455.6988 Fax

info@netspi.com

Copyright ©2012 NetSPI Inc. All rights reserved