Compliance

Compliance Impact of Virtual Artifacts

View all posts by Chris Secrest

Chris Secrest

November 19, 2012

Virtual artifacts run the gamut from computer generated artwork, photographs of family, and other critical files denoting and cataloging our (virtual) lives. However, they also include forgotten or discarded files that were never deleted (of course the true digital archaeologist knows how to dig even deeper to get files not securely deleted). As such, virtual artifacts provide keen insight into a system and the system’s owner. Including such files that we probably would have preferred never to see the light of day again.
READ POST

Compliance

PA-DSS vendors now have training options

View all posts by Steve Kerns

Steve Kerns

August 9, 2012

The PCI-Council is working with SANS for a set of courses that PA-DSS vendors can use. These courses include fundamental courses for developers and security staff as well as development language specific courses. There are also courses for senior level developers, tester and managers.
READ POST

Compliance

The Choice is No Longer Yours – Changes to PCI

View all posts by Chris Secrest

Chris Secrest

May 4, 2012

For those that aren’t keeping track, June 30, 2012 is a day to mark on your calendar. Not because of any special anniversaries or birthdays (although if yours does fall on that day then Congratulations!). June 30 is the day that we can add one more validation point to our compliance lists from the PCI Data Security Standard.
READ POST

Compliance

Social Media and Healthcare: Bane and Gain

View all posts by Chris Secrest

Chris Secrest

February 17, 2012

Social media has both helped and hurt organizations and healthcare is certainly no exclusion. Many entities are getting on, or have been on for some time, the social media band wagon. This can lead to some fairly significant issues for organizations, especially healthcare. So how does an entity prevent these breaches?
READ POST

Compliance

Care and Feeding of your PCI DSS Compliance Program

View all posts by Tony Fulda

Tony Fulda

February 9, 2012

While getting compliant and passing your yearly Report on Compliance audit or filling out a Self Assessment Questionnaire is important to your organization and your customers (and a requirement for merchants and service providers), the PCI Data Security Standard (DSS) is intended to be the foundation of an ongoing program, ensuring you follow best practices throughout the year.
READ POST