<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>NetSPI Blog &#187; PCI</title>
	<atom:link href="http://www.netspi.com/blog/category/pci/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.netspi.com/blog</link>
	<description>Information security consulting</description>
	<pubDate>Mon, 26 Jul 2010 21:26:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Not so Independent Agents?</title>
		<link>http://www.netspi.com/blog/2010/07/26/not-so-independent-agents/</link>
		<comments>http://www.netspi.com/blog/2010/07/26/not-so-independent-agents/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 21:26:00 +0000</pubDate>
		<dc:creator>David Gianna</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[independent agency]]></category>

		<category><![CDATA[payment gateway]]></category>

		<category><![CDATA[SAQ]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=912</guid>
		<description><![CDATA[In the realm of PCI, the network of independent agents might not be so independent after all. When one thinks of agents, one thinks of real estate, insurance and travel. They all provide a service, they all take information, and they all accept payments. Some of these are independent agents who own their own agency [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/07/26/not-so-independent-agents/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Common Compliance Hurdles Part 2: Non-compliant Applications</title>
		<link>http://www.netspi.com/blog/2010/06/23/common-compliance-hurdles-part-2-non-compliant-applications/</link>
		<comments>http://www.netspi.com/blog/2010/06/23/common-compliance-hurdles-part-2-non-compliant-applications/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 19:36:43 +0000</pubDate>
		<dc:creator>Ryan Wakeham</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[pci compliance]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=850</guid>
		<description><![CDATA[In this, the second installment in a series discussing common PCI compliance challenges, I address non-compliant payment applications.  Such applications are nearly ubiquitous in the cardholder data environments of smaller merchants (and even some of the larger ones).  However, merchants that store cardholder data are rarely able to attain a compliant state when using an [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/06/23/common-compliance-hurdles-part-2-non-compliant-applications/feed/</wfw:commentRss>
		</item>
		<item>
		<title>PCI Compliance: Now a Finance Issue as Well</title>
		<link>http://www.netspi.com/blog/2010/05/20/pci-compliance-now-a-finance-issue-as-well/</link>
		<comments>http://www.netspi.com/blog/2010/05/20/pci-compliance-now-a-finance-issue-as-well/#comments</comments>
		<pubDate>Thu, 20 May 2010 15:24:52 +0000</pubDate>
		<dc:creator>Lee Buttke</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=806</guid>
		<description><![CDATA[As an information security professional, my experience within the payment card security industry has taught me that credit card fraud is not just an information security or information technology issue, but increasingly also a financial one.
In order to process payment cards, organizations must execute agreements with financial institutions (&#8221;acquirers&#8221;) that legally obligate them to put [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/05/20/pci-compliance-now-a-finance-issue-as-well/feed/</wfw:commentRss>
		</item>
		<item>
		<title>PCI Assessors Meeting</title>
		<link>http://www.netspi.com/blog/2010/05/14/pci-assessors-meeting/</link>
		<comments>http://www.netspi.com/blog/2010/05/14/pci-assessors-meeting/#comments</comments>
		<pubDate>Fri, 14 May 2010 17:02:25 +0000</pubDate>
		<dc:creator>Lee Buttke</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=802</guid>
		<description><![CDATA[I am currently on my way back from Las Vegas and the PCI (Payment Card Industry) Assessors Meeting.   I guess it is appropriate that the Delta flight that I am on is a cashless flight; you are now able to buy all the $5 Pringles you can eat with a credit card.  But I digress; [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/05/14/pci-assessors-meeting/feed/</wfw:commentRss>
		</item>
		<item>
		<title>What Happens When a Merchant Outsources Their e-Commerce Environment? Part II</title>
		<link>http://www.netspi.com/blog/2010/04/19/what-happens-when-a-merchant-outsources-their-e-commerce-environment-part-ii/</link>
		<comments>http://www.netspi.com/blog/2010/04/19/what-happens-when-a-merchant-outsources-their-e-commerce-environment-part-ii/#comments</comments>
		<pubDate>Mon, 19 Apr 2010 16:01:27 +0000</pubDate>
		<dc:creator>David Gianna</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[e-commerce]]></category>

		<category><![CDATA[pci compliance]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=716</guid>
		<description><![CDATA[Here we continue our discussion of “what happens when a Merchant outsources their e-commerce environment.” In Part I, we touched on the types of e-commerce operators, including those that are purely e-tailers and those that are mixed brick-and-mortar and online retailers. We began a discussion about scoping the e-commerce environment for PCI, what is clearly [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/04/19/what-happens-when-a-merchant-outsources-their-e-commerce-environment-part-ii/feed/</wfw:commentRss>
		</item>
		<item>
		<title>What Happens When a Merchant Outsources Their e-Commerce Environment? Part I</title>
		<link>http://www.netspi.com/blog/2010/04/05/what-happens-when-a-merchant-outsources-their-e-commerce-environment-part-1/</link>
		<comments>http://www.netspi.com/blog/2010/04/05/what-happens-when-a-merchant-outsources-their-e-commerce-environment-part-1/#comments</comments>
		<pubDate>Mon, 05 Apr 2010 20:50:19 +0000</pubDate>
		<dc:creator>David Gianna</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[ecommerce]]></category>

		<category><![CDATA[pci compliance]]></category>

		<category><![CDATA[pci security]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=692</guid>
		<description><![CDATA[Many brick-and-mortar merchants maintain some type of e-commerce environment. For those of you experienced in management of PCI, this has obvious implications: assessment of infrastructure, firewalls, web servers, server administration, access controls, cardholder data encryption, storage, retention and transmission, database administration and management procedures, web application development processes, logging/auditing, file integrity monitoring, and physical security [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/04/05/what-happens-when-a-merchant-outsources-their-e-commerce-environment-part-1/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Common Compliance Hurdles Part 1: Increased PCI Scope</title>
		<link>http://www.netspi.com/blog/2010/03/30/common-compliance-hurdles-part-1-increased-pci-scope/</link>
		<comments>http://www.netspi.com/blog/2010/03/30/common-compliance-hurdles-part-1-increased-pci-scope/#comments</comments>
		<pubDate>Tue, 30 Mar 2010 18:47:40 +0000</pubDate>
		<dc:creator>Ryan Wakeham</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[PCI audit]]></category>

		<category><![CDATA[pci compliance]]></category>

		<category><![CDATA[pci gap analysis]]></category>

		<category><![CDATA[PCI Scope]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=697</guid>
		<description><![CDATA[Looking over the findings of the last few dozen PCI gap assessments that NetSPI has performed, I am struck by the fact that today, well into version 1.2 of the Payment Card Industry Data Security Standard (PCI DSS, or just DSS), one of our most common findings remains increased scope due to lack of network [...]]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2010/03/30/common-compliance-hurdles-part-1-increased-pci-scope/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Brand Reciprocity Revoked by Visa and MasterCard: What It Means for Merchants</title>
		<link>http://www.netspi.com/blog/2009/11/12/brand-reciprocity-revoked-by-visa-and-mastercard-what-it-means-for-merchants/</link>
		<comments>http://www.netspi.com/blog/2009/11/12/brand-reciprocity-revoked-by-visa-and-mastercard-what-it-means-for-merchants/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 15:07:44 +0000</pubDate>
		<dc:creator>Lee Buttke</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[brand reciprocity]]></category>

		<category><![CDATA[MasterCard merchant]]></category>

		<category><![CDATA[PCI ROC]]></category>

		<category><![CDATA[PCI SAQ]]></category>

		<category><![CDATA[Visa merchant]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=473</guid>
		<description><![CDATA[With brand reciprocity revoked, we need to take a look at a merchant's transactions by card brand. By taking a look at these individual card brand transaction volumes, we can assist the merchant in making a determination of its merchant level status and the corresponding type of validation required. ]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2009/11/12/brand-reciprocity-revoked-by-visa-and-mastercard-what-it-means-for-merchants/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Questions on PA-DSS from Software Companies and Straight Answers</title>
		<link>http://www.netspi.com/blog/2009/11/05/questions-on-pa-dss-from-software-companies-and-straight-answers/</link>
		<comments>http://www.netspi.com/blog/2009/11/05/questions-on-pa-dss-from-software-companies-and-straight-answers/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 14:42:54 +0000</pubDate>
		<dc:creator>Alex Crittenden</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[PADSS]]></category>

		<category><![CDATA[PCI SSC]]></category>

		<category><![CDATA[Visa]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=421</guid>
		<description><![CDATA[The process of validating an application under PA-DSS is actually quite involved. It includes documentation review, lab testing, interviewing, process and controls review, documentation, documentation, documentation, and some more documentation.]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2009/11/05/questions-on-pa-dss-from-software-companies-and-straight-answers/feed/</wfw:commentRss>
		</item>
		<item>
		<title>European PCI Community Meeting: Some Impressions</title>
		<link>http://www.netspi.com/blog/2009/11/02/european-pci-community-meeting-some-impressions/</link>
		<comments>http://www.netspi.com/blog/2009/11/02/european-pci-community-meeting-some-impressions/#comments</comments>
		<pubDate>Mon, 02 Nov 2009 22:20:18 +0000</pubDate>
		<dc:creator>Lee Buttke</dc:creator>
		
		<category><![CDATA[PCI]]></category>

		<category><![CDATA[PCI Community Meeting Prague]]></category>

		<category><![CDATA[PCI SSC]]></category>

		<guid isPermaLink="false">http://www.netspi.com/blog/?p=413</guid>
		<description><![CDATA[. . . the feedback from the community on both sides of the Atlantic indicates a need for more clarification and guidance on how organizations that are classified as issuers need to comply, and for more guidance on how to review logs.]]></description>
		<wfw:commentRss>http://www.netspi.com/blog/2009/11/02/european-pci-community-meeting-some-impressions/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
