Sage Advice

Code Review – is automated testing enough?

View all posts by Steve Kerns

Steve Kerns

February 26, 2013

    We have worked with many companies that are following the letter of the law. The law being the PCI Council’s requirement (6.3.2) that all code must be reviewed prior to release. It states: 6.3.2 Review of custom code …
READ POST

Compliance

Common Compliance Hurdles Part 2: Non-compliant Applications

View all posts by Ryan Wakeham

Ryan Wakeham

June 23, 2010

In this, the second installment in a series discussing common PCI compliance challenges, I address non-compliant payment applications.  Such applications are nearly ubiquitous in the cardholder data environments of smaller merchants (and even some of the larger ones).  However, merchants …
READ POST

Security Industry

Risk, Security and Subjectivity Within PCI

View all posts by Deke George

Deke George

April 2, 2010

In late March Thales released an interesting report on the state of PCI – “PCI DSS Trends 2010: QSA Insights Report.”  The report was written by the Ponemon Institute and it highlights the difficulty of taking into account risk, security …
READ POST

Compliance

Security, Compliance, and the New Retail Economy

View all posts by Alex Crittenden

Alex Crittenden

September 21, 2009

. . .leading retailers began to use the requirements of PCI (for example) to re-invigorate broader security initiatives and to use any technical or policy adjustments as opportunities to simplify their security scope and implement better overall security policy.
READ POST