<?xml version="1.0" encoding="utf-8"?>
			<rss version="2.0">
				<channel>
					<title>SecuriTIM PCI DSS Knowledge Base - All Discussions Feed</title>
					<lastBuildDate>Thu, 09 Sep 2010 08:29:17 +0100</lastBuildDate>
					<link>http://securitim.com/vanilla/</link>
					<description></description>
					<generator>
						Lussumo Vanilla 1.1.5a &amp; Feed Publisher
					</generator>
					<item>
			<title>HPY - The latest breach.... 100 million credit cards stolen</title>
			<link>http://securitim.com/vanilla/comments.php?DiscussionID=7&amp;page=hpy-the-latest-breach-100-million-credit-cards-stolen</link>
			<guid isPermaLink="false">http://securitim.com/vanilla/comments.php?DiscussionID=7&amp;page=hpy-the-latest-breach-100-million-credit-cards-stolen</guid>
			<pubDate>Sat, 24 Jan 2009 14:57:34 +0000</pubDate>
			<author>securitim.com</author>
			<description>
				<![CDATA[ Heartland Payment Systems (HPY) on Tuesday disclosed that intruders hacked into the computers it uses to process 100 million payment card transactions per month for 175,000 merchants:<br /><br />http://www.usatoday.com/money/perfi/credit/2009-01-20-heartland-credit-card-security-breach_N.htm<br /><br />I took a moment to see if they were PCI Compliant and they were audited in March 2008 by Trustwave:<br /><br />http://www.mastercard.com/us/sdp/assets/pdf/Compliant%20Service%20Providers%20-%20January%2015%202009.pdf<br /><br />QSAs cannot be held liable for customer breaches, but seeming the compromise occurred only a few months after their final audit it does bring into question PCI DSS auditing practices and whether or not they're just 'tick in the box' or actually leave companies with a long-lasting compliance strategy that actually helps merchants/service providers remain compliant.<br /><br />I'm hoping this wakes companies up to the risks of dealing with credit cards and it highlights the fact that just because they've ticked all the boxes in an audit doesn't mean they can slack off for the rest of the year, play golf and let hackers help themselves to valuable customer records.<br /><br />Especially in times of recession, criminals will always be one step ahead. Point security solutions don't necessarily help, but ensuring the integrity of core systems and ensuring a full independent audit trail is essential to help combat the ever increasing likelihood of successful intrusion. ]]>
			</description>
		</item>
		<item>
			<title>Does two factor authentication under 8.3 apply to my head office network too?</title>
			<link>http://securitim.com/vanilla/comments.php?DiscussionID=8&amp;page=does-two-factor-authentication-under-83-apply-to-my-head-office-network-too</link>
			<guid isPermaLink="false">http://securitim.com/vanilla/comments.php?DiscussionID=8&amp;page=does-two-factor-authentication-under-83-apply-to-my-head-office-network-too</guid>
			<pubDate>Sun, 22 Feb 2009 12:34:40 +0000</pubDate>
			<author>FAQ</author>
			<description>
				<![CDATA[ I've setup 2 factor authentication for remote/VPN users that need to access our payment network, but what about users on the inside and head office - do they need 2 factor authentication too? ]]>
			</description>
		</item>
		<item>
			<title>What's the difference between application (6.6) and penetration (11.3) testing?</title>
			<link>http://securitim.com/vanilla/comments.php?DiscussionID=9&amp;page=whats-the-difference-between-application-66-and-penetration-113-testing</link>
			<guid isPermaLink="false">http://securitim.com/vanilla/comments.php?DiscussionID=9&amp;page=whats-the-difference-between-application-66-and-penetration-113-testing</guid>
			<pubDate>Sun, 22 Feb 2009 12:36:43 +0000</pubDate>
			<author>FAQ</author>
			<description>
				<![CDATA[ At the moment, we have two separate projects.  One is to address application testing under 6.6, for which we are in discussions with a 3rd party and the second is for annual penetration testing for 11.3.  For both we are relying on an experienced 3rd party to deliver, but don't the controls mean the same? ]]>
			</description>
		</item>
		
				</channel>
			</rss>