PCI PCIDSS4.0 PCIDSS PCI DSS v4.0
There are two notable changes that may require a fair bit of runway to fully meet the existing requirement to monitor your critical security control systems.
Continue ReadingPCI PCIDSS4.0 PCIDSS PCI DSS v4.0
There are two notable changes that may require a fair bit of runway to fully meet the existing requirement to monitor your critical security control systems.
Continue ReadingWhat could possibly go wrong with calling out a non-compliant status, or “In Place with Remediation,” on your Attestation of Compliance? Do you have a storm brewing you are yet aware of?
Continue ReadingPCI PCIDSS4.0 PCIDSS PCI DSS v4.0
Are you a SaaS? Do you offer various shared services to merchants and other service providers with access to resources or services being logically controlled or partitioned to keep...
Continue ReadingPCI PCIDSS4.0 PCIDSS PCI DSS v4.0
Mistakes with PAN happen! Data leaks, memory dumps, or debug logs can accidentally contain sensitive information and can leak data into unexpected places in your environment. It is now a...
Continue ReadingPCI PCIDSS4.0 PCIDSS PCI DSS v4.0
There are now two options to meeting the new requirement 6.4.2 for a web application firewall: WAF or RASP. Notice I didn’t say manual code review!
Continue ReadingIf you don’t have documented and employee acknowledged roles and responsibilities for every role that is part of your PCI scope of assessment, you may need a long roadway to get this in...
Continue ReadingRemember the good ole days when Requirement 7 was all about general and privileged user accounts? Well, those days are done as of March 31, 2025!
Continue ReadingHave you ever been off-roading? Full-on four-wheel-drive, low gear, creeping over rocks, or blasting through snowbanks? It’s quite an exhilarating experience. I liken the updates made to...
Continue ReadingThe recent release of PCI DSS v4.0 may give the mistaken impression that there is a lot of time for organizations to prepare for any required changes to people, processes, and technologies....
Continue ReadingI’ve recently spent some time reviewing the PCI DSS v4.0’s updates on the Customized Approach and want to go on record as stating that I believe this is one of the most significant changes...
Continue Reading
Submit a Comment