Pci

This Week’s [in]Security – Issue 115 | insecurity | Control Gap
6 min read

This Week’s [in]Security – Issue 115 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: a quiet week for PCI, RDP MFA bypass, make SSNs public, AMCA (Quest, LabCorp, OPKO) breach, Data...

Read More >
NIST is Sunsetting Triple DES - so what will the Financial Industry do?
2 min read

NIST is Sunsetting Triple DES - so what will the Financial Industry do?

NIST recently published a document "Transitioning the Use of Cryptographic Algorithms and Key Lengths" which formalizes the sunset of Triple DES by...

Read More >
NIST Update to Format Preserving Encryption Standard affects PCI Use Cases
4 min read

NIST Update to Format Preserving Encryption Standard affects PCI Use Cases

Last month NIST announced they were seeking feedback on a proposed updated guidance for FPE. More formally this is SP 800-38G rev 1 "Recommendation...

Read More >
PCI SPoC (PIN on COTS) - Grand Experiment in Mobile Payments
7 min read

PCI SPoC (PIN on COTS) - Grand Experiment in Mobile Payments

Big changes are coming to payment security in 2019. PCI is launching a grand experiment in payment security - Software PIN on COTS (SPoC) - a subset...

Read More >
PCI DSS v3.2.1 - What You Need to Know to Stay PCI Compliant
3 min read

PCI DSS v3.2.1 - What You Need to Know to Stay PCI Compliant

To accept credit cards in Canada, businesses need to be PCI compliant. Becoming PCI compliant can be difficult in the first place and keeping up...

Read More >
If You Take Credit Cards By Phone or Mail - You Need to Read About Visa's October Mandate | blog | Control Gap
2 min read

If You Take Credit Cards By Phone or Mail - You Need to Read About Visa's October Mandate | blog | Control Gap

PCI Rules Aren't the Only Ones You Need to Comply With Most organizations concerned with payment compliance are focused on the PCI Data Security...

Read More >
PCI DSS May Require Pulling Up Your SOX (or ISO) | blog,pci | Control Gap
3 min read

PCI DSS May Require Pulling Up Your SOX (or ISO) | blog,pci | Control Gap

Executives and managers in organizations preparing for their first onsite PCI security assessment may feel confident that having passed a SOX audit...

Read More >
17 Predictions About the Next Version of PCI DSS
5 min read

17 Predictions About the Next Version of PCI DSS

PCI DSS v3.2 is due for an update this year - but what will that look like? In this article, we peer into our crystal ball to make some predictions...

Read More >
Understanding
5 min read

Understanding "Connected-to" - Is The Internet In Scope For PCI DSS?

PCI DSS is all about scope. Getting scope right or wrong is perhaps the single most critical factor determining the ultimate success or failure of an...

Read More >