Email Alerts
-
PCI compliance and Web applications: Code review or firewalls?
The Payment Card Industry Data Security Standard is about to get a new wrinkle involving Web applications. As of June 30, 2008, to achieve PCI compliance, enterprises must either have their custom Web application code reviewed or install Web applicat... Tip
-
Worst practices: Recognizing the biggest compliance mistakes
With all of the compliance requirements and regulations organizations need to abide by these days, corporate compliance blunders are inevitable. In this tip, security management expert Mike Rothman highlights the biggest compliance mistakes seen in t... Tip
-
How to apply ISO 27002 to PCI DSS compliance
The Payment Card Industry Data Security Standard may be fairly straightforward, but it's lacking in defining the processes that will ultimately lead to PCI DSS compliance. In this tip, expert Richard Mackey explains why the ISO 27002 can not only hel... Tip
-
PCI standard, take two
Complying with Payment Card Industry Data Security Standard and its ambiguous requirements and deadlines can be daunting. Fortunately, in an effort to maximize compliance efforts, the industry released a new version of the PCI standard. In this tip, ... Tip
-
A new twist on PCI DSS: Visa's Payment Application Best Practices
The Payment Card Industry (PCI) Security Standards Council is poised to issue another mandate, this time adding Visa's Payment Application Best Practices (PABP) into the compliance mix. New contributor Stephen Cobb examines Visa's controls and how bu... Tip
-
Security management in 2008: What's in store
Looking back on 2007, compliance and PCI DSS preoccupied the minds of most security management professionals. In this tip, security expert Mike Rothman outlines what information security managers can expect to be the hot management topics for the yea... Tip
-
Compliance year in review: PCI DSS progress, yet confusion abounds
For compliance specialists, 2007 has brought massive data security breaches and PCI DSS headaches. What can corporations learn from the past 12 months? In this tip, security management expert Mike Rothman looks back at of the key compliance events of... Tip
-
PCI DSS Section 6: A plan for tackling application security
Section 6 of the PCI DSS is currently a recommended "best practice," but in June 2008, corporations will be required to comply with the sections terms, which may leave some scrambling. In this tip, security expert Joel Dubin explains why its requirem... Tip
-
Applying PCI DSS to Web application security
With millions of online credit card transactions taking place each day, Web application security is a critical issue for any enterprise. In this tip, contributor Diana Kelley reviews the key PCI DSS sub-requirements for Web applications, and explains... Tip
-
PCI DSS emergency: What to do if you're (very) late to the game
The PCI DSS compliance deadline has already passed for top-tier merchants, and an even larger group of enterprises will face their deadline at the end of 2007. Still, there may be organizations that haven't put much effort into complying with PCI DSS... Tip
Security Management Strategies for the CIO