<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Retail Information Security</title>
	
	<link>http://www.retailinfosec.com</link>
	<description>Retail &amp; Hospitality Information Security (including PCI)</description>
	<pubDate>Tue, 27 Jul 2010 17:00:58 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/retailinfosec/aloi" /><feedburner:info uri="retailinfosec/aloi" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Visa Releases New Guidelines For Protecting Card Data</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/MG1xszZ_pQ4/</link>
		<comments>http://www.retailinfosec.com/2010/07/27/visa-releases-new-guidelines-for-protecting-card-data/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 17:00:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[announcements]]></category>

		<category><![CDATA[guidelines]]></category>

		<category><![CDATA[standards]]></category>

		<category><![CDATA[tokenization]]></category>

		<category><![CDATA[VISA]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/2010/07/27/visa-releases-new-guidelines-for-protecting-card-data/</guid>
		<description><![CDATA[For those of you paying attention - I&#8217;m sure that you&#8217;ve already seen this announcement and probably taken a cursory look through the documentation.
I&#8217;ve been a bit out-of-pocket recently (a combination of famility vacation &#38; working on projects with some of our large retail and retail technology clients), but wanted to make sure that I made note of this information from VISA in case you hadn&#8217;t seen it.
Sorry - that&#8217;s it, but as we get through the next crazy week (it&#8217;s Black Hat after all&#8230;) I&#8217;ll try to be more ...]]></description>
			<content:encoded><![CDATA[<p>For those of you paying attention - I&#8217;m sure that you&#8217;ve already seen this announcement and probably taken a cursory look through the documentation.</p>
<p>I&#8217;ve been a bit out-of-pocket recently (a combination of famility vacation &amp; working on projects with some of our large retail and retail technology clients), but wanted to make sure that I made note of this information from VISA in case you hadn&#8217;t seen it.</p>
<p>Sorry - that&#8217;s it, but as we get through the next crazy week (it&#8217;s Black Hat after all&#8230;) I&#8217;ll try to be more active on the blog - I&#8217;ve got a few thoughts on the recent payment terminal announcements from VISA as you might imagine.  Thanks!</p>
<p><a href="http://www.networkcomputing.com/wan-security/visa-releases-new-guidelines-for-protecting-card-data.php" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.networkcomputing.com');">Visa Releases New Guidelines For Protecting Card Data - Network Computing</a>.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://pindebit.blogspot.com/2010/07/visa-inc-completes-acquisition-of.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/pindebit.blogspot.com');">Visa Inc. Completes Acquisition of CyberSource</a> (pindebit.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="https://www.brandenwilliams.com/blog/2010/07/15/tokenization-and-chargebacks/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.brandenwilliams.com');">Tokenization and Chargebacks</a> (brandenwilliams.com)</li>
<li class="zemanta-article-ul-li"><a href="http://go.theregister.com/feed/www.theregister.co.uk/2010/07/08/visa_pci_approval_pin_pads/" onclick="javascript:pageTracker._trackPageview('/outbound/article/go.theregister.com');">Visa yanks PCI approval from PIN entry kit</a> (go.theregister.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=c8277b4e-f5d6-47aa-a303-21ebce9d1378" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/MG1xszZ_pQ4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/07/27/visa-releases-new-guidelines-for-protecting-card-data/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/07/27/visa-releases-new-guidelines-for-protecting-card-data/</feedburner:origLink></item>
		<item>
		<title>Firewall Security - a short article and comment</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/N8g8628k7Tc/</link>
		<comments>http://www.retailinfosec.com/2010/06/15/firewall-security-a-short-article-and-comment/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 19:08:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[featured]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=422</guid>
		<description><![CDATA[This morning I read the short article that I link to below.  It&#8217;s focused on firewall management and review which is a topic that I think many retail and hospitality organizations should be paying more attention to.
The study in the article was sponsored by a vendor that provides firewall management solutions (go figure), but it doesn&#8217;t mean that the message isn&#8217;t an important one - firewalls are easy to forget about once you
have them in place and (particularly in retail and hospitality) there are so many things that your network ...]]></description>
			<content:encoded><![CDATA[<p>This morning I read the short article that I link to below.  It&#8217;s focused on firewall management and review which is a topic that I think many retail and hospitality organizations should be paying more attention to.</p>
<p>The study in the article was sponsored by a vendor that provides firewall management solutions (go figure), but it doesn&#8217;t mean that the message isn&#8217;t an important one - firewalls are easy to forget about once you</p>
<div id="attachment_426" class="wp-caption alignright" style="width: 310px"><a href="http://www.retailinfosec.com/wp-content/uploads/2010/06/private-property-mollybob.jpg" ><img class="size-medium wp-image-426 " title="private-property-mollybob" src="http://www.retailinfosec.com/wp-content/uploads/2010/06/private-property-mollybob-300x225.jpg" alt="Private Property - via Flickr - mollybob" width="300" height="225" /></a><p class="wp-caption-text">Private Property - via Flickr - mollybob</p></div>
<p>have them in place and (particularly in retail and hospitality) there are so many things that your network and security people have on their to-do list that seem more pressing today then reviewing your firewall rules&#8230;</p>
<p>Now, I&#8217;m not supporting the vendor that sponsored this study and wouldn&#8217;t have the slightest feedback on its products effectiveness, but I am supporting the concept of reviewing and maintaining your firewall configuration.  The company that I work for does a lot of firewall rule assessment and while we are often engaged in this capacity as part of a client&#8217;s normal security operations, that isn&#8217;t always the case.  Sometimes it&#8217;s because management hasn&#8217;t appreciated the need to properly maintain firewall rules and now legitimate network traffic is being affected.</p>
<p>OK - back to the article - what&#8217;s also interesting is the implication that a company that is not taking the proper steps to review their firewall rules periodically will run into legal liability issues if they are breached.  They hit this point fairly hard, but don&#8217;t really provide much in the way of support for their argument.  However, it&#8217;s probably fairly valid - if an organization doesn&#8217;t manage their firewalls effectively (and isn&#8217;t able to demonstrate that they are doing so) it certainly could be something that a lawyer might latch onto &#8230;</p>
<p><a href="http://www.ctoedge.com/content/perils-firewall-security" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.ctoedge.com');">The Perils of Firewall Security | CTO Edge</a>.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.computing.co.uk/computing/news/2264409/professionals-cheat-audits" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.computing.co.uk');">One in 10 IT professionals cheat in audits</a> (computing.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-1001_3-20003521-92.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20" onclick="javascript:pageTracker._trackPageview('/outbound/article/news.cnet.com');">McAfee updates firewall hardware for enterprises</a> (news.cnet.com)</li>
</ul>
<p><a id="aptureLink_58WqfLql2z" style="margin: 0pt auto; text-align: center; display: block; padding: 0px 6px;" href="http://en.wikipedia.org/wiki/Firewall%20%28computing%29" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');"><img style="border: 0px none;" title="Firewall (computing)" src="http://placeholder.apture.com/ph/360x320_WikipediaArticle/" alt="" width="360px" height="320px" /></a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=609e036d-22d5-4291-ae64-1bbdcac3d312" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/N8g8628k7Tc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/06/15/firewall-security-a-short-article-and-comment/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/06/15/firewall-security-a-short-article-and-comment/</feedburner:origLink></item>
		<item>
		<title>Short Post On A Lesson Learned - Hackers Break Into Reddit’s Gmail and Twitter Accounts</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/mIxdi2KOe_g/</link>
		<comments>http://www.retailinfosec.com/2010/06/11/short-post-on-a-lesson-learned-hackers-break-into-reddit%e2%80%99s-gmail-and-twitter-accounts/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 14:56:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[gmail]]></category>

		<category><![CDATA[reddit]]></category>

		<category><![CDATA[social media]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=418</guid>
		<description><![CDATA[Why am I posting this on a retail infosec blog?  Because of the last two paragraphs:
&#8230; Why does Reddit use a Gmail account for this purpose, anyway? One of  the site’s moderators answers: “When we were much, much smaller (no mail  server, etc) it was the easiest way for several people to get to the  feedback account at the same time, and it stuck.”
So there you  have it: as the company grows, it should continually update its security  practices, otherwise it might find that certain ...]]></description>
			<content:encoded><![CDATA[<p>Why am I posting this on a retail infosec blog?  Because of the last two paragraphs:</p>
<blockquote><p>&#8230; Why does Reddit use a Gmail account for this purpose, anyway? One of  the site’s moderators answers: “When we were much, much smaller (no mail  server, etc) it was the easiest way for several people to get to the  feedback account at the same time, and it stuck.”</p>
<p>So there you  have it: as the company grows, it should continually update its security  practices, otherwise it might find that certain solutions, that were  good enough a couple of years ago, simply don’t cut it anymore.</p></blockquote>
<p>This is a common situation with many organizations (including many retailers) - not keeping security up-to-snuff as the organization and it&#8217;s systems, personnel, and needs grow and change.</p>
<p>While a social media site like Reddit may not be subject to security and compliance oversight like a retailer would be it reinforces something that I&#8217;m constantly discussing with clients - security (and compliance) is a process and, while point-in-time validations are necessary, they are just that - a point in time.</p>
<p>Make sure that you&#8217;re keeping security needs in mind as your organization and it&#8217;s environment changes&#8230;.</p>
<p><a href="http://mashable.com/2010/06/11/hackers-reddit-gmail/" onclick="javascript:pageTracker._trackPageview('/outbound/article/mashable.com');">Hackers Break Into Reddit’s Gmail and Twitter Accounts</a>.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://mashable.com/2010/06/11/hackers-reddit-gmail/" onclick="javascript:pageTracker._trackPageview('/outbound/article/mashable.com');">Hackers Break Into Reddit&#8217;s Gmail and Twitter Accounts</a> (mashable.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=c09e3331-7654-406a-8f6b-b26af0d0bf5d" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/mIxdi2KOe_g" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/06/11/short-post-on-a-lesson-learned-hackers-break-into-reddit%e2%80%99s-gmail-and-twitter-accounts/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/06/11/short-post-on-a-lesson-learned-hackers-break-into-reddit%e2%80%99s-gmail-and-twitter-accounts/</feedburner:origLink></item>
		<item>
		<title>FTC Settlement Order with Dave &amp; Busters</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/xdBGdK8W4nM/</link>
		<comments>http://www.retailinfosec.com/2010/06/09/ftc-settlement-order-with-dave-busters/#comments</comments>
		<pubDate>Wed, 09 Jun 2010 18:33:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[Retailers]]></category>

		<category><![CDATA[featured]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=412</guid>
		<description><![CDATA[Again via Office of Inadequate Security&#8230; their link is below.
So Dave &#38; Busters&#8217; FTC settlement is finalized and it illustrates another concern for merchants that aren&#8217;t taking a comprehensive approach to security - the burden of being monitored by the FTC.  Here&#8217;s the quote from the press release:
The settlement requires Dave &#38; Buster’s to establish and maintain a  program designed to protect the security, confidentiality, and integrity  of personal information collected from customers.  It also requires the  company to obtain independent, professional audits, every other year ...]]></description>
			<content:encoded><![CDATA[<p>Again via Office of Inadequate Security&#8230; their link is below.</p>
<p>So Dave &amp; Busters&#8217; <a class="zem_slink freebase/en/federal_trade_commission" title="Federal Trade Commission" rel="homepage" href="http://www.ftc.gov" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.ftc.gov');">FTC</a> <a class="zem_slink freebase/en/settlement_hierarchy" title="Human settlement" rel="wikipedia" href="http://en.wikipedia.org/wiki/Human_settlement" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">settlement</a> is finalized and it illustrates another concern for merchants that aren&#8217;t taking a comprehensive approach to security - the burden of being monitored by the FTC.  Here&#8217;s the quote from the press release:</p>
<blockquote><p>The settlement requires <a class="zem_slink freebase/en/dave_busters" title="Dave &amp; Buster's" rel="homepage" href="http://www.daveandbusters.com" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.daveandbusters.com');">Dave &amp; Buster’s</a> to establish and maintain a  program designed to protect the security, confidentiality, and integrity  of personal information collected from customers.  It also requires the  company to obtain independent, professional audits, every other year  for 10 years, to ensure that the security program meets the standards of  the settlement.  In addition, the proposed settlement contains standard  record-keeping provisions to allow the FTC to monitor compliance.</p></blockquote>
<p>This is a huge deal - having an &#8216;independent, professional audit&#8217; of your security program every other year is not covered by your PCI Report on Compliance.  It is an additional audit requirement that goes well beyond PCI&#8217;s card-specific requirements and requires a far more in-depth review of your full security program.  It also requires putting in place the &#8217;standard record-keeping provisions to allow the FTC to monitor compliance.&#8217;  In other words - it&#8217;s not getting ready every year for your QSA, it&#8217;s maintaining the appropriate information and providing access to that information 365 days a year.  Dave &amp; Buster&#8217;s is going</p>
<p>to be requ</p>
<p>ired to document every aspect of their entire security program and be able to demonstrate it&#8217;s effectiveness to auditors and the FTC.</p>
<p>Add this to your list of stuff to worry about and make sure that, if your executive man</p>
<p>agement team isn&#8217;t putting the proper focus on security and compliance, that they understand that this additional concern is real - it&#8217;s not just about PCI.  And if they think maintaining PCI compliance is expensive&#8230;..</p>
<p><a href="http://www.databreaches.net/?p=12090" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.databreaches.net');">FTC Approves Final Settlement Order with Dave &amp; Busters | Office of Inadequate Security</a>.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.ftc.gov/opa/2010/03/davebusters.shtm" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.ftc.gov');">Dave &amp; Buster&#8217;s Settles FTC Charges it Failed to Protect Consumers&#8217; Information</a> (ftc.gov)</li>
<li class="zemanta-article-ul-li"><a href="http://blog.deurainfosec.com/man-sentenced-for-hacking-restaurant-card-data" onclick="javascript:pageTracker._trackPageview('/outbound/article/blog.deurainfosec.com');">Man sentenced for hacking restaurant card data</a> (deurainfosec.com)</li>
<li class="zemanta-article-ul-li"><a href="http://go.theregister.com/feed/www.theregister.co.uk/2010/03/25/gonzalez_sentenced/" onclick="javascript:pageTracker._trackPageview('/outbound/article/go.theregister.com');">Hacker&#8217;s record credit card theft fetches 20-year sentence</a> (go.theregister.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/eb41ea85-6a34-45c0-b24e-768d4570a02c/" onclick="javascript:pageTracker._trackPageview('/outbound/article/reblog.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=eb41ea85-6a34-45c0-b24e-768d4570a02c" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/xdBGdK8W4nM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/06/09/ftc-settlement-order-with-dave-busters/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/06/09/ftc-settlement-order-with-dave-busters/</feedburner:origLink></item>
		<item>
		<title>Additional Information About That Potential Lawsuit</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/12rUPlK8KzU/</link>
		<comments>http://www.retailinfosec.com/2010/06/02/additional-information-about-that-potential-lawsuit/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 17:28:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[Retailers]]></category>

		<category><![CDATA[Vendors]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[Brew HaHa!]]></category>

		<category><![CDATA[CC Productions]]></category>

		<category><![CDATA[lawsuit]]></category>

		<category><![CDATA[Mercury]]></category>

		<category><![CDATA[Mercury Payments]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<category><![CDATA[Point of sale]]></category>

		<category><![CDATA[POSitouch]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=403</guid>
		<description><![CDATA[After posting about the press release regarding the potential lawsuit (here) I got an email from the PR firm that had sent the release out.  He, in turn, connected me to Charles Hoff - the attorney for the retailer that is considering the suit, Brew HaHa!.  We had a very interesting conversation and, not being a lawyer, I&#8217;m not going to make any comments about the merits of any lawsuit that may or may not come from this episode, but, as I said, the conversation was interesting and this is ...]]></description>
			<content:encoded><![CDATA[<p>After posting about the press release regarding the potential lawsuit (<a href="http://www.retailinfosec.com/2010/05/27/lawsuit-brewing-against-popular-pos-software-provider-and-reseller/"  target="_blank">here</a>) I got an email from the PR firm that had sent the release out.  He, in turn, connected me to Charles Hoff - the attorney for the retailer that is considering the suit, Brew HaHa!.  We had a very interesting conversation and, not being a lawyer, I&#8217;m not going to make any comments about the merits of any lawsuit that may or may not come from this episode, but, as I said, the conversation was interesting and this is what I can share from that discussion:</p>
<p>I&#8217;m not a lawyer, so let&#8217;s put this caveat onto everything below -  This is all from one-side of the discussion and it&#8217;s all alleged and I don&#8217;t support one side or the other in this situation.</p>
<ul>
<li>Brew HaHa! purchased a &#8216;turn-key&#8217; solution from what they understood to be a &#8216;exclusive&#8217; reseller of the POSitouch POS solution - <a href="http://www.c-c-p.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.c-c-p.com');">CC Productions</a></li>
<li>It was explained to them that they could utilize a payments solution from <a href="http://www.mercurypay.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.mercurypay.com');" target="_blank">Mercury Payments </a>- any alternative to Mercury would cost Brew HaHa! additional money</li>
<li>Charles claims that Brew HaHa! was not informed that the Mercury solution that was being implemented was not PCI / <a class="zem_slink freebase/guid/9202a8c04000641f800000000bebb66e" title="PA-DSS" rel="wikipedia" href="http://en.wikipedia.org/wiki/PA-DSS" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">PA-DSS</a> compliant and that, after the system was implemented, Brew HaHa! noticed that they were being charged a fee to allow Mercury to make the changes needed for their solution to be PCI compliant.  According to Charles, that&#8217;s the first time they realized that the solution wasn&#8217;t compliant.</li>
<li>They have had a forensics team in and they determined that malware was present on the environment and that the malware was aggregating cardholder data (among other things)</li>
<li>There is another, larger merchant that has yet to come forward that may have a similar situation and complaint&#8230;</li>
</ul>
<p>Not a lot really (I&#8217;m not a great interviewer - not enough practice), but it did answer some of my questions and raise some more.</p>
<p>Also, Restaurant Data Concepts sent a press release as well - <a href="http://www.databreaches.net/?p=11943" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.databreaches.net');" target="_blank">link</a> (the link heads over to the Office Of Inadequate Security site - which is an excellent site btw).  Take a look at the release as it also makes some very interesting points.  Although, I will say that the statement, &#8216;It is not overly difficult or expensive for a merchant to protect themselves against theft of cardholder information&#8217; is a little unfair - it can get very expensive and quite technically involved for many merchants.  The other line I thought was interesting - &#8216;A small expenditure to upgrade and secure their system can stave off significant costs and penalties&#8230;&#8217;</p>
<p>Ultimately it breaks down like this for me:</p>
<ol>
<li>There&#8217;s an involved chain of companies/products/services involved here: Restaurant Data Concepts (software) &#8212;&gt; CC Productions (hardware/installation/implementation/Mercury resellers maybe as well?) &#8212;&gt; Mercury Payments (software?/processing) &#8212;&gt;Brew HaHa!(which is responsible for their broader PCI requirements).    Lot&#8217;s of places for someone to not do their job with PCI/security.  Lots of places to miss something or to not even realize that something wasn&#8217;t getting done by someone else in the chain.</li>
<li>There is a responsibility that lies with a software vendor (as documented in PA-DSS), but does that responsibility extend to resellers?  &#8216;Exclusive&#8217; resellers?</li>
<li>When a small merchant without a big IT staff purchases a &#8216;turn-key&#8217; solution, what does that mean for PCI?</li>
<li>If a reseller or a technology vendor doesn&#8217;t volunteer the fact that they aren&#8217;t PCI compliant (or PA-DSS validated) does that mean anything?  Yes, the retailer should have asked (and really contractually obligated) the vendor regarding compliance, but is the provider responsible for disclosing?  (Either way, it&#8217;s a pretty crappy move if it really went down that way).</li>
</ol>
<p>Regardless - it should continue to be interesting.</p>
<p>Some Additional Info:</p>
<p><a href="http://www.retailinfosec.com/2010/05/27/lawsuit-brewing-against-popular-pos-software-provider-and-reseller/"  target="_blank">Lawsuit Brewing&#8230;</a></p>
<p><a href="http://www.databreaches.net/?p=11932" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.databreaches.net');" target="_blank">Brew HaHa breach no laughing matter</a></p>
<p><a id="aptureLink_w4xxeAWaZ3" style="margin: 0pt auto; text-align: center; display: block; padding: 0px 6px;" href="http://en.wikipedia.org/wiki/Payment%20Card%20Industry%20Data%20Security%20Standard" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');"><img style="border: 0px none;" title="Payment Card Industry Data Security Standard" src="http://placeholder.apture.com/ph/360x320_WikipediaArticle/" alt="" width="360px" height="320px" /></a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/2c2aa33c-8ca7-44e4-9cf1-e2aa997b8104/" onclick="javascript:pageTracker._trackPageview('/outbound/article/reblog.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=2c2aa33c-8ca7-44e4-9cf1-e2aa997b8104" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/12rUPlK8KzU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/06/02/additional-information-about-that-potential-lawsuit/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/06/02/additional-information-about-that-potential-lawsuit/</feedburner:origLink></item>
		<item>
		<title>Lawsuit Brewing Against Popular POS Software Provider and Reseller</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/C4eFzxoDP5g/</link>
		<comments>http://www.retailinfosec.com/2010/05/27/lawsuit-brewing-against-popular-pos-software-provider-and-reseller/#comments</comments>
		<pubDate>Thu, 27 May 2010 17:16:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[application security]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[lawsuit]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[PABP]]></category>

		<category><![CDATA[PADSS]]></category>

		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>

		<category><![CDATA[Point of sale]]></category>

		<category><![CDATA[Point of Sale Systems]]></category>

		<category><![CDATA[POSitouch]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=399</guid>
		<description><![CDATA[Hey look - another lawsuit&#8230;.
Well - right now it&#8217;s just the threat of a suit&#8230;  The information is a bit thin and I&#8217;m not sure (based on the press release) whether or not this is a complaint about the software, the implementation of the software, the hardware system, or all of the above.
What it does look like is a bit of a fishing exercise by the law firms - let&#8217;s send out the press release, make it general enough that we include just about anyone that even thought about touching the ...]]></description>
			<content:encoded><![CDATA[<p>Hey look - another <a class="zem_slink freebase/en/lawsuit" title="Lawsuit" rel="wikipedia" href="http://en.wikipedia.org/wiki/Lawsuit" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">lawsuit</a>&#8230;.</p>
<p>Well - right now it&#8217;s just the threat of a suit&#8230;  The information is a bit thin and I&#8217;m not sure (based on the <a class="zem_slink freebase/en/news_release" title="Press release" rel="wikipedia" href="http://en.wikipedia.org/wiki/Press_release" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">press release</a>) whether or not this is a complaint about the software, the implementation of the software, the hardware system, or all of the above.</p>
<p>What it does look like is a bit of a fishing exercise by the law firms - let&#8217;s send out the press release, make it general enough that we include just about anyone that even thought about touching the system and see if the vendors jump for that settlement opening (&#8217;there is hope that RDC and CC Productions will decide to resolve the  situation before it goes to court.&#8217;).</p>
<p>This could be very interesting if it is more than just a &#8217;shake-down&#8217; - we don&#8217;t know the software releases/revs, we don&#8217;t know when systems were installed, we don&#8217;t know how the alleged breaches actually occurred, we don&#8217;t know much of anything except that the lawyers are crying &#8216;PCI&#8217; and waiting to see what happens&#8230;</p>
<p>It might be a completely legitimate complaint by merchants that implemented a solution that was over-sold to them as a fix to their &#8216;PCI problem&#8217;.  It might be that the merchants installed a solution that was secure in itself, but didn&#8217;t take any steps to secure their own environment beyond the <a class="zem_slink freebase/en/point_of_sale" title="Point of sale" rel="wikipedia" href="http://en.wikipedia.org/wiki/Point_of_sale" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">POS</a>.  It might be that the implementer took a secure solution and made it insecure through improper implementation (following that <a class="zem_slink freebase/guid/9202a8c04000641f800000000bebb66e" title="PA-DSS" rel="wikipedia" href="http://en.wikipedia.org/wiki/PA-DSS" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">PA-DSS</a> Program Guide?  huh?).  It might be software issues.  It might be who knows what&#8230;..</p>
<p>I want more information and I want to know if they are going through with this or if they are just using this as leverage.</p>
<p>Looking at the PA-DSS validated list, two of the POSitouch solutions are listed - both under <a class="zem_slink freebase/en/pci_dss" title="Payment Card Industry Data Security Standard" rel="wikipedia" href="http://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">PABP</a> 1.4 - don&#8217;t know if these were the solutions/revs that the merchants had installed, but, if they were it would be an interesting exercise to see how much protection the <a id="aptureLink_hZhKtAzh2t" href="https://www.pcisecuritystandards.org/security_standards/vpa/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.pcisecuritystandards.org');">PA-DSS validated list</a> would provide a POS vendor&#8230;</p>
<p><a href="http://www.prlog.org/10700613-lawsuit-brewing-against-popular-pos-software-provider-and-reseller.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.prlog.org');">Lawsuit Brewing Against Popular POS Software Provider and Reseller</a>.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/9577292b-5635-41cf-8b13-155409cffb66/" onclick="javascript:pageTracker._trackPageview('/outbound/article/reblog.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=9577292b-5635-41cf-8b13-155409cffb66" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/C4eFzxoDP5g" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/05/27/lawsuit-brewing-against-popular-pos-software-provider-and-reseller/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/05/27/lawsuit-brewing-against-popular-pos-software-provider-and-reseller/</feedburner:origLink></item>
		<item>
		<title>ExxonMobil’s PA-DSS Extension</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/NVsW1r2m8KU/</link>
		<comments>http://www.retailinfosec.com/2010/05/27/exxonmobils-pa-dss-extension/#comments</comments>
		<pubDate>Thu, 27 May 2010 15:22:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[PED / Payment Terminals]]></category>

		<category><![CDATA[Retailers]]></category>

		<category><![CDATA[application security]]></category>

		<category><![CDATA[headline]]></category>

		<category><![CDATA[deadline]]></category>

		<category><![CDATA[ExxonMobil]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[PADSS]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<category><![CDATA[Point of sale]]></category>

		<category><![CDATA[VISA]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=392</guid>
		<description><![CDATA[The link to the article on StorefrontBacktalk is below (thanks Evan) - this is really interesting.  It appears that VISA is providing an extension to ExxonMobil on the July 1st, 2010 PA-DSS deadline&#8230;
This implies two things (as far as I can see):

That the deadline everyone was wondering about is legit - why would ExxonMobil feel the need to negotiate an extension with VISA unless the deadline was going to mean something and VISA was going to enforce it at some meaningful level?
If you are big enough, VISA is going to ...]]></description>
			<content:encoded><![CDATA[<p>The link to the article on StorefrontBacktalk is below (thanks Evan) - this is really interesting.  It appears that VISA is providing an extension to ExxonMobil on the July 1st, 2010 PA-DSS deadline&#8230;</p>
<p>This implies two things (as far as I can see):</p>
<ol>
<li>That the deadline everyone was wondering about is legit - why would ExxonMobil feel the need to negotiate an extension with VISA unless the deadline was going to mean something and VISA was going to enforce it at some meaningful level?</li>
<li>If you are big enough, VISA is going to play ball&#8230;</li>
</ol>
<p>Not sure that #2 bodes all that well for smaller merchants (of all types) as I doubt that VISA&#8217;s all that interested in negotiating with everyone of extensions.</p>
<p>As is mentioned in the article, providing extensions to this sort of deadline creates problems unless you make them very, very rarely.  Which, again, strengthens the case for July 1st being a &#8216;real&#8217; deadline for merchants.</p>
<p>We are currently doing a LOT of PA-DSS work for software clients, but, at this point those applications, even if they are validated prior to the first of July, will most likely not be fully deployed at merchant sites&#8230;.</p>
<p>It&#8217;s getting interesting as July approaches.</p>
<p><a href="http://www.storefrontbacktalk.com/securityfraud/exxonmobil-discovers-that-a-pci-deadline-is-a-deadline-unless-it-isnt/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.storefrontbacktalk.com');">StorefrontBacktalk » Blog Archive » ExxonMobil Discovers That A PCI Deadline Is A Deadline, Unless It Isn’t</a>.</p>
<p><a id="aptureLink_1cEnPJdV4D" style="margin: 0pt auto; text-align: center; display: block; padding: 0px 6px;" href="http://search.twitter.com/search?q=PA-DSS" onclick="javascript:pageTracker._trackPageview('/outbound/article/search.twitter.com');"><img style="border: 0px none;" title="What people are saying about &quot;PA-DSS&quot;" src="http://placeholder.apture.com/ph/370x341_TwitterArticle/" alt="" width="370px" height="341px" /></a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/875bf25a-b5fa-49b0-985c-a5f4e8818a99/" onclick="javascript:pageTracker._trackPageview('/outbound/article/reblog.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=875bf25a-b5fa-49b0-985c-a5f4e8818a99" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/NVsW1r2m8KU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/05/27/exxonmobils-pa-dss-extension/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/05/27/exxonmobils-pa-dss-extension/</feedburner:origLink></item>
		<item>
		<title>Upcoming NetSPI Webinar — PCI 2.0: Moving Beyond Simple Compliance to Improved Security with Application Whitelisting</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/GtuNwYCDVrY/</link>
		<comments>http://www.retailinfosec.com/2010/04/01/upcoming-netspi-webinar-%e2%80%94-pci-20-moving-beyond-simple-compliance-to-improved-security-with-application-whitelisting/#comments</comments>
		<pubDate>Thu, 01 Apr 2010 13:53:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[PCI Philosophy / Approach]]></category>

		<category><![CDATA[CoreTrace]]></category>

		<category><![CDATA[David Gianna]]></category>

		<category><![CDATA[NetSPI]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<category><![CDATA[webinar]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/2010/04/01/upcoming-netspi-webinar-%e2%80%94-pci-20-moving-beyond-simple-compliance-to-improved-security-with-application-whitelisting/</guid>
		<description><![CDATA[Here&#8217;s the link to a webinar that NetSPI and CoreTrace are doing on April 8th.  So far we have a really good set of attendees and David Gianna, one of NetSPI&#8217;s senior consultants and QSAs, is going to be presenting on:

Quick PCI overview, including the role of the PCI Security  Standards Council and QSAs; the interrelationship of PCI-DSS, PA-DSS and  PED; Merchant-Acquirer-QSA relationship; and the major PCI-DSS  requirements
Discussion of PCI compliance versus Information Security and the  relationship between each
Baseline view of the operational realities that make ...]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s the link to a webinar that NetSPI and CoreTrace are doing on April 8th.  So far we have a really good set of attendees and David Gianna, one of NetSPI&#8217;s senior consultants and QSAs, is going to be presenting on:</p>
<ul class="margin_bottom_3p5em">
<li>Quick PCI overview, including the role of the PCI Security  Standards Council and QSAs; the interrelationship of PCI-DSS, PA-DSS and  PED; Merchant-Acquirer-QSA relationship; and the major PCI-DSS  requirements</li>
<li>Discussion of PCI compliance versus Information Security and the  relationship between each</li>
<li>Baseline view of the operational realities that make POS systems  unique</li>
<li>Review of the pros / cons of security solutions (e.g.,  blacklist-based antivirus, emergency security patches, application  white-listing)</li>
<li>Discussion of POS antivirus and file integrity monitoring  requirements in POS systems; operational and deployment challenges;  application whitelisting as compensating controls (Case Study)</li>
</ul>
<p>Here&#8217;s the link to the registration and hope to see you there&#8230;</p>
<p><a href="http://coretrace.com/resources/webinars/NetSPI_Webinar--PCI_2.0_Moving_Beyond_Simple_Compliance_to_Improved_Security.aspx" onclick="javascript:pageTracker._trackPageview('/outbound/article/coretrace.com');">NetSPI Webinar — PCI 2.0: Moving Beyond Simple Compliance to Improved Security with Application Whitelisting</a>.</p>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/GtuNwYCDVrY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/04/01/upcoming-netspi-webinar-%e2%80%94-pci-20-moving-beyond-simple-compliance-to-improved-security-with-application-whitelisting/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/04/01/upcoming-netspi-webinar-%e2%80%94-pci-20-moving-beyond-simple-compliance-to-improved-security-with-application-whitelisting/</feedburner:origLink></item>
		<item>
		<title>Good Information On Another State Adopting PCI As Law</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/OE_sptoMMCs/</link>
		<comments>http://www.retailinfosec.com/2010/03/25/good-information-on-another-state-adopting-pci-as-law/#comments</comments>
		<pubDate>Thu, 25 Mar 2010 16:48:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[law]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<category><![CDATA[Washington]]></category>

		<category><![CDATA[Washington State]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=383</guid>
		<description><![CDATA[Thank you to David Navetta - his site is an excellent source of information regarding privacy law and he spends a lot of time putting out very good information about the legal issues surrounding compliance.
FAQ on Washington State&#8217;s Impending PCI Law : Info Law Group .



]]></description>
			<content:encoded><![CDATA[<p>Thank you to David Navetta - his site is an excellent source of information regarding privacy law and he spends a lot of time putting out very good information about the legal issues surrounding compliance.</p>
<p><a id="aptureLink_7jSjqx3gNr" href="http://www.infolawgroup.com/2010/03/articles/payment-card-breach-laws/faq-on-washington-states-pci-law/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.infolawgroup.com');">FAQ on Washington State&#8217;s Impending PCI Law : Info Law Group</a> .</p>
<p><a id="aptureLink_eH3ZTbt3hw" style="margin: 0pt auto; text-align: center; display: block; padding: 0px 6px;" href="http://en.wikipedia.org/wiki/Payment%20Card%20Industry%20Data%20Security%20Standard" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');"><img style="border: 0px none;" title="Payment Card Industry Data Security Standard" src="http://placeholder.apture.com/ph/360x320_WikipediaArticle/" alt="" width="360px" height="320px" /></a></p>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/OE_sptoMMCs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/03/25/good-information-on-another-state-adopting-pci-as-law/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/03/25/good-information-on-another-state-adopting-pci-as-law/</feedburner:origLink></item>
		<item>
		<title>YouTube - Hitler and Cloud Computing Security</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/2-orDo87u_Q/</link>
		<comments>http://www.retailinfosec.com/2010/02/26/youtube-hitler-and-cloud-computing-security/#comments</comments>
		<pubDate>Fri, 26 Feb 2010 19:26:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[funny]]></category>

		<category><![CDATA[video]]></category>

		<category><![CDATA[weird]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/2010/02/26/youtube-hitler-and-cloud-computing-security/</guid>
		<description><![CDATA[
I had know idea that there was a genre of online comedy videos that used scenes of Hitler from movies coupled with fake closed caption information&#8230;.
Didn&#8217;t really think Hitler could be all that funny, but this one is pretty good.  Mind - I don&#8217;t speak a lick of German and have no idea what is really being said here, but the captions are hilarious&#8230;
Thanks to ReadWriteWeb for the spot.
YouTube - Hitler and Cloud Computing Security.


]]></description>
			<content:encoded><![CDATA[<p><object width="425" height="350"><param name="movie" value="http://www.youtube.com/v/VjfaCoA2sQk&#038;feature=player_embedded#"></param><param name="wmode" value="transparent"></param><embed src="http://www.youtube.com/v/VjfaCoA2sQk&#038;feature=player_embedded#" type="application/x-shockwave-flash" wmode="transparent" width="425" height="350"></embed></object></p>
<p>I had know idea that there was a genre of online comedy videos that used scenes of Hitler from movies coupled with fake closed caption information&#8230;.</p>
<p>Didn&#8217;t really think Hitler could be all that funny, but this one is pretty good.  Mind - I don&#8217;t speak a lick of German and have no idea what is really being said here, but the captions are hilarious&#8230;</p>
<p>Thanks to ReadWriteWeb for the spot.</p>
<p><a href="http://www.youtube.com/watch?v=VjfaCoA2sQk&amp;feature=player_embedded#" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.youtube.com');">YouTube - Hitler and Cloud Computing Security</a>.</p>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/2-orDo87u_Q" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/02/26/youtube-hitler-and-cloud-computing-security/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/02/26/youtube-hitler-and-cloud-computing-security/</feedburner:origLink></item>
	</channel>
</rss>
