<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Retail Information Security</title>
	
	<link>http://www.retailinfosec.com</link>
	<description>Retail &amp; Hospitality Information Security (including PCI)</description>
	<pubDate>Mon, 08 Nov 2010 17:38:19 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/retailinfosec/aloi" /><feedburner:info uri="retailinfosec/aloi" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Things are a changing at RetailInfoSec</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/bqqsp19DjA8/</link>
		<comments>http://www.retailinfosec.com/2010/11/08/things-are-a-changing-at-retailinfosec/#comments</comments>
		<pubDate>Mon, 08 Nov 2010 17:38:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[headline]]></category>

		<category><![CDATA[blog]]></category>

		<category><![CDATA[InfoSecureComply]]></category>

		<category><![CDATA[moving]]></category>

		<category><![CDATA[new blog]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[update]]></category>

		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=499</guid>
		<description><![CDATA[Good morning (or whatever it is where you are)!
I&#8217;m putting up this post to let everyone know that the blog is going to be changing very shortly - I&#8217;m continuing to do a lot of work with leading retailers on information security initiatives and I&#8217;m still paying close attention to retail and payments security, but I&#8217;m discovering that some other areas of the business world are also starting to become a large part of my daily work life.
As I grow my involvement in these other areas of business (including the ...]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.retailinfosec.com/wp-content/uploads/2010/11/enter.jpg" ><img class="size-thumbnail wp-image-500 alignright" title="enter" src="http://www.retailinfosec.com/wp-content/uploads/2010/11/enter-150x150.jpg" alt="" width="150" height="150" /></a>Good morning (or whatever it is where you are)!</p>
<p>I&#8217;m putting up this post to let everyone know that the blog is going to be changing very shortly - I&#8217;m continuing to do a lot of work with leading retailers on information security initiatives and I&#8217;m still paying close attention to retail and payments security, but I&#8217;m discovering that some other areas of the business world are also starting to become a large part of my daily work life.</p>
<p>As I grow my involvement in these other areas of business (including the healthcare and software technology verticals), I&#8217;m starting to find that I have a lot to say regarding issues important to those other business verticals as well, so I&#8217;m going to be expanding the focus of the blog to incorporate some of these additional vertical focuses.  Not moving away from retail (and a lot of the articles are still going to be retail-focused - after all, retail technology has been a very, very important part of my professional career) just expanding the discussion.</p>
<p>This blog address is going to become inactive as of this week and all content will be posted to a new URL - <a href="http://www.infosecurecomply.com" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.infosecurecomply.com');">http://www.infosecurecomply.com</a>.  Check it out, send me feedback (positive or negative) and thanks for reading.  I&#8217;ll keep the same twitter feed (@alexcrittenden) since it&#8217;s my personal twitter feed and I&#8217;ve pulled all data from this blog into the new site, so all the articles should still be available (although the images might have gotten messed up a bit in the move.</p>
<p>The blog&#8217;s also a new design, so don&#8217;t be thrown by that.  Thanks to all for reading RetailInfoSec and please head over to <a href="http://www.infosecurecomply.com" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.infosecurecomply.com');">InfoSecureComply</a> to keep things going!  Thank you!!!!</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=4bbe4921-a583-4d25-8a03-ad5abb264fa4" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/bqqsp19DjA8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/11/08/things-are-a-changing-at-retailinfosec/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/11/08/things-are-a-changing-at-retailinfosec/</feedburner:origLink></item>
		<item>
		<title>PCI Community Meeting Follow-Up</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/y2VJ1iv7JxQ/</link>
		<comments>http://www.retailinfosec.com/2010/09/30/pci-community-meeting-follow-up/#comments</comments>
		<pubDate>Thu, 30 Sep 2010 16:10:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Conferences / Webinars]]></category>

		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[PCI Philosophy / Approach]]></category>

		<category><![CDATA[PED / Payment Terminals]]></category>

		<category><![CDATA[headline]]></category>

		<category><![CDATA[NetSPI]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[PA-DSS 2.0]]></category>

		<category><![CDATA[Payment card industry]]></category>

		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>

		<category><![CDATA[PCI 2.0]]></category>

		<category><![CDATA[PCI Community Meeting]]></category>

		<category><![CDATA[Qualified Security Assessor]]></category>

		<category><![CDATA[Tony Fulda]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=484</guid>
		<description><![CDATA[
I started to write a detailed feedback post on the 2010 PCI Community Meeting in Orlando that I attended last week, but realized that there were far more intelligent people than myself already posting, so I&#8217;m going to keep my commentary to impressions and general feedback and provide some links to posts that should prove useful for those that are interested in some of the details that came out of the meeting (and what&#8217;s coming in PCI / PA 2.0).
To begin with, the entire attitude of the meeting this year ...]]></description>
			<content:encoded><![CDATA[<div id="attachment_447" class="wp-caption alignleft" style="width: 169px"><a href="../wp-content/uploads/2010/08/untitled_by_paalia_via_flickr.jpg"><img class="size-medium wp-image-447" title="untitled_by_paalia_via_flickr" src="../wp-content/uploads/2010/08/untitled_by_paalia_via_flickr.jpg" alt="untitled_by_paalia_via_flickr" width="159" height="240" /></a><p class="wp-caption-text">untitled_by_paalia_via_flickr</p></div>
<p>I started to write a detailed feedback post on the 2010 <a class="zem_slink freebase/en/payment_card_industry" title="Payment card industry" rel="wikipedia" href="http://en.wikipedia.org/wiki/Payment_card_industry" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">PCI</a> Community Meeting in Orlando that I attended last week, but realized that there were far more intelligent people than myself already posting, so I&#8217;m going to keep my commentary to impressions and general feedback and provide some links to posts that should prove useful for those that are interested in some of the details that came out of the meeting (and what&#8217;s coming in PCI / PA 2.0).</p>
<p>To begin with, the entire attitude of the meeting this year was a bit different than in past years - I was surprised at the less &#8216;aggressive&#8217; posture of both the PCI SSC and the card brands themselves and how willing they were to admit the fact that the standard still doesn&#8217;t address everything that it maybe should.  The merchants in attendance this year also seemed to be less upset then in past meetings.  Maybe it&#8217;s just that this was not a feedback year, but everyone seemed less tense and I think the SSC made an active effort to promote that more relaxed attitude (which I think was a good idea).</p>
<p>Regardless, it made for a more pleasant meeting - the networking opportunities were more productive and useful for all involved and hallway discussions were certainly more prevalent than in past years which I take as an indication that everyone was feeling a bit less tense than in previous years.</p>
<p>The one discussion that seemed a bit more contentious was the <a class="zem_slink freebase/en/pa_dss" title="PA-DSS" rel="wikipedia" href="http://en.wikipedia.org/wiki/PA-DSS" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">PA-DSS</a> discussion as it remains a standard with some inherent confusion for those organizations that are not &#8216;typical&#8217; POS providers.  Some of the clarifications that came from the brands and the SSC regarding PA-DSS applicability to non-standard POS were helpful, but there were still a number of good points raised by software vendors that the council acknowledged have not yet been fully addressed.</p>
<p>I will pass on one piece of advice - if you are a company that makes (or uses) a payment application for the iPhone or a similar, non-hardened mobile device I would pay close attention to any opinion the SSC may release and I&#8217;d get your PA-<a class="zem_slink freebase/en/qualified_security_assessor" title="Qualified Security Assessor" rel="wikipedia" href="http://en.wikipedia.org/wiki/Qualified_Security_Assessor" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">QSA</a> or QSA on the phone today to discuss.</p>
<p>Now read this post:</p>
<p><strong><a href="http://www.netspi.com/blog/2010/09/24/whats-new-in-pci-dss-20-no-surprise-that-there-are-no-surprises/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.netspi.com');">Tony Fulda&#8217;s post - </a></strong><a href="http://www.netspi.com/blog/2010/09/24/whats-new-in-pci-dss-20-no-surprise-that-there-are-no-surprises/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.netspi.com');">What&#8217;s New in PCI DSS 2.0 - No Surprise That There Are No Surprises</a></p>
<p>Tony&#8217;s great and his post is both funny and informative as it provides a really good overview of the important points of clarification that were discussed at the meeting regarding PCI.</p>
<p>Some additional posts/links that would prove useful:</p>
<p><a href="https://www.pcisecuritystandards.org/pdfs/summary_of_changes_highlights.pdf" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.pcisecuritystandards.org');">Summary of changes from the SSC</a></p>
<p><a href="https://www.pcisecuritystandards.org/education/fact_sheets.shtml" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.pcisecuritystandards.org');">The Fact Sheets page for the SSC</a> - they made reference to several documents that will shortly be released, so I&#8217;d check back on this page periodically</p>
<p><a href="http://www.mckeay.net/2010/09/25/in-defense-of-the-pci-no-social-media-policy/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+MartinMckeaysNetworkSecurityBlog+%28Network+Security+Blog%29&amp;utm_content=Google+Reader" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.mckeay.net');">In Defense of the PCI &#8220;No social media&#8221; Policy</a> - Martin Mckeay</p>
<p><a href="https://www.brandenwilliams.com/blog/2010/09/28/full-review-of-the-2010-pci-community-meeting/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.brandenwilliams.com');">Full Review of the PCI Community Meeting</a> - Branden Williams</p>
<p>UPDATE - one more post to add:</p>
<div>
<div style="overflow: hidden; color: #000000; background-color: transparent; text-align: left; text-decoration: none; border: medium none;"><a href="http://www.storefrontbacktalk.com/securityfraud/pci-2-0-major-step-forward-if-you-value-vagueness/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.storefrontbacktalk.com');">PCI 2.0: Major Step Forward, If You Value Vagueness</a><span> - StorefrontBacktalk<br />
<a style="color: #003399;" href="http://www.storefrontbacktalk.com/securityfraud/pci-2-0-major-step-forward-if-you-value-vagueness/#ixzz111vHEXTV"><br />
</a></span></div>
</div>
<p>As you know - I&#8217;m not a QSA (nor do I pretend to be one on TV) and while I may work for a leading QSA firm my commentary is going to stay pretty high level, but the links above should provide some very good insight into the meeting.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://blogs.forbes.com/firewall/2010/08/16/payment-card-industry-punts-on-key-security-questions/" onclick="javascript:pageTracker._trackPageview('/outbound/article/blogs.forbes.com');">Payment Card Industry Punts On Key Security Questions</a> (blogs.forbes.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.pcworld.com/article/203140/revisions_to_credit_card_security_standard_on_the_way.html?tk=rss_news" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.pcworld.com');">Revisions to Credit Card Security Standard on the Way</a> (pcworld.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=448e1ddb-8f31-423c-8e8b-d2bcd69e9f26" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/y2VJ1iv7JxQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/09/30/pci-community-meeting-follow-up/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/09/30/pci-community-meeting-follow-up/</feedburner:origLink></item>
		<item>
		<title>Where it all began: chain retailers’ first locations</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/irK-CfKal9I/</link>
		<comments>http://www.retailinfosec.com/2010/09/29/where-it-all-began-chain-retailers-first-locations/#comments</comments>
		<pubDate>Wed, 29 Sep 2010 15:52:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[Chain store]]></category>

		<category><![CDATA[retail]]></category>

		<category><![CDATA[Retail Trade]]></category>

		<category><![CDATA[Retailers]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/2010/09/29/where-it-all-began-chain-retailers-first-locations/</guid>
		<description><![CDATA[OK - this has nothing to do with security, but I stumbled across this article this morning and had to share.
Having worked with large retail organizations for years implementing technology solutions (and now providing security services) it&#8217;s sometimes pretty easy to think of these giant companies as having always been massive, multi-national organizations.
In truth, they all began as a store-front or two, founded by individuals with a vision for their store and how they would succeed.  The culture and the value-proposition that these initial founders established are what have allowed ...]]></description>
			<content:encoded><![CDATA[<p>OK - this has nothing to do with security, but I stumbled across this article this morning and had to share.</p>
<p>Having worked with large retail organizations for years implementing technology solutions (and now providing security services) it&#8217;s sometimes pretty easy to think of these giant companies as having always been massive, multi-national organizations.</p>
<p>In truth, they all began as a store-front or two, founded by individuals with a vision for their store and how they would succeed.  The culture and the value-proposition that these initial founders established are what have allowed these retailers to grow to the size that they have today.</p>
<p>What I think is interesting is that the retailers mentioned in the article have typically done well over the years when sticking with their core founding principles, but have faltered if they have attempted to change the culture and the attitude of their organization.</p>
<p>Retail, no matter how big, is still a relationship with the consumer and when that relationship changes is can be very difficult to digest for both the retailer and their customer.</p>
<p><a href="http://www.walletpop.com/blog/2010/09/28/where-it-all-began-chain-retailers-first-locations/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.walletpop.com');">Where it all began: chain retailers&#8217; first locations</a>.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=76312382-54d7-46ee-90f9-1380975bbe6b" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/irK-CfKal9I" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/09/29/where-it-all-began-chain-retailers-first-locations/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/09/29/where-it-all-began-chain-retailers-first-locations/</feedburner:origLink></item>
		<item>
		<title>On my way to the PCI North American Community Meeting</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/hBOocKjTVD0/</link>
		<comments>http://www.retailinfosec.com/2010/09/20/on-my-way-to-the-pci-north-american-community-meeting/#comments</comments>
		<pubDate>Mon, 20 Sep 2010 14:27:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[Conferences / Webinars]]></category>

		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[headline]]></category>

		<category><![CDATA[conference]]></category>

		<category><![CDATA[Orlando]]></category>

		<category><![CDATA[Orlando  Florida]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>

		<category><![CDATA[PCI Community Meeting]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<category><![CDATA[PCI-SSC]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=464</guid>
		<description><![CDATA[OK - so I&#8217;m on a plane this afternoon (for the 4th week in a row - my wife loves me right now!) heading to Orlando - it&#8217;s time for the PCI Community Meeting!
Last year blogging was unofficially encouraged, but there really wasn&#8217;t all that much to blog about - this year should prove a bit different given the release of the updated standard.  I&#8217;ll try to put together a post or two on relevant and interesting information (that I&#8217;m allowed to share), but I&#8217;ll also be the moderator on ...]]></description>
			<content:encoded><![CDATA[<p>OK - so I&#8217;m on a plane this afternoon (for the 4th week in a row - my wife loves me right now!) heading to Orlando - it&#8217;s time for the PCI Community Meeting!</p>
<p>Last year blogging was unofficially encouraged, but there really wasn&#8217;t all that much to blog about - this year should prove a bit different given the release of the updated standard.  I&#8217;ll try to put together a post or two on relevant and interesting information (that I&#8217;m allowed to share), but I&#8217;ll also be the moderator on a webinar that NetSPI is putting on next week - check the NetSPI website in a day or two.  I&#8217;ll also be posting the information here as well once everything is fully finalized.</p>
<dl id="attachment_466" class="wp-caption alignright">
<dt class="wp-caption-dt"> </dt>
</dl>
<dl id="attachment_466" class="wp-caption alignright">
<dt class="wp-caption-dt"> </dt>
</dl>
<dl id="attachment_466" class="wp-caption alignright">
<dt class="wp-caption-dt"> </dt>
</dl>
<p>If you are heading down to the meeting and want to meet-up or grab a beer, let me know -</p>
<dl id="attachment_466" class="wp-caption alignright">
<dt class="wp-caption-dt"> </dt>
</dl>
<p>info@retailinfosec.com.</p>
<dl id="attachment_466" class="wp-caption alignright">
<dt class="wp-caption-dt"> </dt>
</dl>
<p><a href="https://www.pcisecuritystandards.org/community_meeting_2010/orlando/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.pcisecuritystandards.org');">PCI North American Community Meeting</a>.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.mckeay.net/2010/09/19/defcon-18-the-pci-panel/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.mckeay.net');">Defcon 18: The PCI Panel</a> (mckeay.net)</li>
<li class="zemanta-article-ul-li"><a href="https://www.brandenwilliams.com/blog/2010/08/27/pci-dss-versus-y2k/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.brandenwilliams.com');">PCI DSS versus Y2K</a> (brandenwilliams.com)</li>
</ul>
<p><a id="aptureLink_LD8dDMDvbe" style="margin: 0pt auto; text-align: center; display: block; padding: 0px 6px;" href="http://twitter.com/PCIguy" onclick="javascript:pageTracker._trackPageview('/outbound/article/twitter.com');"><img style="border: 0px none;" title="@PCIguy" src="http://placeholder.apture.com/ph/370x341_TwitterArticle/" alt="" width="370px" height="341px" /></a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=b57f0af1-1e46-4761-b49f-cd9cbac51ff1" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/hBOocKjTVD0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/09/20/on-my-way-to-the-pci-north-american-community-meeting/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/09/20/on-my-way-to-the-pci-north-american-community-meeting/</feedburner:origLink></item>
		<item>
		<title>Interesting Posts Summary</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/UdrpvJ4HdE4/</link>
		<comments>http://www.retailinfosec.com/2010/09/03/interesting-posts-summary/#comments</comments>
		<pubDate>Fri, 03 Sep 2010 15:46:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[Retailers]]></category>

		<category><![CDATA[application security]]></category>

		<category><![CDATA[article]]></category>

		<category><![CDATA[Articles]]></category>

		<category><![CDATA[business]]></category>

		<category><![CDATA[cloud security]]></category>

		<category><![CDATA[EMV]]></category>

		<category><![CDATA[Magnetic stripe card]]></category>

		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>

		<category><![CDATA[payment security]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[skimming]]></category>

		<category><![CDATA[VISA]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=462</guid>
		<description><![CDATA[I&#8217;ve been traveling a lot lately and, although I&#8217;ve read and had lots of commentary about a number of blog posts and news article recently relating to retail security, I haven&#8217;t had the time to write them down and post them&#8230;
So I&#8217;ve decided that I&#8217;m going to post a summary of the posts and articles that I&#8217;ve read over the last week or so that I&#8217;ve thought were interesting and relevant.  This isn&#8217;t what I&#8217;d really prefer to do - I&#8217;d much rather take the opportunity to rant about something ...]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been traveling a lot lately and, although I&#8217;ve read and had lots of commentary about a number of blog posts and news article recently relating to retail security, I haven&#8217;t had the time to write them down and post them&#8230;</p>
<p>So I&#8217;ve decided that I&#8217;m going to post a summary of the posts and articles that I&#8217;ve read over the last week or so that I&#8217;ve thought were interesting and relevant.  This isn&#8217;t what I&#8217;d really prefer to do - I&#8217;d much rather take the opportunity to rant about something or to try to explain something that we&#8217;ve seen out in the &#8216;real world&#8217;, but sometimes you just don&#8217;t have the time, so forgive me my laziness this time around.</p>
<p><a href="http://http://pymnts.com/heartland-payment-systems-and-discover-agree-to-5-million-intrusion-settlement-20100901006944/" onclick="javascript:pageTracker._trackPageview('/outbound/article/pymnts.com');">Heartland and Discover Agree to Settlement</a></p>
<p><a href="http://www.ehospitalitytimes.com/?p=2722" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.ehospitalitytimes.com');">PCI Compliance - Why Spas, Hotels, and Resorts Can No Longer Ignore IT</a></p>
<p><a href="http://www.netspi.com/blog/2010/09/02/security-in-the-cloud/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.netspi.com');">NetSPI Blog - Security in the Cloud</a></p>
<p><a href="http://www.storefrontbacktalk.com/securityfraud/visa-raises-the-bar-for-pa-dss-applications-and-vendors/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.storefrontbacktalk.com');">Some Additional Commentary on VISA Payment Security Best Practices Guidelines&#8230;</a></p>
<p><a href="http://www.americanbanker.com/btn_issues/23_9/the-fed-gets-involved-with-emv-1024784-1.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.americanbanker.com');">The Fed Gets Involved with EMV</a> (I find EMV an interesting topic although I might be alone in this&#8230;)</p>
<p><a href="http://www.bankinfosecurity.com/articles.php?art_id=2877" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.bankinfosecurity.com');">Skimming: Old Crime, New Tools</a> (this one is also interesting to me)</p>
<p>I hope that you find these article interesting and I&#8217;ll get back to more comment-rich posting shortly.  Thanks!</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://pindebit.blogspot.com/2010/07/european-payments-council-newsletter.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/pindebit.blogspot.com');">European Payments Council Newsletter: New Business Opportunities with Chip and PIN</a> (pindebit.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://pindebit.blogspot.com/2010/07/is-us-wising-up-to-smart-card-use-in.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/pindebit.blogspot.com');">Is U.S. &#8220;Wising Up&#8221; to Smart Card Use in America?</a> (pindebit.blogspot.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=6b82c886-8c68-4800-ab92-1dab440067e1" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/UdrpvJ4HdE4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/09/03/interesting-posts-summary/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/09/03/interesting-posts-summary/</feedburner:origLink></item>
		<item>
		<title>Some Security Metrics Education</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/GRMhcwoBRCM/</link>
		<comments>http://www.retailinfosec.com/2010/08/25/some-security-metrics-education/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 19:12:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[application security]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[budgeting]]></category>

		<category><![CDATA[Metrics]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[security metrics]]></category>

		<category><![CDATA[tracking]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=458</guid>
		<description><![CDATA[
Short post here, but things always seem to happen in groups, so I thought I&#8217;d make everyone aware of a couple of current and upcoming opportunities to dig into a very important topic (particularly during budget season) - Security Metrics.
NetSPI is putting on a webinar tomorrow (Thursday, Aug 26th) with Symantec - here&#8217;s the info/sign-up page on their website (full disclosure, if you don&#8217;t know by now I work for NetSPI):
Application Security - without metrics it doesn&#8217;t exist
And I got the August issue of The ISSA Journal yesterday and the ...]]></description>
			<content:encoded><![CDATA[<div class="mceTemp"></div>
<div id="attachment_459" class="wp-caption alignleft" style="width: 160px"><a href="http://www.retailinfosec.com/wp-content/uploads/2010/08/actual-is-not-normal-a-tribute-to-edward-tufte.jpg" ><img class="size-thumbnail wp-image-459 " title="actual-is-not-normal-a-tribute-to-edward-tufte" src="http://www.retailinfosec.com/wp-content/uploads/2010/08/actual-is-not-normal-a-tribute-to-edward-tufte-150x150.jpg" alt="Actual is not normal (a tribute to Edward Tufte) - kevindooley via flickr" width="150" height="150" /></a><p class="wp-caption-text">Actual is not normal (a tribute to Edward Tufte) - kevindooley via flickr</p></div>
<p>Short post here, but things always seem to happen in groups, so I thought I&#8217;d make everyone aware of a couple of current and upcoming opportunities to dig into a very important topic (particularly during budget season) - Security Metrics.</p>
<p>NetSPI is putting on a webinar tomorrow (Thursday, Aug 26th) with Symantec - here&#8217;s the info/sign-up page on their website (full disclosure, if you don&#8217;t know by now I work for NetSPI):</p>
<p><a href="http://www.netspi.com/registration/register.php?event=f623329af4ac4a4b27a106e6fbda3ed0" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.netspi.com');">Application Security - without metrics it doesn&#8217;t exist</a></p>
<p>And I got the August issue of The ISSA Journal yesterday and the cover story is &#8216;Security Metrics, An Overview&#8217; by Clare Nelson.  It&#8217;s a good starting point for Security Metrics and it provides a good list of sources for additional information.  You&#8217;re going to have to be an ISSA member to access the article, but if you are reading this blog you should probably join the ISSA regardless (it&#8217;s like $95 a year or something).</p>
<p>The Journal is available to ISSA members for download from the ISSA site - <a href="http://www.issa.org" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.issa.org');">ISSA </a></p>
<p>I will highlight one of the sources that Clare uses for her article (seriously - join the ISSA and read her article) - the Center for Internet Security - not all of their information is free, but the information that you would need to get started implementing a security metrics program is free - it&#8217;ll at least get your conversations started&#8230;   <a href="http://cisecurity.org" onclick="javascript:pageTracker._trackPageview('/outbound/article/cisecurity.org');">CIS</a></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://blog.tenablesecurity.com/2010/08/security-metrics---is-this-network-getting-better.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/blog.tenablesecurity.com');">Security Metrics - Is This Network Getting Better?</a> (tenablesecurity.com)</li>
</ul>
<p><a id="aptureLink_ou9lZBzzYA" style="margin: 0pt auto; text-align: center; display: block; padding: 0px 6px;" href="http://www.amazon.com/gp/product/0321349989?tag=apture-20" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.amazon.com');"><img style="border: 0px none;" title="Amazon.com: Security Metrics: Replacing Fear, Uncertainty, and Doubt…" src="http://placeholder.apture.com/ph/360x320_AmazonProduct/" alt="" width="360px" height="320px" /></a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=d07ffe87-5551-4e3d-900c-943b6252586d" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/GRMhcwoBRCM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/08/25/some-security-metrics-education/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/08/25/some-security-metrics-education/</feedburner:origLink></item>
		<item>
		<title>VISA Provides Guidance on Secure Implementation and Management of Payment Applications</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/KTfAMrZzZEA/</link>
		<comments>http://www.retailinfosec.com/2010/08/25/visa-provides-guidance-on-secure-implementation-and-management-of-payment-applications/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 14:42:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[Vendors]]></category>

		<category><![CDATA[application security]]></category>

		<category><![CDATA[headline]]></category>

		<category><![CDATA[Data security]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[PADSS]]></category>

		<category><![CDATA[Payment card industry]]></category>

		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>

		<category><![CDATA[reseller]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[Tokenization (data security)]]></category>

		<category><![CDATA[Visa Inc]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=446</guid>
		<description><![CDATA[I walked into the office this morning and got this in my RSS feed aggregator:
VISA Provides Guidance on Secure Implementation and Management of Payment Applications [link]
After  taking a look at the press release and looking through the actual  document that VISA (and SANS apparently) produced [link] I think it’s a  pretty interesting move on the part of VISA.  If you haven’t yet taken a  look and you work for a retailer or a software vendor that sells to the  retail space, I’d advise downloading the ...]]></description>
			<content:encoded><![CDATA[<h4><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">I walked into the office this morning and got this in my RSS feed aggregator:</span></h4>
<p><a href="http://www.prnewswire.com/news-releases/visa-provides-guidance-on-secure-implementation-and-management-of-payment-applications-101369319.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.prnewswire.com');"><em><strong>VISA Provides Guidance on Secure Implementation and Management of Payment Applications</strong></em></a> [link]</p>
<p><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">After  taking a look at the press release and looking through the actual  document that <a href="http://usa.visa.com/download/merchants/bulletin_payment_app_companies_best_practices.pdf" onclick="javascript:pageTracker._trackPageview('/outbound/article/usa.visa.com');">VISA (and SANS apparently) produced [link]</a> I think it’s a  pretty interesting move on the part of <a class="zem_slink freebase/en/visa" title="Visa Inc." rel="homepage" href="http://www.corporate.visa.com" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.corporate.visa.com');">VISA</a>.  If you haven’t yet taken a  look and you work for a retailer or a software vendor that sells to the  retail space, I’d advise downloading the document and reviewing. </span><br />
<span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;"><br class="kix-line-break" />Basically,  this guidance provides VISA’s best-practices regarding the  implementation and support of payment applications that are already  PA-DSS validated.  It appears that some of the recent breaches that have  occurred (<a href="http://www.retailinfosec.com/2010/06/02/additional-information-about-that-potential-lawsuit/" >as per the post here</a>) where the break-down in security may  have happened during the implementation of the software or through  after-deployment support processes has created some action </span></p>
<div id="attachment_447" class="wp-caption alignright" style="width: 160px"><a href="http://www.retailinfosec.com/wp-content/uploads/2010/08/untitled_by_paalia_via_flickr.jpg" ><img class="size-thumbnail wp-image-447 " title="untitled_by_paalia_via_flickr" src="http://www.retailinfosec.com/wp-content/uploads/2010/08/untitled_by_paalia_via_flickr-150x150.jpg" alt="untitled_by_paalia_via_flickr" width="150" height="150" /></a><p class="wp-caption-text">untitled_by_paalia_via_flickr</p></div>
<p><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">from VISA.</span></p>
<p><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">Now - what does this mean for you?</span></p>
<p><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">If  you are a retailer - I’d say that it provides you a list of items that  you are going to want to discuss with your software vendors and their  resellers.  Most of the items in the document are something that your  vendors should already be doing already, but some will, most likely, not  be in place today (the reseller training program is something that I  wouldn’t expect everyone to have in place today for example).  Number 6  in the press release is interesting as well - most of the software  vendors that I’ve been working with are trying not to force an upgrade  on all their retail clients (you’d expect otherwise, but, really, most  of the vendors aren’t being pushy about it with their clients as far as I  can tell), but in #6 VISA is basically telling the vendors to tell you  that you have to upgrade if you have an older, pre-validation, version  of their solution.</span></p>
<p><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">If  you are a software vendor - get ready to spend more money and good luck  not being held responsible for the actions of your resellers&#8230;  In all  honesty - most of the items shouldn’t be a huge stretch (a lot of this  is just good application security stuff), but the specific notes  regarding the reseller training program makes this interesting.  I’m  sure that you already have some sort of program in place for your  resellers, but this might be a bit different from your general training -  what happens when a reseller installs your solution incorrectly AFTER  going through your newly implemented security training program and there  is a breach?  Who’s going to take the blame (legally or otherwise) for  the incorrect installation?</span></p>
<p><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">If you have any comments or insight that you’d like to add - please feel free to comment or send me a note via the contact page.</span></p>
<p><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">Also  - I’ll be heading down to the PCI SSC meeting in September - look for a  post after that trip highlighting some of the changes coming from the  council on the <a class="zem_slink freebase/en/pci_dss" title="Payment Card Industry Data Security Standard" rel="wikipedia" href="http://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">PCI DSS</a>.<br />
</span></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.newswire.ca/en/releases/archive/July2010/15/c4310.html&amp;a=20952785&amp;rid=b6744971-b0bf-4ea4-9b2b-9cb795b70028&amp;e=a6aa6255027138aa5a51d3484891842a" onclick="javascript:pageTracker._trackPageview('/outbound/article/r.zemanta.com');">Visa Releases Global Best Practices for Card Data Tokenization</a> (newswire.ca)</li>
<li class="zemanta-article-ul-li"><a href="http://blog.deurainfosec.com/pci-ssc-releases-highlights-for-2-0-changes" onclick="javascript:pageTracker._trackPageview('/outbound/article/blog.deurainfosec.com');">PCI SSC releases highlights for 2.0 changes</a> (deurainfosec.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.channelweb.co.uk/crn/news/2266290/plug-pci-compliance-gap" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.channelweb.co.uk');">Time to plug the PCI compliance gap</a> (channelweb.co.uk)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=b6744971-b0bf-4ea4-9b2b-9cb795b70028" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/KTfAMrZzZEA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/08/25/visa-provides-guidance-on-secure-implementation-and-management-of-payment-applications/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/08/25/visa-provides-guidance-on-secure-implementation-and-management-of-payment-applications/</feedburner:origLink></item>
		<item>
		<title>Why Your Phone Can’t Really Replace Your Credit Card | Epicenter | Wired.com</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/M78mxLaxmVU/</link>
		<comments>http://www.retailinfosec.com/2010/08/05/why-your-phone-can%e2%80%99t-really-replace-your-credit-card-epicenter%c2%a0-wiredcom/#comments</comments>
		<pubDate>Fri, 06 Aug 2010 02:19:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[article]]></category>

		<category><![CDATA[credit cards]]></category>

		<category><![CDATA[payments]]></category>

		<category><![CDATA[Wired]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=443</guid>
		<description><![CDATA[This is a good, quick article from Wired in response to some recent news stories that the wireless carriers were trying to do an end-around on the credit card companies.  Some one finally got around to doing some actual investigation on what the carriers were doing and it&#8217;s not an end-around, Discover&#8217;s highly involved.
The article also talks about why the major card brands work and attempts at breaking the system and introducing a new model for credit cards (none of which have yet worked)&#8230;  Not really a security article, but ...]]></description>
			<content:encoded><![CDATA[<p>This is a good, quick article from Wired in response to some recent news stories that the wireless carriers were trying to do an end-around on the credit card companies.  Some one finally got around to doing some actual investigation on what the carriers were doing and it&#8217;s not an end-around, Discover&#8217;s highly involved.</p>
<p>The article also talks about why the major card brands work and attempts at breaking the system and introducing a new model for credit cards (none of which have yet worked)&#8230;  Not really a security article, but one that is highly relevant given the focus on payment security.</p>
<p><a href="http://www.wired.com/epicenter/2010/08/phone-credit-card/2/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.wired.com');">Why Your Phone Can’t Really Replace Your Credit Card | Epicenter | Wired.com</a>.</p>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/M78mxLaxmVU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/08/05/why-your-phone-can%e2%80%99t-really-replace-your-credit-card-epicenter%c2%a0-wiredcom/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/08/05/why-your-phone-can%e2%80%99t-really-replace-your-credit-card-epicenter%c2%a0-wiredcom/</feedburner:origLink></item>
		<item>
		<title>Visa Releases New Guidelines For Protecting Card Data</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/MG1xszZ_pQ4/</link>
		<comments>http://www.retailinfosec.com/2010/07/27/visa-releases-new-guidelines-for-protecting-card-data/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 17:00:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[announcements]]></category>

		<category><![CDATA[guidelines]]></category>

		<category><![CDATA[standards]]></category>

		<category><![CDATA[tokenization]]></category>

		<category><![CDATA[VISA]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/2010/07/27/visa-releases-new-guidelines-for-protecting-card-data/</guid>
		<description><![CDATA[For those of you paying attention - I&#8217;m sure that you&#8217;ve already seen this announcement and probably taken a cursory look through the documentation.
I&#8217;ve been a bit out-of-pocket recently (a combination of famility vacation &#38; working on projects with some of our large retail and retail technology clients), but wanted to make sure that I made note of this information from VISA in case you hadn&#8217;t seen it.
Sorry - that&#8217;s it, but as we get through the next crazy week (it&#8217;s Black Hat after all&#8230;) I&#8217;ll try to be more ...]]></description>
			<content:encoded><![CDATA[<p>For those of you paying attention - I&#8217;m sure that you&#8217;ve already seen this announcement and probably taken a cursory look through the documentation.</p>
<p>I&#8217;ve been a bit out-of-pocket recently (a combination of famility vacation &amp; working on projects with some of our large retail and retail technology clients), but wanted to make sure that I made note of this information from VISA in case you hadn&#8217;t seen it.</p>
<p>Sorry - that&#8217;s it, but as we get through the next crazy week (it&#8217;s Black Hat after all&#8230;) I&#8217;ll try to be more active on the blog - I&#8217;ve got a few thoughts on the recent payment terminal announcements from VISA as you might imagine.  Thanks!</p>
<p><a href="http://www.networkcomputing.com/wan-security/visa-releases-new-guidelines-for-protecting-card-data.php" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.networkcomputing.com');">Visa Releases New Guidelines For Protecting Card Data - Network Computing</a>.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://pindebit.blogspot.com/2010/07/visa-inc-completes-acquisition-of.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/pindebit.blogspot.com');">Visa Inc. Completes Acquisition of CyberSource</a> (pindebit.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="https://www.brandenwilliams.com/blog/2010/07/15/tokenization-and-chargebacks/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.brandenwilliams.com');">Tokenization and Chargebacks</a> (brandenwilliams.com)</li>
<li class="zemanta-article-ul-li"><a href="http://go.theregister.com/feed/www.theregister.co.uk/2010/07/08/visa_pci_approval_pin_pads/" onclick="javascript:pageTracker._trackPageview('/outbound/article/go.theregister.com');">Visa yanks PCI approval from PIN entry kit</a> (go.theregister.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=c8277b4e-f5d6-47aa-a303-21ebce9d1378" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/MG1xszZ_pQ4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/07/27/visa-releases-new-guidelines-for-protecting-card-data/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/07/27/visa-releases-new-guidelines-for-protecting-card-data/</feedburner:origLink></item>
		<item>
		<title>Firewall Security - a short article and comment</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/N8g8628k7Tc/</link>
		<comments>http://www.retailinfosec.com/2010/06/15/firewall-security-a-short-article-and-comment/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 19:08:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[firewall]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=422</guid>
		<description><![CDATA[This morning I read the short article that I link to below.  It&#8217;s focused on firewall management and review which is a topic that I think many retail and hospitality organizations should be paying more attention to.
The study in the article was sponsored by a vendor that provides firewall management solutions (go figure), but it doesn&#8217;t mean that the message isn&#8217;t an important one - firewalls are easy to forget about once you
have them in place and (particularly in retail and hospitality) there are so many things that your network ...]]></description>
			<content:encoded><![CDATA[<p>This morning I read the short article that I link to below.  It&#8217;s focused on firewall management and review which is a topic that I think many retail and hospitality organizations should be paying more attention to.</p>
<p>The study in the article was sponsored by a vendor that provides firewall management solutions (go figure), but it doesn&#8217;t mean that the message isn&#8217;t an important one - firewalls are easy to forget about once you</p>
<div id="attachment_426" class="wp-caption alignright" style="width: 310px"><a href="http://www.retailinfosec.com/wp-content/uploads/2010/06/private-property-mollybob.jpg" ><img class="size-medium wp-image-426 " title="private-property-mollybob" src="http://www.retailinfosec.com/wp-content/uploads/2010/06/private-property-mollybob-300x225.jpg" alt="Private Property - via Flickr - mollybob" width="300" height="225" /></a><p class="wp-caption-text">Private Property - via Flickr - mollybob</p></div>
<p>have them in place and (particularly in retail and hospitality) there are so many things that your network and security people have on their to-do list that seem more pressing today then reviewing your firewall rules&#8230;</p>
<p>Now, I&#8217;m not supporting the vendor that sponsored this study and wouldn&#8217;t have the slightest feedback on its products effectiveness, but I am supporting the concept of reviewing and maintaining your firewall configuration.  The company that I work for does a lot of firewall rule assessment and while we are often engaged in this capacity as part of a client&#8217;s normal security operations, that isn&#8217;t always the case.  Sometimes it&#8217;s because management hasn&#8217;t appreciated the need to properly maintain firewall rules and now legitimate network traffic is being affected.</p>
<p>OK - back to the article - what&#8217;s also interesting is the implication that a company that is not taking the proper steps to review their firewall rules periodically will run into legal liability issues if they are breached.  They hit this point fairly hard, but don&#8217;t really provide much in the way of support for their argument.  However, it&#8217;s probably fairly valid - if an organization doesn&#8217;t manage their firewalls effectively (and isn&#8217;t able to demonstrate that they are doing so) it certainly could be something that a lawyer might latch onto &#8230;</p>
<p><a href="http://www.ctoedge.com/content/perils-firewall-security" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.ctoedge.com');">The Perils of Firewall Security | CTO Edge</a>.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.computing.co.uk/computing/news/2264409/professionals-cheat-audits" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.computing.co.uk');">One in 10 IT professionals cheat in audits</a> (computing.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-1001_3-20003521-92.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20" onclick="javascript:pageTracker._trackPageview('/outbound/article/news.cnet.com');">McAfee updates firewall hardware for enterprises</a> (news.cnet.com)</li>
</ul>
<p><a id="aptureLink_58WqfLql2z" style="margin: 0pt auto; text-align: center; display: block; padding: 0px 6px;" href="http://en.wikipedia.org/wiki/Firewall%20%28computing%29" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');"><img style="border: 0px none;" title="Firewall (computing)" src="http://placeholder.apture.com/ph/360x320_WikipediaArticle/" alt="" width="360px" height="320px" /></a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=609e036d-22d5-4291-ae64-1bbdcac3d312" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/N8g8628k7Tc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/06/15/firewall-security-a-short-article-and-comment/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/06/15/firewall-security-a-short-article-and-comment/</feedburner:origLink></item>
	</channel>
</rss>

