<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: pci-compliant]]></title>
    <link>http://securityratty.com/tag/pci-compliant</link>
    <description></description>
    <pubDate>Tue, 04 Nov 2008 08:42:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[PCI DSS Blogs]]></title>
      <link>http://securityratty.com/article/680e726961476b01eb06206d6d3d3e36</link>
      <guid>http://securityratty.com/article/680e726961476b01eb06206d6d3d3e36</guid>
      <description><![CDATA[I polled a few lists to create a longer lost of PCI DSS related blogs (looking especially for blogs by QSAs), so IN NO PARTICULAR ORDER
Obviously: http://chuvakin.blogspot.com/search/label/PCI
PCI DSS...]]></description>
      <content:encoded><![CDATA[<p>I polled a few lists to create a longer lost of PCI DSS related blogs (looking especially for blogs by QSAs), so IN NO PARTICULAR ORDER:</p>  <ul>   <li>Obviously:&#160; <a title="http://chuvakin.blogspot.com/search/label/PCI" href="http://chuvakin.blogspot.com/search/label/PCI">http://chuvakin.blogspot.com/search/label/PCI</a>&#160;&#160; :-)</li>    <li><a href="http://treasuryinstitute.org/blog/">PCI DSS News and Information</a> at <a title="http://www.treasuryinstitute.org/blog" href="http://www.treasuryinstitute.org/blog">http://www.treasuryinstitute.org/blog</a>&#160;</li>    <li><a href="http://pcianswers.com/">PCI Answers</a> at <a title="http://pcianswers.com/" href="http://pcianswers.com/">http://pcianswers.com/</a></li>    <li><a href="http://blogs.verisign.com/securityconvergence/">Branden Williams' Security Convergence Blog</a>&#160; at <a title="http://blogs.verisign.com/securityconvergence/" href="http://blogs.verisign.com/securityconvergence/">http://blogs.verisign.com/securityconvergence/</a>&#160;</li>    <li><a href="http://www.securitim.com/blog.html">SecuriTIM on PCI DSS</a> at <a title="http://www.securitim.com/blog.html" href="http://www.securitim.com/blog.html">http://www.securitim.com/blog.html</a></li>    <li><a href="http://pcidss.wordpress.com">Payment Card Security &amp; IT Controls Explained</a> at <a title="http://pcidss.wordpress.com/" href="http://pcidss.wordpress.com/">http://pcidss.wordpress.com/</a>&#160;</li> </ul>  <p>If I missed anybody, sorry, please add below and I will update my list!</p>  <p>Just FYI.</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=mqNpN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=mqNpN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=NpamN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=NpamN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=P6qnN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=P6qnN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/464433611" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 24 Nov 2008 12:20:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/pci dss news">pci dss news</category>
      <category domain="http://securityratty.com/tag/blogs">blogs</category>
      <category domain="http://securityratty.com/tag/payment card security">payment card security</category>
      <category domain="http://securityratty.com/tag/security convergence blog">security convergence blog</category>
      <category domain="http://securityratty.com/tag/securitim">securitim</category>
      <category domain="http://securityratty.com/tag/chuvakin">chuvakin</category>
      <category domain="http://securityratty.com/tag/pci answers">pci answers</category>
      <category domain="http://securityratty.com/tag/lists">lists</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/464433611/pci-dss-blogs.html">PCI DSS Blogs</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-11-19 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/359d830ca1e8df85568ee491fac7b4b0</link>
      <guid>http://securityratty.com/article/359d830ca1e8df85568ee491fac7b4b0</guid>
      <description><![CDATA[QualysGuard PCI Pass/Fail Status Criteria - Qualys
Press Releases - November 11, 2008 - Q1 Labs free, downloadable, log management and compliance product that provides organizations with visibility...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.qualys.com/products/pci/qgpci/pass_fail_criteria/">QualysGuard PCI Pass/Fail Status Criteria - Qualys</a></li>
<li><a href="http://www.q1labs.com/pr.php?id=711">Press Releases - November 11, 2008 - Q1 Labs</a><br/>
free, downloadable, log management and compliance product that provides organizations with visibility across their networks, data centers, and infrastructures</li>
<li><a href="http://www.cheapest-service.com/blog/2008/11/11/healthy-paranoia-top-50-internet-security-blogs/">&nbsp; Healthy Paranoia: Top 50 Internet Security Blogs&nbsp;by&nbsp;The Daily Netizen</a></li>
<li><a href="http://www.govcert.nl/symposium/audiovideo.html">GOVCERT.NL Symposium 2008</a></li>
<li><a href="http://sec.online.wsj.com/article/SB122461917614955373.html">Looking for Trouble - WSJ.com</a></li>
<li><a href="http://blog.clearnetsec.com/articles/2008/11/11/it%E2%80%99s-hard-to-build-a-smart-siem">ClearNet Security : It&rsquo;s hard to build a smart SIEM</a><br/>
If you find yourself evaluating SIEM products, dig in and investigate how each works - you don’t want yesterday’s product.</li>
<li><a href="http://www.thecomplianceauthority.rsvp1.com/articles/111908_taylor.shtm">PCI Perspectives by Dave Taylor</a></li>
<li><a href="http://physicsworld.com/blog/2008/09/killed_by_complexity_1.html">Lehman Bros 'killed by complexity' (physicsworld.com Blog) - physicsworld.com</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/459218630" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/internet security blogs">internet security blogs</category>
      <category domain="http://securityratty.com/tag/clearnet security">clearnet security</category>
      <category domain="http://securityratty.com/tag/dave taylor">dave taylor</category>
      <category domain="http://securityratty.com/tag/compliance product">compliance product</category>
      <category domain="http://securityratty.com/tag/healthy paranoia">healthy paranoia</category>
      <category domain="http://securityratty.com/tag/labs free">labs free</category>
      <category domain="http://securityratty.com/tag/press releases">press releases</category>
      <category domain="http://securityratty.com/tag/physicsworld">physicsworld</category>
      <category domain="http://securityratty.com/tag/siem products">siem products</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/459218630/anton18">Links for 2008-11-19 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[International Challenges in PCI Security]]></title>
      <link>http://securityratty.com/article/383b5bc7418aefa54c267b0148c6dbcc</link>
      <guid>http://securityratty.com/article/383b5bc7418aefa54c267b0148c6dbcc</guid>
      <description><![CDATA[In a country that's seen many regulatory compliance challenges this decade, the headaches of PCI security tend to be analyzed from a largely American...]]></description>
      <content:encoded><![CDATA[In a country that's seen many regulatory compliance challenges this decade, the headaches of PCI security tend to be analyzed from a largely American perspective.]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci security">pci security</category>
      <category domain="http://securityratty.com/tag/regulatory compliance challenges">regulatory compliance challenges</category>
      <category domain="http://securityratty.com/tag/american perspective">american perspective</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/decade">decade</category>
      <category domain="http://securityratty.com/tag/headaches">headaches</category>
      <source url="http://www.networkworld.com/news/2008/111908-international-challenges-in-pci.html?fsrc=rss-security">International Challenges in PCI Security</source>
    </item>
    <item>
      <title><![CDATA[PCI Compliance: Visa Announces Global Deadlines]]></title>
      <link>http://securityratty.com/article/ba5bdbf0ffaee194038c2d46f0eefbbb</link>
      <guid>http://securityratty.com/article/ba5bdbf0ffaee194038c2d46f0eefbbb</guid>
      <description><![CDATA[In response to the complex and global threats faced by the cardholder ecosystem, Visa Inc recently announced worldwide deadlines for PCI DSS Compliance . &quot;Compliance with PCI DSS is vital to ensuring...]]></description>
      <content:encoded><![CDATA[<p>In response to the <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1324">complex and global</a> threats faced by the cardholder ecosystem, <a href="http://www.visa.com/globalgateway/gg_selectcountry.html?retcountry=1">Visa Inc</a> recently announced <a href="http://corporate.visa.com/md/nr/press873.jsp">worldwide deadlines for PCI DSS Compliance</a>.&nbsp; &quot;Compliance with PCI DSS is vital to ensuring the integrity of the global payments
  system,&quot; said Eduardo Perez, head of global data security, Visa Inc.&nbsp; &quot;Aligning
  compliance programs across the Visa regions is the latest step in our commitment
  to safeguarding cardholder data.&quot; </p>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/visa">visa</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/pci dss compliance">pci dss compliance</category>
      <category domain="http://securityratty.com/tag/visa regions">visa regions</category>
      <category domain="http://securityratty.com/tag/compliance programs">compliance programs</category>
      <category domain="http://securityratty.com/tag/global payments system">global payments system</category>
      <category domain="http://securityratty.com/tag/global data security">global data security</category>
      <category domain="http://securityratty.com/tag/global threats faced">global threats faced</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1391">PCI Compliance: Visa Announces Global Deadlines</source>
    </item>
    <item>
      <title><![CDATA[PCI council sharpens oversight of security auditors]]></title>
      <link>http://securityratty.com/article/092db7fdd8ce420ec4ed5019f12c970b</link>
      <guid>http://securityratty.com/article/092db7fdd8ce420ec4ed5019f12c970b</guid>
      <description><![CDATA[The PCI Security Standards Council introduces plan to sharpen oversight of qualified security assessors and approved scanning...]]></description>
      <content:encoded><![CDATA[The PCI Security Standards Council introduces plan to sharpen oversight of qualified security assessors and approved scanning vendors.]]></content:encoded>
      <pubDate>Sun, 16 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oversight">oversight</category>
      <category domain="http://securityratty.com/tag/security assessors">security assessors</category>
      <category domain="http://securityratty.com/tag/vendors">vendors</category>
      <source url="http://www.networkworld.com/news/2008/111708-pci-reports.html?fsrc=rss-security">PCI council sharpens oversight of security auditors</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up October 2008]]></title>
      <link>http://securityratty.com/article/425e8bb2014656857a1c215075620790</link>
      <guid>http://securityratty.com/article/425e8bb2014656857a1c215075620790</guid>
      <description><![CDATA[As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see today . These monthly round-ups is an attempt to remind...]]></description>
      <content:encoded><![CDATA[<p>As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. These <a href="http://chuvakin.blogspot.com/search/label/Monthly">monthly round-ups</a> is an attempt to remind people of useful content from the past month!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>OF COURSE, the news of my “transition” is the item #1, by far. “<a href="http://chuvakin.blogspot.com/2008/10/change.html">Change!!!</a>” and “<a href="http://www.qualys.com/solutions/pci_compliance/">Qualys</a>” posts rule the list.</li>    <li>Last month I posted a bunch of my presentations on logs, security, etc on the blog.&#160; “<a href="http://www.slideshare.net/anton_chuvakin/logs-for-incident-response-and-forensics-key-issues-for-govcertnl-2008-presentation-620704">Presentation from GOVCERT.NL 2008: Log Forensics</a>” takes one of the tops spots; and so do “<a href="http://www.slideshare.net/anton_chuvakin/application-logging-good-bad-ugly-beautiful-presentation">Presentation on Application Logging, Done Wrong or Very Wrong</a>” and “<a href="http://www.slideshare.net/anton_chuvakin/logs-vs-insiders-presentation">Presentation on Optimizing Your Logging for Insider Attack Tracking</a>.”&#160; BTW, all the presentations are <a href="http://chuvakin.blogspot.com/search/label/presentation">here</a>.</li>    <li>Shockingly, <a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">AGAIN</a> this month, the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as #1 most popular post (maybe driven by <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">my poll</a>).&#160; BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a> and my other “top 11” lists.</li>    <li>SIEM bashing reached a new high (eh…“low”? :-)), now that Richard is <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">helping too</a>;&#160; my “<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a> is on the top list. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a> and <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">here</a>.)</li>    <li>Somewhat predictably, PCI compliance is obviously still all the rage: <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was again propelled to a place in my monthly Top5 list.</li> </ol>  <p><a href="http://chuvakin.blogspot.com/search/label/Monthly">See you</a> in November.</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - September 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160; <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div></p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bZriN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bZriN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=8jskN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=8jskN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=haLRN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=haLRN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/448986147" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 13:35:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/monthly round-ups">monthly round-ups</category>
      <category domain="http://securityratty.com/tag/monthly top5 list">monthly top5 list</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/448986147/monthly-blog-round-up-october-2008.html">Monthly Blog Round-Up October 2008</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-11-06 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/a88afa49f28b659bf98722bc908c9727</link>
      <guid>http://securityratty.com/article/a88afa49f28b659bf98722bc908c9727</guid>
      <description><![CDATA[TaoSecurity: Defining Security Event Correlation
PCI DSS Automated Scanning Vendor (ASV) Shame Payment Card Security &amp; IT Controls...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://taosecurity.blogspot.com/2008/11/defining-security-event-correlation.html">TaoSecurity: Defining Security Event Correlation</a></li>
<li><a href="http://pcidss.wordpress.com/2008/01/11/pci-dss-automated-scanning-vendor-asv-shame/">PCI DSS Automated Scanning Vendor (ASV) Shame&hellip; &laquo; Payment Card Security &amp; IT Controls Explained</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/445139559" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security event correlation">security event correlation</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/asv">asv</category>
      <category domain="http://securityratty.com/tag/controls">controls</category>
      <category domain="http://securityratty.com/tag/taosecurity">taosecurity</category>
      <category domain="http://securityratty.com/tag/vendor">vendor</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/445139559/anton18">Links for 2008-11-06 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-11-04 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/5e84689208a4d24a69dded2b66fde252</link>
      <guid>http://securityratty.com/article/5e84689208a4d24a69dded2b66fde252</guid>
      <description><![CDATA[PCI Blog - Compliance Demystified Blog Archive E-Commerce Startups deal with PCI...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://pcianswers.com/2008/11/03/e-commerce-startups-deal-with-pci-compliance/">PCI Blog - Compliance Demystified &raquo; Blog Archive &raquo; E-Commerce Startups deal with PCI compliance</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/442884066" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 04 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci compliance">pci compliance</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/pci blog">pci blog</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/442884066/anton18">Links for 2008-11-04 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[PCI's Post-Audit Pain Points]]></title>
      <link>http://securityratty.com/article/dea175de37d7d8cb10b5064529683ba4</link>
      <guid>http://securityratty.com/article/dea175de37d7d8cb10b5064529683ba4</guid>
      <description><![CDATA[Those who thought their PCI security challenges would be over after the first passing compliance audit say they continue to be dogged by the same problems that caused pain in the...]]></description>
      <content:encoded><![CDATA[Those who thought their PCI security challenges would be over after the first passing compliance audit say they continue to be dogged by the same problems that caused pain in the beginning.]]></content:encoded>
      <pubDate>Tue, 04 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci security challenges">pci security challenges</category>
      <category domain="http://securityratty.com/tag/pain">pain</category>
      <category domain="http://securityratty.com/tag/compliance audit">compliance audit</category>
      <category domain="http://securityratty.com/tag/continue">continue</category>
      <source url="http://www.networkworld.com/news/2008/110508-pcis-post-audit-pain.html?fsrc=rss-security">PCI's Post-Audit Pain Points</source>
    </item>
    <item>
      <title><![CDATA[On Small Companies and PCI Compliance]]></title>
      <link>http://securityratty.com/article/e0e1165c2e26892133c37ebe3e10c017</link>
      <guid>http://securityratty.com/article/e0e1165c2e26892133c37ebe3e10c017</guid>
      <description><![CDATA[Read this post ( &quot;E-Commerce Startups deal with PCI compliance &quot; at &quot;PCI Anwsers&quot; Blog ) and weeeeeeep: &quot;I once was talking with a small business owner who was reading through the Self-Assessment...]]></description>
      <content:encoded><![CDATA[Read <a href="http://pcianswers.com/2008/11/03/e-commerce-startups-deal-with-pci-compliance/">this post</a> (<a href="http://pcianswers.com/2008/11/03/e-commerce-startups-deal-with-pci-compliance/">"E-Commerce Startups deal with PCI compliance</a>" at <a href="http://pcianswers.com">"PCI Anwsers" Blog</a>) and weeeeeeep:  "I once was talking with a small business owner who was reading through the Self-Assessment Questionnaire (SAQ) and stopped at the first question, which basically said, Do you have a properly configured firewall? <span style="font-weight: bold;"> The business owner called into the back room and asked the store manager, “Hey, do we have a firewall?”</span>  <span style="font-weight: bold;">The store manager replied that he thought they had a fire extinguisher which was up to date.  </span>I then watched as the store manger<span style="font-weight: bold;"> checked the “In Place” box</span> on the form stating they had a properly configured firewall in place."<br /><br />Wonna "sell  PCI compliance" to small businesses? One need to get smart in a very special way! :-)<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=McEHN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=McEHN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=g0W2N"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=g0W2N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=IAe6N"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=IAe6N" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/442458664" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 04 Nov 2008 08:42:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci compliance">pci compliance</category>
      <category domain="http://securityratty.com/tag/store manager">store manager</category>
      <category domain="http://securityratty.com/tag/business owner">business owner</category>
      <category domain="http://securityratty.com/tag/e-commerce startups deal">e-commerce startups deal</category>
      <category domain="http://securityratty.com/tag/firewall">firewall</category>
      <category domain="http://securityratty.com/tag/self-assessment questionnaire">self-assessment questionnaire</category>
      <category domain="http://securityratty.com/tag/properly">properly</category>
      <category domain="http://securityratty.com/tag/fire extinguisher">fire extinguisher</category>
      <category domain="http://securityratty.com/tag/store manger">store manger</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/442458664/on-small-companies-and-pci-compliance.html">On Small Companies and PCI Compliance</source>
    </item>
  </channel>
</rss>
