Payment Card Assessments | Compliance and Certification | Education | Healthcare Assessments
By:
DEBBIE ZALLER
September 30th, 2015
NOTE: Schellman has since updated and expanded on this information in an article here. Nobody likes a compliance audit, but they serve a necessary purpose in the business world. If an organization is lacking in its adherence to global compliance regulations, there could be serious fallout. Employees or customers may lose trust. Your company’s reputation could be damaged, and worse — lawsuits and fines can significantly damage financial health. For this reason, chief compliance officers must change the way they think about audits. Painstaking as they may be, an audit provides you the opportunity to rectify issues before they become larger problems. Instead of dreading and avoiding an upcoming audit, here’s how compliance leaders can prepare their company to make the review process less agonizing.
FedRAMP | Payment Card Assessments | Federal Assessments
By:
MATT WILGUS
July 9th, 2015
Overview In the last 30 days, the FedRAMP Program Management Office (PMO) has published guidance for both vulnerability scanning and penetration testing. The updated guidance comes on the heels of PCI mandating the enhanced penetration testing requirements within its requirement 11.3 as part of the 3.0, now 3.1, version of the DSS. These augmented PCI requirements, introduced in the fall of 2013, took effect on June 30th. For many cloud service providers this means the requirements for vulnerability scanning and penetration testing are more thorough and will require additional resources for planning, executing and remediating findings. This article will walk through the updates and discuss the differentiation between FedRAMP and the PCI Data Security Standard (DSS).
Payment Card Assessments | PCI DSS | TPRM
By:
Ken Van Allen
December 10th, 2014
The Payment Card Industry Data Security Standard (PCI DSS) is a global security framework designed to safeguard credit card information, protect sensitive authentication data, and minimize the risk of fraud. The PCI Security Standards Council (SSC) released a set of guidelines detailing how to manage third-party service provider (TPSP) relationships and PCI DSS compliance requirements. In this article, we break down everything you need to know about navigating PCI DSS TPSP requirements for PCI compliance.
By:
ERIC SAMPSON
October 3rd, 2014
The media has been filled with stories of high profile credit card breaches, including those from Target, Neiman Marcus, P.F. Chang’s and most recently Home Depot. Details on the Home Depot breach are still emerging, but the details around the Target and Neiman Marcus breaches are well known and causing the public to ask if it will happen again?
Cloud Computing | Payment Card Assessments
By:
Douglas Barbin
April 11th, 2013
By Eric Sampson and Doug Barbin In a previous article, we provided a summary of the key components of the PCI DSS Cloud Computing Guidelines (“cloud supplement”). That article focused on roles, responsibilities, agreements, and audit considerations. This article speaks more to the technical considerations.
Cloud Computing | Payment Card Assessments
By:
Douglas Barbin
April 4th, 2013
By Eric Sampson and Doug Barbin