<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: 10 Fallacies in PCI Conversations</title>
	<atom:link href="http://chaordicmind.com/blog/2009/06/09/10-fallacies-in-pci-conversations/feed/" rel="self" type="application/rss+xml" />
	<link>http://chaordicmind.com/blog/2009/06/09/10-fallacies-in-pci-conversations/</link>
	<description>Mixing childlike wonder with adultlike understanding</description>
	<lastBuildDate>Tue, 15 May 2012 19:54:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Chaordic Mind &#187; Personal Responsibility in PCI</title>
		<link>http://chaordicmind.com/blog/2009/06/09/10-fallacies-in-pci-conversations/comment-page-1/#comment-118</link>
		<dc:creator>Chaordic Mind &#187; Personal Responsibility in PCI</dc:creator>
		<pubDate>Sun, 16 Aug 2009 19:44:01 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=41#comment-118</guid>
		<description>[...] we look at the 10 Fallacies of PCI and read the 10 Myths of PCI [PDF] direct from the PCI SSC, you can see Myth #4 says, &#8220;PCI [...]</description>
		<content:encoded><![CDATA[<p>[...] we look at the 10 Fallacies of PCI and read the 10 Myths of PCI [PDF] direct from the PCI SSC, you can see Myth #4 says, &#8220;PCI [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anton Chuvakin</title>
		<link>http://chaordicmind.com/blog/2009/06/09/10-fallacies-in-pci-conversations/comment-page-1/#comment-46</link>
		<dc:creator>Anton Chuvakin</dc:creator>
		<pubDate>Thu, 11 Jun 2009 21:16:29 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=41#comment-46</guid>
		<description>&quot;One of the thins I’ve been considering is that we have reached critical mass with getting people on-board with payments security.&quot;

God no. Nowhere near reached it, if you look at smaller orgs.

&quot;What I’d like to work on next is helping people ask better questions about payments security.&quot;

Definitely! I just had a freak-out recently over &quot;PCI is toothless.&quot;    For fuck&#039;s sake, you are not doing PCI because of some teeth, but to secure your data!!!

&quot;After almost 4 years of fielding questions, I have a list of them in my head that come up over and over. &quot;

Mike, you need to ...uh... write a book on it or something :-) Sorry! :-(</description>
		<content:encoded><![CDATA[<p>&#8220;One of the thins I’ve been considering is that we have reached critical mass with getting people on-board with payments security.&#8221;</p>
<p>God no. Nowhere near reached it, if you look at smaller orgs.</p>
<p>&#8220;What I’d like to work on next is helping people ask better questions about payments security.&#8221;</p>
<p>Definitely! I just had a freak-out recently over &#8220;PCI is toothless.&#8221;    For fuck&#8217;s sake, you are not doing PCI because of some teeth, but to secure your data!!!</p>
<p>&#8220;After almost 4 years of fielding questions, I have a list of them in my head that come up over and over. &#8221;</p>
<p>Mike, you need to &#8230;uh&#8230; write a book on it or something <img src='http://chaordicmind.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  Sorry! <img src='http://chaordicmind.com/blog/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://chaordicmind.com/blog/2009/06/09/10-fallacies-in-pci-conversations/comment-page-1/#comment-45</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Thu, 11 Jun 2009 21:05:53 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=41#comment-45</guid>
		<description>Anton, yes, many of us preach the same thing over and over.  One of the thins I&#039;ve been considering is that we have reached critical mass with getting people on-board with payments security.  I believe the remaining people are those who have heard the warning signs and disregarded them.

What I&#039;d like to work on next is helping people ask better questions about payments security.  I think we focus so much on the answers that we don&#039;t ask if we are asking the right questions.

After almost 4 years of fielding questions, I have a list of them in my head that come up over and over.  In fact you only need to get the questions for a few months before you see them repeat.  In fact, I believe most people are asking the wrong questions and then debating the answers, which at that point are potentially irrelevant.</description>
		<content:encoded><![CDATA[<p>Anton, yes, many of us preach the same thing over and over.  One of the thins I&#8217;ve been considering is that we have reached critical mass with getting people on-board with payments security.  I believe the remaining people are those who have heard the warning signs and disregarded them.</p>
<p>What I&#8217;d like to work on next is helping people ask better questions about payments security.  I think we focus so much on the answers that we don&#8217;t ask if we are asking the right questions.</p>
<p>After almost 4 years of fielding questions, I have a list of them in my head that come up over and over.  In fact you only need to get the questions for a few months before you see them repeat.  In fact, I believe most people are asking the wrong questions and then debating the answers, which at that point are potentially irrelevant.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PCI punk</title>
		<link>http://chaordicmind.com/blog/2009/06/09/10-fallacies-in-pci-conversations/comment-page-1/#comment-44</link>
		<dc:creator>PCI punk</dc:creator>
		<pubDate>Thu, 11 Jun 2009 15:28:25 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=41#comment-44</guid>
		<description>Good to see you back on the blog scene again!

BTW, what happened with you and Aegenis?</description>
		<content:encoded><![CDATA[<p>Good to see you back on the blog scene again!</p>
<p>BTW, what happened with you and Aegenis?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://chaordicmind.com/blog/2009/06/09/10-fallacies-in-pci-conversations/comment-page-1/#comment-43</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Wed, 10 Jun 2009 16:00:56 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=41#comment-43</guid>
		<description>If the acquirer agrees to the request of the merchant to self validate:

http://usa.visa.com/merchants/risk_management/cisp_merchants.html

Level 1 Merchants
The Annual On-Site PCI Data Security Assessment must be completed for Level 1 merchants according to the PCI Requirements and Security Assessment Procedures v1.2 document. This document is also to be used as the template for the Report on Compliance.

Level 1 merchants should engage a Qualified Security Assessor to complete the Report on Compliance and provide the report to their acquirer. Alternatively, acquirers may elect to accept the Report on Compliance from a Level 1 merchant, provided that a letter signed by a merchant officer accompanies the report. Level 1 merchants must also submit the Attestation of Compliance for Onsite Assessments – Merchants form completed by their assessor to their acquirers. The Attestation of Compliance for Onsite Assessments – Merchants can be found in the PCI Requirements and Security Assessment Procedures v1.2 document.

Acquirers must submit the Attestation of Compliance for Onsite Assessments - Merchants form and a letter accepting the merchant’s full compliance validation to Visa upon receipt and acceptance of the merchant’s validation documentation.

Download the PCI Data Security Standard v1.2.

Download the Attestation of Compliance for Onsite Assessments - Merchants.</description>
		<content:encoded><![CDATA[<p>If the acquirer agrees to the request of the merchant to self validate:</p>
<p><a href="http://usa.visa.com/merchants/risk_management/cisp_merchants.html" rel="nofollow">http://usa.visa.com/merchants/risk_management/cisp_merchants.html</a></p>
<p>Level 1 Merchants<br />
The Annual On-Site PCI Data Security Assessment must be completed for Level 1 merchants according to the PCI Requirements and Security Assessment Procedures v1.2 document. This document is also to be used as the template for the Report on Compliance.</p>
<p>Level 1 merchants should engage a Qualified Security Assessor to complete the Report on Compliance and provide the report to their acquirer. Alternatively, acquirers may elect to accept the Report on Compliance from a Level 1 merchant, provided that a letter signed by a merchant officer accompanies the report. Level 1 merchants must also submit the Attestation of Compliance for Onsite Assessments – Merchants form completed by their assessor to their acquirers. The Attestation of Compliance for Onsite Assessments – Merchants can be found in the PCI Requirements and Security Assessment Procedures v1.2 document.</p>
<p>Acquirers must submit the Attestation of Compliance for Onsite Assessments &#8211; Merchants form and a letter accepting the merchant’s full compliance validation to Visa upon receipt and acceptance of the merchant’s validation documentation.</p>
<p>Download the PCI Data Security Standard v1.2.</p>
<p>Download the Attestation of Compliance for Onsite Assessments &#8211; Merchants.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George</title>
		<link>http://chaordicmind.com/blog/2009/06/09/10-fallacies-in-pci-conversations/comment-page-1/#comment-42</link>
		<dc:creator>George</dc:creator>
		<pubDate>Wed, 10 Jun 2009 08:10:05 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=41#comment-42</guid>
		<description>In addition to Lucas&#039; point, the list of service providers MasterCard publishes, also says &#039;compliant&#039;.

With astonishment, I have read the following argument of yours: 

&quot;Most merchants forget a small fact that every level of merchant is allowed to self assess if they wish.  Level 1 merchants can use their internal audit group or a QSA, and Levels 2-4 all use the Self-Assessment Questionnaire (SAQ).&quot;

Of course Level 1&#039;s can self-assess, so can my grandmother, but they also have to get in a QSA for validation! If not, please show me where that is written.</description>
		<content:encoded><![CDATA[<p>In addition to Lucas&#8217; point, the list of service providers MasterCard publishes, also says &#8216;compliant&#8217;.</p>
<p>With astonishment, I have read the following argument of yours: </p>
<p>&#8220;Most merchants forget a small fact that every level of merchant is allowed to self assess if they wish.  Level 1 merchants can use their internal audit group or a QSA, and Levels 2-4 all use the Self-Assessment Questionnaire (SAQ).&#8221;</p>
<p>Of course Level 1&#8242;s can self-assess, so can my grandmother, but they also have to get in a QSA for validation! If not, please show me where that is written.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anton Chuvakin</title>
		<link>http://chaordicmind.com/blog/2009/06/09/10-fallacies-in-pci-conversations/comment-page-1/#comment-41</link>
		<dc:creator>Anton Chuvakin</dc:creator>
		<pubDate>Tue, 09 Jun 2009 20:02:49 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=41#comment-41</guid>
		<description>What&#039;s up with everybody&#039;s PCI myths being the same? http://www.slideshare.net/anton_chuvakin/pci-dss-myths-mistakes-misconceptions-2009-teaser-version-1171140</description>
		<content:encoded><![CDATA[<p>What&#8217;s up with everybody&#8217;s PCI myths being the same? <a href="http://www.slideshare.net/anton_chuvakin/pci-dss-myths-mistakes-misconceptions-2009-teaser-version-1171140" rel="nofollow">http://www.slideshare.net/anton_chuvakin/pci-dss-myths-mistakes-misconceptions-2009-teaser-version-1171140</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anton Chuvakin</title>
		<link>http://chaordicmind.com/blog/2009/06/09/10-fallacies-in-pci-conversations/comment-page-1/#comment-40</link>
		<dc:creator>Anton Chuvakin</dc:creator>
		<pubDate>Tue, 09 Jun 2009 20:01:30 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=41#comment-40</guid>
		<description>&quot;The PCI DSS is all about “risk transference”

I have to restrain myself physically when people say those naughty two words.&quot;


Exactly! Me too! Me too!! I want to also remind them that risk needs to be transferred to the party responsible - which, in a conservative 99% of cases :-), is the merchant...</description>
		<content:encoded><![CDATA[<p>&#8220;The PCI DSS is all about “risk transference”</p>
<p>I have to restrain myself physically when people say those naughty two words.&#8221;</p>
<p>Exactly! Me too! Me too!! I want to also remind them that risk needs to be transferred to the party responsible &#8211; which, in a conservative 99% of cases <img src='http://chaordicmind.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> , is the merchant&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lucas</title>
		<link>http://chaordicmind.com/blog/2009/06/09/10-fallacies-in-pci-conversations/comment-page-1/#comment-39</link>
		<dc:creator>Lucas</dc:creator>
		<pubDate>Tue, 09 Jun 2009 16:31:59 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=41#comment-39</guid>
		<description>Good writeup! One small thing though. The Visa web site admins aren&#039;t very good at keeping up with the CISP team. &quot;PCI DDS&quot; was in there for quite a while. It wasn&#039;t until January this year that they updated the payment app security mandates to clarify that PA-DSS compliance is what&#039;s required, not validation (For obvious reasons). It&#039;s only in the last month or two, after RBS Lynk and Heartland that Visa changed the wording on service providers to say validated instead of compliant. That mistake has always been a pet peeve of mine since it contradicts compliant vs validated preaching. Check out the wayback machine (http://web.archive.org/web/20080126112739/http://usa.visa.com/merchants/risk_management/cisp_service_providers.html) or even the name of the pdf doc itself (cisp-list-of-pcidss-compliant-service-providers.pdf).</description>
		<content:encoded><![CDATA[<p>Good writeup! One small thing though. The Visa web site admins aren&#8217;t very good at keeping up with the CISP team. &#8220;PCI DDS&#8221; was in there for quite a while. It wasn&#8217;t until January this year that they updated the payment app security mandates to clarify that PA-DSS compliance is what&#8217;s required, not validation (For obvious reasons). It&#8217;s only in the last month or two, after RBS Lynk and Heartland that Visa changed the wording on service providers to say validated instead of compliant. That mistake has always been a pet peeve of mine since it contradicts compliant vs validated preaching. Check out the wayback machine (<a href="http://web.archive.org/web/20080126112739/http://usa.visa.com/merchants/risk_management/cisp_service_providers.html" rel="nofollow">http://web.archive.org/web/20080126112739/http://usa.visa.com/merchants/risk_management/cisp_service_providers.html</a>) or even the name of the pdf doc itself (cisp-list-of-pcidss-compliant-service-providers.pdf).</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.750 seconds -->

