<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: MasterCard change for L2 merchants increases the market for QSAs by 2-4x</title>
	<atom:link href="http://chaordicmind.com/blog/2009/06/17/mastercard-change-for-l2-merchants-increases-the-market-for-qsas-by-2-4x/feed/" rel="self" type="application/rss+xml" />
	<link>http://chaordicmind.com/blog/2009/06/17/mastercard-change-for-l2-merchants-increases-the-market-for-qsas-by-2-4x/</link>
	<description>Mixing childlike wonder with adultlike understanding</description>
	<lastBuildDate>Thu, 09 Feb 2012 14:50:58 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: admin</title>
		<link>http://chaordicmind.com/blog/2009/06/17/mastercard-change-for-l2-merchants-increases-the-market-for-qsas-by-2-4x/comment-page-1/#comment-65</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Tue, 23 Jun 2009 16:30:13 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=56#comment-65</guid>
		<description>Here&#039;s the interesting thing.  I feel that the MasterCard change, along with other conversations in the industry, are going to push merchants towards adopting end-to-end encryption and other scope reduction measures faster than they would normally.

I&#039;ll argue that the MasterCard change *could* increase the work for QSAs or it *could* drive people to reduce the amount of data they accept and retain.

The PCI Answers blog has a &lt;a href=&quot;http://pcianswers.com/2009/06/08/visa-leads-the-way-end-to-end-encryption/&quot; target=&quot;_new&quot; rel=&quot;nofollow&quot;&gt;list of companies that currently offer end-to-end encryption options&lt;/a&gt;.  Though, I&#039;m not sure if they do so in South Africa yet. ;)</description>
		<content:encoded><![CDATA[<p>Here&#8217;s the interesting thing.  I feel that the MasterCard change, along with other conversations in the industry, are going to push merchants towards adopting end-to-end encryption and other scope reduction measures faster than they would normally.</p>
<p>I&#8217;ll argue that the MasterCard change *could* increase the work for QSAs or it *could* drive people to reduce the amount of data they accept and retain.</p>
<p>The PCI Answers blog has a <a href="http://pcianswers.com/2009/06/08/visa-leads-the-way-end-to-end-encryption/" target="_new" rel="nofollow">list of companies that currently offer end-to-end encryption options</a>.  Though, I&#8217;m not sure if they do so in South Africa yet. <img src='http://chaordicmind.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dominic White</title>
		<link>http://chaordicmind.com/blog/2009/06/17/mastercard-change-for-l2-merchants-increases-the-market-for-qsas-by-2-4x/comment-page-1/#comment-63</link>
		<dc:creator>Dominic White</dc:creator>
		<pubDate>Tue, 23 Jun 2009 06:58:07 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=56#comment-63</guid>
		<description>I agree with what you&#039;ve said, but it feels like the PCI is pushing the other way, for external QSA&#039;s and Internal Audit isn&#039;t ideal. If that is the case, and if the Mastercard change will drive more QSA work (I also think MC wants a QSA at some point if you use IA anyway), then they need to address the independence issue, which is my main point.</description>
		<content:encoded><![CDATA[<p>I agree with what you&#8217;ve said, but it feels like the PCI is pushing the other way, for external QSA&#8217;s and Internal Audit isn&#8217;t ideal. If that is the case, and if the Mastercard change will drive more QSA work (I also think MC wants a QSA at some point if you use IA anyway), then they need to address the independence issue, which is my main point.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://chaordicmind.com/blog/2009/06/17/mastercard-change-for-l2-merchants-increases-the-market-for-qsas-by-2-4x/comment-page-1/#comment-62</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Tue, 23 Jun 2009 06:52:14 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=56#comment-62</guid>
		<description>I think one of the most forgotten items is that Level 2-4 merchants can validate with the Self-Assessment Questionnaire and Level 1 merchants can request their bank let them self-assess.  If you have the skills internally then ask to use them.

That being said, I think there are a number of skilled professionals out there that can provide a *huge* benefit in assisting the audit process.  I&#039;ve been involved on PCI DSS audits driven by the Internal Audit team of a company and it was checklist based.  That does not happen everywhere, but you really want these internal auditors trained as well.</description>
		<content:encoded><![CDATA[<p>I think one of the most forgotten items is that Level 2-4 merchants can validate with the Self-Assessment Questionnaire and Level 1 merchants can request their bank let them self-assess.  If you have the skills internally then ask to use them.</p>
<p>That being said, I think there are a number of skilled professionals out there that can provide a *huge* benefit in assisting the audit process.  I&#8217;ve been involved on PCI DSS audits driven by the Internal Audit team of a company and it was checklist based.  That does not happen everywhere, but you really want these internal auditors trained as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dominic White</title>
		<link>http://chaordicmind.com/blog/2009/06/17/mastercard-change-for-l2-merchants-increases-the-market-for-qsas-by-2-4x/comment-page-1/#comment-60</link>
		<dc:creator>Dominic White</dc:creator>
		<pubDate>Tue, 23 Jun 2009 06:44:39 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=56#comment-60</guid>
		<description>If the QSA sector grows massively, we&#039;re going to need to see some audit type regulation being put in place by the PCI and payment brands. I think the fact that a QSA can implement and audit their work right now and that won&#039;t influence their attestation is a Enron like problem. Internal audit departments on the other hand are good at dealing with this stuff, and frankly could use some upskilling. I think the PCI should be pushing QSA training for Internal Audit out instead of &#039;bullying&#039; merchants to hire in external people, or if they are hell bent on using externals, then lower the unlimited liability clause to allow external audit to do it. I think the payment brands are reinventing the wheel.

#Disclosure, I work for an auditing house, but not as an auditor.</description>
		<content:encoded><![CDATA[<p>If the QSA sector grows massively, we&#8217;re going to need to see some audit type regulation being put in place by the PCI and payment brands. I think the fact that a QSA can implement and audit their work right now and that won&#8217;t influence their attestation is a Enron like problem. Internal audit departments on the other hand are good at dealing with this stuff, and frankly could use some upskilling. I think the PCI should be pushing QSA training for Internal Audit out instead of &#8216;bullying&#8217; merchants to hire in external people, or if they are hell bent on using externals, then lower the unlimited liability clause to allow external audit to do it. I think the payment brands are reinventing the wheel.</p>
<p>#Disclosure, I work for an auditing house, but not as an auditor.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 1.196 seconds -->

