<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Chaordic Mind &#187; Uncategorized</title>
	<atom:link href="http://chaordicmind.com/blog/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://chaordicmind.com/blog</link>
	<description>Mixing childlike wonder with adultlike understanding</description>
	<lastBuildDate>Fri, 13 Jan 2012 17:13:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>3rd Annual Top 10 Sexy InfoSec Geeks for 2011</title>
		<link>http://chaordicmind.com/blog/2012/01/01/3rd-annual-top-10-sexy-infosec-geeks-for-2011/</link>
		<comments>http://chaordicmind.com/blog/2012/01/01/3rd-annual-top-10-sexy-infosec-geeks-for-2011/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 03:17:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=697</guid>
		<description><![CDATA[This year has been full of surprises.  Life has taught me that you never really exist in a state of calm or unrest, but some stratified grey area in between.  When life gets rough I think back to the &#8220;in between&#8221; that is water. I&#8217;ve received a few questions about the 2011 sexy infosec geeks [...]]]></description>
			<content:encoded><![CDATA[<p>This year has been full of surprises.  Life has taught me that you never really exist in a state of calm or unrest, but some stratified grey area in between.  When life gets rough I think back to the <a href="http://moreintelligentlife.com/story/david-foster-wallace-in-his-own-words">&#8220;in between&#8221; that is water</a>.</p>
<p>I&#8217;ve received a few questions about the 2011 sexy infosec geeks list, and <a href="http://chaordicmind.com/blog/2010/12/17/top-10-sexy-infosec-geeks-of-2010/">last year was such a hit</a> as was <a href="http://chaordicmind.com/blog/2009/12/28/top-10-sexy-infosec-geeks-of-2009/">the year before</a> that I thought we should do it again.  It is hard to keep a list to just 10 people when you really have a list about 50 long.</p>
<p>A friend asked me how I compiled the list.  I told her it was based on the people I know and those referred to me.  I&#8217;m easily influenced by recommendations of others, as are so many people in this world.  I solicited input, averaged out the outliers, and once again used biased weighting to determine the final set.  Again, these are only my opinions.  I encourage you to make your own list as well. As always, feel free to disagree or add your own using the comments.</p>
<p>Without further commentary and tangent, I give you the Third Annual Top 10 Secy InfoSec Geeks for 2011.</p>
<p style="text-align: left;"><strong>10. <a href="http://addxorrol.blogspot.com/">Halvar Flake</a> (<a href="https://twitter.com/halvarflake">@halvarflake</a>)</strong><br />
<img class="wp-image-717 aligncenter" style="border: 5px solid black; margin-top: 5px; margin-bottom: 5px;" title="flake" src="http://chaordicmind.com/blog/wp-content/uploads/2011/12/flake-300x225.jpg" alt="" width="243" height="183" /></p>
<p>Halvar has many skills. He was denied access to the US in 2007 and prevented from teaching a class at BlackHat &#8211; probably because the information was much needed. He specializes in math, reverse engineering, and making friends with people who recommend him for lists list this.</p>
<p><strong>09.  Felix &#8216;FX&#8217; Lindner (<a href="https://twitter.com/41414141">@41414141</a>)<br />
</strong></p>
<p style="text-align: center;"><img class="wp-image-714 alignnone" style="border: 5px solid black; margin: 5px;" title="FX" src="http://chaordicmind.com/blog/wp-content/uploads/2011/12/FX-294x300.png" alt="" width="265" height="270" /></p>
<p>FX is a well known member of the German security team Phenoelit and Head of Recurity Labs.  He is a mainstay in the security world, who along with the rest of the Pheloelit team has brought many others into security.  He participated in C3, speaks on security, and is overall a nice guy.</p>
<p><strong>08. <a href="http://f0rb1dd3n.com/">Jayson E. Street</a> (<a href="https://twitter.com/jaysonstreet">@jaysonstreet</a>)<br />
</strong></p>
<p style="text-align: center;"><a href="http://chaordicmind.com/blog/wp-content/uploads/2012/01/jayson.jpg"><img class="wp-image-724 alignnone" style="border: 5px solid black; margin: 5px;" title="jayson" src="http://chaordicmind.com/blog/wp-content/uploads/2012/01/jayson.jpg" alt="" width="434" height="240" /></a></p>
<p>Jayson Street, much like Zaphod Beeblebrox, is &#8220;just this guy, ya know&#8221;.  Jayson presents at conferences around the world and people attend his talks because of how entertaining he is, regardless of the topic.  He frequently speaks on the topic of social engineering, is never without his vest of pockets, and amazingly somehow able to find a Pizza Hut and Pepsi in every country he visits. He has received several <a href="http://www.dissectingthehack.com/profiles/blogs/lessons">accolades over the ages</a>.</p>
<p><strong>07. <a href="http://perimeterusa.com/perimeter-e-security/management-team">Andrew Jaquith</a> (<a href="https://twitter.com/ARJ">@arj</a>)</strong></p>
<p style="text-align: center;"><strong><img class="wp-image-718 aligncenter" style="border: 5px solid black; margin-top: 5px; margin-bottom: 5px;" title="arj" src="http://chaordicmind.com/blog/wp-content/uploads/2011/12/arj-300x225.png" alt="" width="240" height="180" /></strong></p>
<p>Aside from being an all around likable guy Andrew has severed in various CTO positions, co-founder of @Stake, and industry analyst positions. Andrew authored the book Security Metrics, started MetriCon, manages Mini-Metricon, and is a full-time pundit.  If someone mentions the words metrics they will probably quote something that Andrew has said.</p>
<p><strong>06. <a href="http://theinvisiblethings.blogspot.com/">Joanna Rutkowska</a></strong></p>
<p style="text-align: center;"><a href="http://chaordicmind.com/blog/wp-content/uploads/2012/01/Joanna-Rutkowska.jpg"><img class="wp-image-725 alignnone" style="border: 5px solid black; margin: 5px;" title="Joanna-Rutkowska" src="http://chaordicmind.com/blog/wp-content/uploads/2012/01/Joanna-Rutkowska-245x300.jpg" alt="" width="245" height="300" /></a></p>
<p>Joanna made a splash in 2006 with her Black Hat presentation on an attack against Vista kernel protection mechanism and a technique dubbed <a title="Blue Pill (malware)" href="http://en.wikipedia.org/wiki/Blue_Pill_%28malware%29">Blue Pill</a>, that used hardware virtualization to move a running OS into a virtual machine. In 2010 she co-created the <a title="Qubes (page does not exist)" href="http://en.wikipedia.org/w/index.php?title=Qubes&amp;action=edit&amp;redlink=1">Qubes</a> security-centric operating system based on Disposable Virtual Machine.  In this era of virtual machines, we need more people to promote the need for security in virtual systems.</p>
<p><strong>05. <a href="http://alexhutton.com/">Alex Hutton</a> (<a href="https://twitter.com/alexhutton">@alexhutton</a>)</strong></p>
<p style="text-align: center;"><img class="wp-image-716 aligncenter" style="border: 5px solid black; margin-top: 5px; margin-bottom: 5px;" title="hutton" src="http://chaordicmind.com/blog/wp-content/uploads/2011/12/hutton1-274x300.jpg" alt="" width="219" height="240" /></p>
<p>Alex Hutton has been involved in so many risky things, he is most certainly an infosec bad-boy. He graduated from the Jack Jones school of Factor Analysis and Information Risk (FAIR), former Research &amp; Intelligence with the Verizon Business RISK Team, author on the Verizon Data Breach Investigation (DBIR) and PCI Compliance report (PCIR), and organized (Security Metrics) Metricon 2011. Now that is one risky dude!</p>
<p><strong>04. <a href="http://www.topheavysecurity.com/">Michelle Klinger</a> (<a href="https://twitter.com/diami03">@diami03</a>)<br />
</strong></p>
<p style="text-align: center;"><img class="wp-image-719 alignnone" style="border: 5px solid black; margin: 5px;" title="klinger" src="http://chaordicmind.com/blog/wp-content/uploads/2011/12/klinger-271x300.jpg" alt="" width="217" height="240" /></p>
<p>Michelle may like infosec as much as she likes cats &#8211; and that&#8217;s saying something.  She co-organized BSidesDFW two years in a row.  She is an excellent cat herder who never likes the lime-lite but always does what it takes to get things done.  She has sarcasm and charm to spare.  In 2011 she was nominated for an RSA Blogger award due to her post, <a href="http://topheavysecurity.com/2010/12/13/securitybsides-turned-me-into-an-adult/">Security B-Sides Turned Me into an Adult</a>.</p>
<p><strong>03. <a href="http://quietcontent.com/blog">Kyle Creyts</a> (<a href="https://twitter.com/hushedfeet">@hushedfeet</a>)<br />
</strong></p>
<p style="text-align: center;"><a href="http://chaordicmind.com/blog/wp-content/uploads/2012/01/kyle.jpg"><img class="wp-image-726 alignnone" style="border: 5px solid black; margin: 5px;" title="kyle" src="http://chaordicmind.com/blog/wp-content/uploads/2012/01/kyle-267x300.jpg" alt="" width="267" height="300" /></a></p>
<p>In a DO-ocracy Kyle would be King (or close to it).  Kyle is founder of BSidesDetroit, an event he started to bring together people in the greater Detroit to Ann Arbor area.  At a youthful age he stood up a conference in one of the most diaspora cities and created a conflagration of like minded people.</p>
<p><strong>02. <a href="https://www.eff.org/about/staff/marcia-hofmann">Marcia Hofmann</a> (<a href="https://twitter.com/marciahofmann">@marciahofmann</a>)</strong></p>
<p style="text-align: center;"><strong><img class="wp-image-720 alignnone" style="border: 5px solid black; margin: 5px;" title="hofmann" src="http://chaordicmind.com/blog/wp-content/uploads/2011/12/hofmann-300x234.jpg" alt="" width="270" height="211" /><br />
</strong></p>
<p>Marcia is a Senior staff attorney at the Electronic Frontier Foundation (EFF) focusing on helping ensure that modern technology is used for liberation rather than control. She liaisons with hackers at security conferences and help guide them on how to proceed with sometimes sensitive topics. She has the legal perspective that every aspiring hacker needs.</p>
<p><strong>01. <a href="http://justmyopinionman.wordpress.com/">Joseph Sokoly</a> (<a href="https://twitter.com/jsokoly">@jsokoly</a>)<br />
</strong></p>
<p style="text-align: center;"><a href="http://chaordicmind.com/blog/wp-content/uploads/2012/01/joseph.jpg"><img class="wp-image-723 alignnone" style="border: 5px solid black; margin: 5px;" title="joseph" src="http://chaordicmind.com/blog/wp-content/uploads/2012/01/joseph-298x300.jpg" alt="" width="238" height="240" /></a></p>
<p>Joseph has been my &#8216;poster guy&#8217; for Security B-Sides.  In 12 months he took a presentation on how hard it is to break into the industry (BSidesAustin) to a followup on all the support he received (BSidesBoston) back to his home town and co-founded BSidesDFW.  I&#8217;ve always enjoyed out long one-on-one conversations about life, people, and leadership.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fchaordicmind.com%2Fblog%2F2012%2F01%2F01%2F3rd-annual-top-10-sexy-infosec-geeks-for-2011%2F&amp;title=3rd%20Annual%20Top%2010%20Sexy%20InfoSec%20Geeks%20for%202011" id="wpa2a_2"><img src="http://chaordicmind.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://chaordicmind.com/blog/2012/01/01/3rd-annual-top-10-sexy-infosec-geeks-for-2011/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Poems by silvi</title>
		<link>http://chaordicmind.com/blog/2010/02/13/poems-by-silvi/</link>
		<comments>http://chaordicmind.com/blog/2010/02/13/poems-by-silvi/#comments</comments>
		<pubDate>Sun, 14 Feb 2010 01:23:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[poems]]></category>
		<category><![CDATA[poetry]]></category>
		<category><![CDATA[secret]]></category>
		<category><![CDATA[serial killers]]></category>
		<category><![CDATA[silvi]]></category>

		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=304</guid>
		<description><![CDATA[Yesterday our friend Julie Michell, of CALIBER and ilivehere::sf, had her photos at Secession, a gallery/store event in the Mission.  We went and met a number of great people, one of which is the on-the-spot poet Silvi Alcivar.  She runs a portable business called The Poetry Store where she will create you a poem based [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" style="border: 5px solid black;" title="The Poetry Store" src="http://farm5.static.flickr.com/4011/4353305112_cf8dd71be1.jpg" alt="" width="158" height="210" />Yesterday our friend <a href="http://femmefotographie.com/">Julie Michell</a>, of <a href="http://calibersf.com">CALIBER</a> and <a href="http://iliveheresf.com/">ilivehere::sf</a>, had her photos at Secession, a gallery/store event in the Mission.  We went and met a number of great people, one of which is the on-the-spot poet Silvi Alcivar.  She runs a portable business called <a href="http://www.thepoetrystore.net/">The Poetry Store</a> where she will create you a poem based on a seed thought/word/idea from you.</p>
<p>She has a cute, red ROYAL typewriter that she types them out on and some great little accessories to put your poem in, ranging from message-in-a-bottle to picture frames.  I chatted with her a while and it turns out not only does she pop up at events around town but also does weddings.  She is forward thinking enough to keep a carbon (literally) copy of the poem in the hopes of eventually publishing a book of them in the future.</p>
<p>Since I&#8217;ve been watching the drama-turn-soap-opera <a href="http://www.sho.com/site/dexter/">Dexter</a> lately, I asked her to write me a poem about secret serial killers.  The following is what she created.</p>
<blockquote><p>in the night<br />
for mike</p>
<p>secret serial killers come out<br />
with the stars, catching glimpses<br />
of the moon on their knives. with<br />
more stealth than cheetahs<br />
they pierce the necks of their<br />
prey, a tiny imperceptible bite.</p>
<p>silvi<br />
2.12.10<br />
secession</p></blockquote>
<p>The best part of all is the nice, happy Little Rabbit paper, which looks strangely like Hello Kitty, that it&#8217;s typed on.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fchaordicmind.com%2Fblog%2F2010%2F02%2F13%2Fpoems-by-silvi%2F&amp;title=Poems%20by%20silvi" id="wpa2a_4"><img src="http://chaordicmind.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://chaordicmind.com/blog/2010/02/13/poems-by-silvi/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>New Directions for 2010</title>
		<link>http://chaordicmind.com/blog/2010/01/06/new-directions-for-2010/</link>
		<comments>http://chaordicmind.com/blog/2010/01/06/new-directions-for-2010/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 09:24:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[new year]]></category>

		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=279</guid>
		<description><![CDATA[I cannot deny the fact that 2009 was less than optimal, which I hear is Fedspeak for &#8220;oh yeah, it sucked but we got through it.&#8221;  In fact, more than getting through it we have found a rebirth and I&#8217;d like to share a few of those with you. New Blog. That&#8217;s right, I have [...]]]></description>
			<content:encoded><![CDATA[<p>I cannot deny the fact that 2009 was less than optimal, which I hear is <a href="http://www.businessweek.com/bwdaily/dnflash/mar2005/nf20050324_7926_db016.htm" target="_blank">Fedspeak</a> for &#8220;oh yeah, it sucked but we got through it.&#8221;  In fact, more than getting through it we have found a rebirth and I&#8217;d like to share a few of those with you.</p>
<ol>
<li><strong>New Blog.</strong> That&#8217;s right, I have a new blog wherein I write mostly personal information peppered with thoughts on the professional world around me.  My favorite sections are those no the topics of <a href="http://chaordicmind.com/blog/tag/becoming-fearless/">becoming fearless</a>, <a href="http://chaordicmind.com/blog/tag/becoming-immortal/" target="_blank">becoming immortal</a>, and the ever popular <a href="http://chaordicmind.com/blog/2009/12/28/top-10-sexy-infosec-geeks-of-2009/">sexy geeks post</a>.</li>
<li><strong>Security B-Sides.</strong> In 2009 we completed two BSides events: <a href="http://www.securitybsides.org/BSidesLasVegas01">BSidesLasVegas</a> and <a href="http://www.securitybsides.org/BSidesBay">BSidesBay</a>.  We are starting 2010 with plans for 4+ BSides events: <a href="http://www.securitybsides.org/BSidesSanFrancisco">BSidesSanFrancisco</a>, <a href="http://www.securitybsides.org/BSidesBoston">BSidesBoston</a>, <a href="http://www.securitybsides.org/BSidesLasVegas">BSidesLasVegas</a>, and <a href="http://www.securitybsides.org/BSidesAustin">BSidesAustin</a>.  This is just January.  There are many more plans ahead. BSides is brought to you by the <a href="http://chaordicmind.com/blog/2009/12/12/security-b-sides-bsidesbay-2009/">hard working people who make it happen</a>.</li>
<li><strong>New Job.</strong> I&#8217;ve taken a job that, for the first time, I can do from just about anywhere &#8211; not just in the US but anywhere around the globe.  That being the case, I am considering taking a page from the <a href="http://www.fourhourworkweek.com/">4 Hour Workweek</a> and taking this show on the road.  This year I have a rather lofty goal of ditching the home and living/working 1 month abroad in a country where the cost of living is less than San Francisco, which should not be too hard to find.</li>
<li><strong>New Column.</strong> I found out today that I&#8217;ll be writing a new column for a yet-unnamed magazine.  I need to prepare an editorial calendar and much more.  This is really a small part of a longer term goal of mine which is to write several books.  I have stalled at this in the past but plan on using this new opportunity to spur my ideas.</li>
<li><strong>New Conferences.</strong> I&#8217;m lucky/good enough to know some really amazing people.  This past year brought me to speak at <a href="http://ww2.itweb.co.za/events/securitysummit/2009/">ITWeb Security Summit</a> in South Africa wherein those fun <a href="http://www.sensepost.com/">Sensepost</a> guys enabled <a href="http://www.flickr.com/photos/volubis/3597654433/in/set-72157619805980287/">Hackers on Safari</a>.  I want this year to be another of <em>new events, places, and people</em>.  For the first time I&#8217;ll be presenting/attending <a href="http://www.shmoocon.org/">ShmooCon 2010</a> and hope to add many others to this list shortly.  (I hope to meet Heidi Potter and appreciate the <a href="http://video.google.com/videoplay?docid=4508649066074989965#">0wn the c0n</a> talk.)  Stay tuned here and on <a href="http://twitter.com/sfoak">twitter</a>.</li>
<li><strong>New Webmaster.</strong> I&#8217;ve taken the role of &#8220;webmaster&#8221; for the people I camp with (Barbie Death Camp and Wine Bistro) at <a href="http://www.burningman.com/">Burning Man</a>.  I uploaded <a href="http://www.flickr.com/photos/bdcwb">10 years of photos</a> to Flickr and got the blog going at <a href="http://barbiedeathcamp.com">barbiedeathcamp.com</a>.</li>
<li><strong>New Laptop?</strong> Ok, I&#8217;m getting small here, but I have been pining over a <a href="http://www.apple.com/macbookpro/">MacBook Pro</a> for quite some time.  The purchase was not in the stars for 2009 but I&#8217;m hoping this year will bring new possibilities. I actually don&#8217;t want one of the new <a href="http://www.google.com/search?q=apple+tablet">Apple Tablet</a> or <a href="http://www.google.com/search?q=netbook">netbook</a>.  Call me old fashion but I just want a sleek, unibody laptop.</li>
</ol>
<p>So let&#8217;s take a deep breath.  Take one last look back.  And plow ahead into the new year that lies before us.</p>
<p>Good luck and good night.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fchaordicmind.com%2Fblog%2F2010%2F01%2F06%2Fnew-directions-for-2010%2F&amp;title=New%20Directions%20for%202010" id="wpa2a_6"><img src="http://chaordicmind.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://chaordicmind.com/blog/2010/01/06/new-directions-for-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Becoming Fearless: Only after disaster can we be resurrected</title>
		<link>http://chaordicmind.com/blog/2009/09/17/becoming-fearless-only-after-disaster-can-we-be-resurrected/</link>
		<comments>http://chaordicmind.com/blog/2009/09/17/becoming-fearless-only-after-disaster-can-we-be-resurrected/#comments</comments>
		<pubDate>Fri, 18 Sep 2009 01:53:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=157</guid>
		<description><![CDATA[“Only after disaster can we be resurrected. It’s only after you’ve lost everything, that you’re free to do anything.” – Tyler Durden (Fight Club) Parents like to tell their children that bad things do not happen to good people.  When we grow up we learn this is not at all true.  In fact, people have [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>“Only after disaster can we be resurrected. It’s only after you’ve lost everything, that you’re free to do anything.”<br />
– Tyler Durden (Fight Club)</p></blockquote>
<p>Parents like to tell their children that bad things do not happen to good people.  When we grow up we learn this is not at all true.  In fact, people have been exploring why bad things happen to good people for centuries.  C.S. Lewis wrote an entire book on <em>The Problem of Pain</em>.</p>
<p>Only when you embrace that good/bad things are not directly related to good/bad people can you stop asking why and start planning your next steps.</p>
<p>In fact, bad times can be an opportunity to reinvent yourself.  When you are freed of the forces that bind you to your current path you are free to choose a new one.  Disaster can lead to despair or resurrection.  Where will it lead you?</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fchaordicmind.com%2Fblog%2F2009%2F09%2F17%2Fbecoming-fearless-only-after-disaster-can-we-be-resurrected%2F&amp;title=Becoming%20Fearless%3A%20Only%20after%20disaster%20can%20we%20be%20resurrected" id="wpa2a_8"><img src="http://chaordicmind.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://chaordicmind.com/blog/2009/09/17/becoming-fearless-only-after-disaster-can-we-be-resurrected/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>PCI DSS v1.2.1 &#8211; No PAN, No Cardholder Data</title>
		<link>http://chaordicmind.com/blog/2009/08/12/pci-dss-v1-2-1-no-pan-no-cardholder-data/</link>
		<comments>http://chaordicmind.com/blog/2009/08/12/pci-dss-v1-2-1-no-pan-no-cardholder-data/#comments</comments>
		<pubDate>Wed, 12 Aug 2009 22:16:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=93</guid>
		<description><![CDATA[The PCI SSC quietly released version 1.2.1 (July 2009) and some very minor wording changes.  The following is a list of those minor changes: Oct. 2008 &#124; v1.2 &#124;=&#62; To introduce PCI DSS v1.2 as “PCI DSS Requirements and Security Assessment Procedures,” eliminating redundancy between documents, and make both general and specific changes from PCI [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="https://www.pcisecuritystandards.org/" target="_blank">PCI SSC</a> quietly released <a href="https://www.pcisecuritystandards.org/security_standards/download.html?id=pci_dss_v1-2.pdf" target="_blank">version 1.2.1</a> (July 2009) and some <em>very minor</em> wording changes.  The following is a list of those minor changes:</p>
<ul>
<li>Oct. 2008 | v1.2 |=&gt; To introduce PCI DSS v1.2 as “PCI DSS Requirements and Security Assessment Procedures,” eliminating redundancy between documents, and make both general and specific changes from PCI DSS Security Audit Procedures v1.1. For complete information, see PCI Data Security Standard Summary of Changes from PCI DSS Version 1.1 to 1.2.&#8221;</li>
<li>July 2009 | v1.2.1 |=&gt; Add sentence that was incorrectly deleted between PCI DSS v1.1 and v1.2.</li>
<li>July 2009 | v1.2.1 |=&gt; Correct “then” to “than” in testing procedures 6.3.7.a and 6.3.7.b.</li>
<li>July 2009 | v1.2.1 |=&gt; Remove grayed-out marking for “in place” and “not in place” columns in testing procedure 6.5.b.</li>
<li>July 2009 | v1.2.1 |=&gt; For Compensating Controls Worksheet – Completed Example, correct wording at top of page to say “Use this worksheet to define compensating controls for any requirement noted as ‘in place’ via compensating controls.”</li>
</ul>
<p>So, pray tell what is that sentence incorrectly deleted?</p>
<blockquote><p><strong>PCI DSS requirements are applicable if a Primary Account Number (PAN) is stored, processed, or transmitted. If a PAN is not stored, processed, or transmitted, PCI DSS requirements do not apply.</strong></p></blockquote>
<p>This is a rather minor clarification.  Many people read the cardholder data matrix and think that all elements including the name and expiration date are considered cardholder data (CHD).  With this update from the PCI SSC we are reminded that these are only considered CHD if they are stored with the PAN.</p>
<p>Translation?  <strong>No PAN, no cardholder data!</strong></p>
<p>This leaves us with only one remaining question&#8230;</p>
<p>Now that we are completing the In Place / Not In Place areas for requirement 6.5.b, what are the necessary validation steps?  Perhaps documentation review, observation of process/action/state, and interview staff.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fchaordicmind.com%2Fblog%2F2009%2F08%2F12%2Fpci-dss-v1-2-1-no-pan-no-cardholder-data%2F&amp;title=PCI%20DSS%20v1.2.1%20%26%238211%3B%20No%20PAN%2C%20No%20Cardholder%20Data" id="wpa2a_10"><img src="http://chaordicmind.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://chaordicmind.com/blog/2009/08/12/pci-dss-v1-2-1-no-pan-no-cardholder-data/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 3.135 seconds -->

