thePCI Portal

Category: Assessments

Travel Agent PCI DSS Deadline June 1 2017 UPDATE! EXTENSION FROM IATA

The countdown is on for IATA Accredited Agents to be Payment Card Industry (PCI) Data Security Standard (DSS) compliant by June 1, 2017 IATA has issued the deadline to reduce the risks associated with payment card transactions and potential data breaches and made PCI DSS compliance a mandatory condition to obtain and retain accreditation as an…

SharePoint users rejoice

It seems like PCI Assessments and large SharePoint file repositories go hand in hand.  I am sure we have all learned a SharePoint trick or two like: How to open SharePoint sites in file explorer for easy file manipulation. Mapping a drive to a SharePoint site. Using Microsoft’s agent to synch a SharePoint site locally.…

Whats the 411 on section 4.11 Managed Service Provider?

While completing a version 3.2 PCI DSS assessment, you will eventually get to section 4.11 titled Managed service providers.  (the section formerly known as 4.12 in version 3.1) Presuming that the assessed entity is a service provider, what constitutes a “managed” service provider? Section 4.11 does not shed much light on the topic.  Time to…

the Council Plans to Publish Scoping Guidance!

The latest news update for QSA’s includes news of an upcoming holiday gift for those in the PCI DSS world! The Security Standards Council plans to publish “Guidance for PCI DSS Scoping and Network Segmentation.”  in December 2016.  The Council informs that the guidance “aims to clarify scoping and segmentation principles provided in the PCI DSS”.…

Don’t descope your redirecting ecommerce web server!

Another fresh article regarding the risks to consider when implementing a fully redirected e-commerce solution.  Benj Hosack writes about something the forensics team at Foregenix have seen.  While it discusses a few variants that are not specifically of the SAQ A variety, it has a few relevant examples of risks. And don’t forget about the old paypaul.ca…