<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!-- SwishCommand noindex -->
<rss version="2.0">
<channel>
  <title>ComplianceHome: PCI Resources</title>
  <link>http://www.compliancehome.com/</link>
  <description>ComplianceHome is one of the Web's largest library of resources for compliance management of HIPAA, SOX, FISMA, GLBA, FDA, FFIEC, Basel II, OSHA and ISO 27002/17799. Visit our directories which are the best source on White papers, related news articles, resources on the web, training, webinars, conferences, rules &amp; regulation overview, ask the expert, job and search on vendors, solutions &amp; products.</description>
<image>
  <url>http://www.compliancehome.com/images/rsslogo.gif</url>
  <title>ComplianceHome</title>
  <link>http://www.compliancehome.com/</link>
</image>
  <language>en-us</language>
  <item>
    <title>Detecting Abnormal Technology Systems Behavior</title>
    <pubDate>Mon, 05 Jul 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18994.html</link>
    <description>With hundreds and thousands of automated systems producing log data, an organization's ability to respond to</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18994.html</guid>
  </item>
  <item>
    <title>Achieve Both PCI Compliance &amp; Web Security</title>
    <pubDate>Mon, 05 Jul 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18992.html</link>
    <description>View this on-demand Webcast from Akamai and featured analyst firm Gartner</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18992.html</guid>
  </item>
  <item>
    <title>Helpful Ways to Pass Your Payment Card Industry Audit</title>
    <pubDate>Fri, 18 Jun 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18989.html</link>
    <description>For organisations that store, transmit or process credit card information, it is vital as they must be able to demonstrate compliance with the Payment Card Industry Data Security Standards (PCI DSS). The PCI DSS standard attempts to protect consumers while safeguarding the reputation of the industry itself and, while not a government mandate, this industry initiative has rapidly become compulsory for any merchant wishing to transact with the major credit card companies. With every company reliant on software to run its business, an alarming rise in data breach incidents across industries, but especially credit card processing, means application security is becoming an increasingly critical part of any organisations overall IT security strategy.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18989.html</guid>
  </item>
  <item>
    <title>Ways To Pass your Payment Card Industry Audit</title>
    <pubDate>Fri, 18 Jun 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18982.html</link>
    <description>With every company reliant on software to run its business, an alarming rise in data breach incidents across industries, but especially credit card processing, means application security is becoming an increasingly critical part of any organisations overall IT security strategy. For organisations that store, transmit or process credit card information, it is vital as they must be able to demonstrate compliance with the Payment Card Industry Data Security Standards (PCI DSS). The PCI DSS standard attempts to protect consumers while safeguarding the reputation of the industry itself and, while not a government mandate, this industry initiative has rapidly become compulsory for any merchant wishing to transact with the major credit card companies. By being able to demonstrate and sustain compliance, the industry as a whole is signalling to the public that they have efficient and effective processes that assure the security of payment software. However, not all organisations are able to d</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18982.html</guid>
  </item>
  <item>
    <title>Making PCI Compliance Simpler for Data Security</title>
    <pubDate>Fri, 18 Jun 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18981.html</link>
    <description>Incase your business accepts credit or debit payments, its likely that youre required to comply with the Payment Card Industry Data Security Standard. PCI DSS was created in 2006 to establish minimum data security measures for organizations around the world that hold, process, or exchange cardholder information from any of the major card brands. These security measures are reviewed and revised on a rotating two-year schedule to be sure they remain adequate in protecting sensitive data.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18981.html</guid>
  </item>
  <item>
    <title>PCI - It's Not Quite Everywhere It Should Be</title>
    <pubDate>Fri, 18 Jun 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18971.html</link>
    <description>be a part of this webinar to learn about critical technologies that can assist your PCI compliance efforts. We will discuss how to: Protect critical data from leaving your enterprise through malicious hackers and/or employee mistakes, Go beyond intrusion detection and prevention to a positive, proactive, security model that protects against new email and web-borne attacks, Safely enable remote employees, partners, contractors and other third parties to authenticate and access pertinent information, Implement security measures that ensure simultaneous compliance with PCI, SOX, GLBA, HIPAA and other privacy and data protection regulations</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18971.html</guid>
  </item>
  <item>
    <title>Payment Card Security Market Trends</title>
    <pubDate>Fri, 18 Jun 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18970.html</link>
    <description>The Heartland Payment Systems data breach has been the information security story of the year. And it's shined a bright spotlight on the Payment Card Industry Data Security Standard (PCI DSS) - and the question</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18970.html</guid>
  </item>
  <item>
    <title>Questions on the Efficiency of PCI DSS</title>
    <pubDate>Fri, 18 Jun 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18949.html</link>
    <description>There seems to be much debate ongoing these days regarding the effectiveness of PCI DSS. There have been several high profile cases such as Heartland and RBS WorldPay where these companies had PCI DSS certification, yet still suffered card data breaches.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18949.html</guid>
  </item>
  <item>
    <title>PCI: The Risks And The Opportunities For VARs</title>
    <pubDate>Tue, 25 May 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18941.html</link>
    <description>For anyone supplying merchants with hardware, software, or services, the Payment Card Industry Data Security Standard (PCI DSS) represents both a profound challenge and a major opportunity. Vendors and resellers who position themselves correctly can see PCI as driving a universal technology refresh and creating new demand for hardware, software, and services. Those who move too slowly will find their world turned upside down, with their merchants asking completely new questions, demanding new types of solutions, or literally being forced to move their business to other solutions providers.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18941.html</guid>
  </item>
  <item>
    <title>Significant Corporate Compliance Challenges for Financial Services Firms</title>
    <pubDate>Tue, 25 May 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18935.html</link>
    <description>With data security breaches continuing to make the news, legislatures and regulators are focusing their attention on enforcing data protection. This has meant fines, law suits, and lost customers for businesses involved. As a result, new data breach notification laws and the codification of industry specific standards has made compliance with data protection rules a top priority for financial services firms in 2010. And with continuing political pressure, its only certain that compliance requirements will become even more stringent.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18935.html</guid>
  </item>
  <item>
    <title>Mixed Reviews for PCI Update</title>
    <pubDate>Tue, 25 May 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18933.html</link>
    <description>The new point of sale standard released by the PCI Security Standard Council receives mixed reactions from industry security experts. The revised standard is meant to enhance and prevent payment card fraud on devices that accept payment transactions, and will cover everything from retail point of sale card readers to unattended payment terminals at gas stations and parking lots. But does the standard go far enough to secure the merchant endpoint?</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18933.html</guid>
  </item>
  <item>
    <title>Two technologies--end-to-end encryption and tokenization to protect credit-card data</title>
    <pubDate>Tue, 25 May 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18930.html</link>
    <description>PCI and Security pros have a different kind of relationship. On one hand, the standard compels management to invest in security and mandates operational best practices. Failure to toe the line can result in fines and penalties, including increased costs for credit card transactions. Visa, MasterCard, and other card brands could go so far as to revoke a company's right to process cards, effectively killing the business.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18930.html</guid>
  </item>
  <item>
    <title>Certification program for IT staff launched by PCI council</title>
    <pubDate>Mon, 03 May 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18917.html</link>
    <description>A new program to help enterprises conduct self-assessments of their compliance with the standard has been launched by Computerworld - The organization responsible for administering the Payment Card Industry Data Security Standard (PCI DSS). The PCI Security Standards Council LLC, which was set up by Visa, MasterCard, American Express and other credit card companies, today announced a new Internal Security Assessors (ISA) program for merchants and processors covered by the standard.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18917.html</guid>
  </item>
  <item>
    <title>Dropping costs and complexity of PCI DSS compliance</title>
    <pubDate>Mon, 03 May 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18915.html</link>
    <description>YESpay International, in partnership with ITIM, has added Trago Mills and The Entertainer amongst many other major high-street retailers to its managed card payment service leading to significant reduction in costs and PCI DSS compliance. Historically these retailers have had their own in-house card payment solution, before PCI-DSS (Payment Card Industry Data Security Standard) and EMV (Europay, Visa and MasterCard) Chip &amp; PIN standards were mandated by their Card Acquirers. Like Trago Mills and The Entertainer, many major retailers are switching to the YESpay EMBOSS card payment service in order to achieve significant CAPEX and operational cost reductions of up to 40% and also to minimise PCI DSS compliance risk.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18915.html</guid>
  </item>
  <item>
    <title>Ways to Secure Your On-line Booking Website</title>
    <pubDate>Wed, 28 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18912.html</link>
    <description>Securing your on-line booking website is critical to the safety of your transactions and your customer data.  Whether you are planning to create your own booking form or you are going to use a web-based tour operator reservation system, you need to know what to look for to protect your business from potential security and credit card theft, and the hefty fines which may result.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18912.html</guid>
  </item>
  <item>
    <title>PCI Burden Eliminated by Hosted Order Automation</title>
    <pubDate>Wed, 28 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18906.html</link>
    <description>Vindicia,which offers an on-demand strategic billing solution, announced the availability of its new Hosted Order Automation capabilities as part of the Vindicia CashBox solution. By using HOA in CashBox, online merchants can offload PCI compliance to Vindicia while maintaining complete control over their customers buying experience.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18906.html</guid>
  </item>
  <item>
    <title>Rapid7's NeXpose Vulnerability Assessment Solution Included by Datapipe in PCI DSS Solution</title>
    <pubDate>Wed, 28 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18905.html</link>
    <description>A provider of managed hosting and security services, Datapipe,announced that it has entered into a contract with Rapid7 for using its Vulnerability Assessment solution NeXpose as part of its managed security services and PCI DSS compliance solution.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18905.html</guid>
  </item>
  <item>
    <title>New Version of Service Provider Offering Launched by Parallels</title>
    <pubDate>Wed, 28 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18904.html</link>
    <description>Parallels has launched a new version of its service provider offering Plesk Panel. Version 9.5 offering a range of new services, including Google Services for Websites, PCI compliance, support of most virtualisation platforms, and a smattering of self-diagnostic tools.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18904.html</guid>
  </item>
  <item>
    <title>Sheetz Assisted by Accuvant  to Protect Data and Improve PCI Compliance</title>
    <pubDate>Wed, 28 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18903.html</link>
    <description>Accuvant, a provider of research-driven information security solutions that deliver alignment, clarity and confidence to enterprise clients, has announced that the company has provided remote access IT management and Web filtering solutions to Sheetz, a family-owned convenience store chain.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18903.html</guid>
  </item>
  <item>
    <title>Implementing Least-Privilege Security Management in Complex Linux and UNIX Environments</title>
    <pubDate>Wed, 21 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18890.html</link>
    <description>Virtually all government and private security regulations, such as Sarbanes-Oxley and the Payment Card Industrys Data Security Standard, have a few common requirements: that access to sensitive data and servers be granted only to those whose job function requires it, and that those individuals are granted only the privileges they need to perform their duties. This least-privilege security model has obvious merits in theory, but in practice it can be challenging to implement, particularly in Linux and UNIX environments, where it is still all too common for administrators to share passwords to root or other superuser accounts. How, for example, do you give backup administrators the superuser privilege to copy a database and move it to another volume without giving them access to the database itself? While sudo and other tools provide some help, they can be cumbersome to manage and implement and become unworkable in complex environments with hundreds of heterogeneous servers and multip</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18890.html</guid>
  </item>
  <item>
    <title>The PCI Paradox - why PCI DSS isn't preventing data breaches</title>
    <pubDate>Wed, 21 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18889.html</link>
    <description>PCI DSS has been criticized as being both too prescriptive and too vague. The standards effectiveness has come under scrutiny once again as PCI compliant organizations have suffered huge data breaches in recent times. Danny Bradbury looks at the standard to find the root of the problem</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18889.html</guid>
  </item>
  <item>
    <title>Additional data breach measure passed by Washington</title>
    <pubDate>Wed, 21 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18888.html</link>
    <description>A supplemental data breach law intended to protect financial institutions from data breaches that occur as a result of negligence by businesses or card processors, primarily those that do not encrypt card data or fail to comply with PCI DSS rules is recently passed by the state of Washington .</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18888.html</guid>
  </item>
  <item>
    <title>A Collected Approach to PCI Compliance for Small Merchants</title>
    <pubDate>Wed, 21 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18886.html</link>
    <description>As smaller merchants struggle with data-security requirements set by the bank card networks, some security firms are working on ways to simplify compliance. An example is Panoptic Security Inc., a Salt Lake City, Utah-based company that distributes its software through independent sales organizations and acquiring banks. It has started talking to point-of-sale terminal and software firms about integrating that software with their systems.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18886.html</guid>
  </item>
  <item>
    <title>Addressing Cloud Security Challenges with Identity Management</title>
    <pubDate>Fri, 09 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18870.html</link>
    <description>Increasingly, organizations are turning to cloud computing to realize its promise of better cost-efficiency, IT agility, time-to-value and simplicity. But security, regulatory compliance and vendor lock-in are rated among the top barriers to the adoption of cloud computing. Enabling cloud computing in the enterprise to be secure and compliant with both internal controls and industry regulations requires a solid architectural foundation.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18870.html</guid>
  </item>
  <item>
    <title>Best Practices in Higher Ed Security Assessments: Virginia Techs IT Security Review Process</title>
    <pubDate>Fri, 09 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18869.html</link>
    <description>With responsibility for the private data of thousands of students, faculty, staff and alumni, its no wonder that Virginia Polytechnic Institute counts information security as one of its top priorities. Leading the ongoing effort to assess security across the universitys 180+ departments is Randy Marchany, director of the VA Tech IT Security Lab. Please join Core Security for a best practices webcast where Marchany will share his insights from Virginia Techs proven IT Security Review process, which includes the proactive replication of threats originating from both inside and outside the university.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18869.html</guid>
  </item>
  <item>
    <title>Protecting Sensitive Data: Detecting and Blocking Unauthorized Access or Changes</title>
    <pubDate>Fri, 09 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18863.html</link>
    <description>In 2009, databases were the number one source of breached records globally.  Databases are an attractive target, containing organizations' most sensitive data, including financial records, credit card information and customer data.  It is also the reason they are increasingly subject to regulations such as SOX, PCI DSS and the EU Data Privacy Directive.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18863.html</guid>
  </item>
  <item>
    <title>Responsibilities of Data Center and Merchant or Service Pro</title>
    <pubDate>Fri, 09 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18847.html</link>
    <description>Potential data center customers often ask data center operators if they are PCI Compliant. There has been some confusion surrounding the answer to this question. Data center providers normally do not have anything to do with their customers sensitive information handling procedures. To clarify and answer the PCI question, lets discuss the responsibilities of the data center and the responsibilities of the merchant or service provider.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18847.html</guid>
  </item>
  <item>
    <title>Secure Hosting Environment for Cardholder Data to be Offered by PCI Compliant Codero</title>
    <pubDate>Fri, 09 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18846.html</link>
    <description>Codero specializes in dedicated and managed hosting services for small- to mid-sized business. Coderos technology portfolio includes high-performance Windows and Linux servers delivering advanced email, eCommerce, security and networking solutions. Codero has announced that the company has met all the requirements of the Payment Card Industry Data Security Standard. The company has proactively decided to manage risks and minimize exposure by meeting the global data security standards. PCI compliance was achieved through a comprehensive review of its data center infrastructure which included networks, web applications, operating systems and other services to assess account data security.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18846.html</guid>
  </item>
  <item>
    <title>PCI Compliance - Learn Everything You Need To Know</title>
    <pubDate>Fri, 09 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18842.html</link>
    <description>Join this ondemand webinar in which the Burton Groups Diana Kelley will provide you with an overview of PCI as well as advice on avoiding common PCI pitfalls to avoid costly penalties.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18842.html</guid>
  </item>
  <item>
    <title>True Cost of Failing PCI Compliance</title>
    <pubDate>Fri, 09 Apr 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18841.html</link>
    <description>While PCI deadlines have come and gone, many leading retail companies have taken aggressive steps to adopt each requirement. These companies have realized the true cost of failing a PCI audit isn't just a fine, but an increase in risk for a major data breach. The presenter will discuss how to assess the risk, what are the recent data breaches, and how to analyze the costs and benefits of failing PCI Compliance.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18841.html</guid>
  </item>
  <item>
    <title>Data Breaches On Increase at Hotels .</title>
    <pubDate>Thu, 18 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18800.html</link>
    <description>Hotels are now the main target of the hackers stealing credit-card data than any other industry, according to data-security companies. In a recent report, SpiderLabs, a unit of data-security firm Trustwave, said 38% of its data-breach investigations in 2009 occurred at hotels. Financial services accounted for 19% of the company's data-breach investigations. Once an attack occurred, it took an average of 156 days for the business to realize it, according to the report. The problem has continued into 2010, says Nicholas Percoco, senior vice president of Trustwave and head of SpiderLabs.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18800.html</guid>
  </item>
  <item>
    <title>PCI DSS is Not to Blame</title>
    <pubDate>Wed, 17 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18794.html</link>
    <description>PCI DSS is blamed by many payment processing industry players for leading organisations to prioritize compliance instead of security. However, the PCI DSS is not to blame, as there is no such thing as complete security, said a recent article. According to PCI Guru, organisations should not expect full protection from payment processing security threats under the PCI DSS - or under anything else, for that matter, as even the most thorough security measures do not eliminate risk.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18794.html</guid>
  </item>
  <item>
    <title>The Guide to PCI and the Art of the Compensating Control</title>
    <pubDate>Wed, 17 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18793.html</link>
    <description>Few payment security professionals can find a hotter PCI DSS topic than compensating controls. They always look like this mythical accelerator to compliance used to push PCI Compliance initiatives through completion at a minimal cost to your company with little or no effort. Compensating controls are challenging. They often require a risk-based approach that can vary greatly from one Qualified Security Assessor (QSA) to another. There is no guarantee a compensating control that works today will work one year from now, and the evolution of the standard itself could render a previous control invalid.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18793.html</guid>
  </item>
  <item>
    <title>Tokenization Success Story</title>
    <pubDate>Mon, 15 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18792.html</link>
    <description>Tune in to this Tokenization webcast where well discuss the business drivers behind tokenization, exactly what tokenization is, some best practices for a successful implementation, and lastly, a customer example of tokenization used to reduce the PCI DSS audit scope.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18792.html</guid>
  </item>
  <item>
    <title>QualysGuard PCI Web Application Scanning Demonstration</title>
    <pubDate>Mon, 15 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18787.html</link>
    <description>QualysGuard PCI 3.0 Web Application Scanning module is an automated tool for evaluating Web applications before and after deployment. This 10 minute demonstration is available on demand and includes a brief Abstract of the product along with a detailed walkthrough of the new features.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18787.html</guid>
  </item>
  <item>
    <title>Winning the PCI Compliance Battle - Best Practices to Manage the PCI Process</title>
    <pubDate>Mon, 15 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18786.html</link>
    <description>Speaker: Terry Ramos, Director Strategic Development, Qualys The Payment Card Industry Security Data Standard, or PCI, protects cardholders and businesses by establishing standard practices for processing, storing and transmitting credit card data but thefts still occur at an unprecedented rate. This webcast will explore: * Compliance Requirements of the PCI Data Security Standard * Participation and Validation Requirements * Selecting a PCI Network Security Testing Service * Automating the PCI Validation Process with QualysGuard PCI</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18786.html</guid>
  </item>
  <item>
    <title>Ways to Reduce Security Risks Associated with Storing Credit Card Data</title>
    <pubDate>Mon, 15 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18784.html</link>
    <description>Companies that follow best practices in data security have a risk assessment program. As outlined by the United States General Accounting Office (GAO), risk assessments</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18784.html</guid>
  </item>
  <item>
    <title>Architecting PCI DSS compliance with encryption, tokenization, and key management - Vendor Webcast</title>
    <pubDate>Tue, 09 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18780.html</link>
    <description>Securing cardholder data is not just about passing annual PCI DSS audits. It can mean a big difference in the cost of audits and the amount of effort needed for ongoing compliance. Research conducted by PriceWaterhouseCoopers found encryption and tokenization to be among the most promising technologies to reduce the scope of PCI DSS audits  saving time and money. However, depending on your key management architecture and implementation, you could be spending too much time maintaining compliance or, even worse, not meeting the PCI DSS requirements for scope reduction.  Covered by PCI DSS requirements 3.4 to 3.6, key management is a critical element in a cardholder data protection strategy.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18780.html</guid>
  </item>
  <item>
    <title>PCI DSS logging, an essential for compliance</title>
    <pubDate>Tue, 09 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18776.html</link>
    <description>The PCI DSS continues its march from the largest to the smallest merchants, affecting the way thousands of organizations approach security. PCI DSS applies to all organizations that handle credit-card transactions or that store or process payment-card data.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18776.html</guid>
  </item>
  <item>
    <title>Architecting PCI DSS compliance with encryption, tokenization, and key management</title>
    <pubDate>Tue, 02 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18774.html</link>
    <description>ABSTRACT: Securing cardholder data is not just about passing annual PCI DSS audits. It can mean a big difference in the cost of audits and the amount of effort needed for ongoing compliance. Research conducted by PriceWaterhouseCoopers found encryption and tokenization to be among the most promising technologies to reduce the scope of PCI DSS audits  saving time and money. However, depending on your key management architecture and implementation, you could be spending too much time maintaining compliance or, even worse, not meeting the PCI DSS requirements for scope reduction.  Covered by PCI DSS requirements 3.4 to 3.6, key management is a critical element in a cardholder data protection strategy.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18774.html</guid>
  </item>
  <item>
    <title>To seed cloud growth its essential to implement Cloud security standards</title>
    <pubDate>Tue, 02 Mar 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18772.html</link>
    <description>IEEE, a professional association for the advancement of technology, and the Cloud Security Alliance (CSA), a not-for-profit organization formed to promote the use of best practices for providing security assurance within cloud computing, have announced results of a survey of IT professionals that reveals overwhelming agreement on the importance and urgency of cloud computing security standards.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18772.html</guid>
  </item>
  <item>
    <title>The Movement to Virtualization: Nemertes Research and Altor Networks on Cloud Security</title>
    <pubDate>Wed, 24 Feb 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18765.html</link>
    <description>Nemertes Research is a research advisory firm that specializes in the business impact of emerging technologies. They have been tracking the trends in virtualization since about 2005, and have been looking at the phenomenon emerge with enormous speed. Watch this webinar, with Nemertes Research and Altor Network, and learn about the trends of moving to virtualization, dynamics of the cloud, security challenges virtualization gives us, issues of compliance, and why existing solutions dont really fulfill the needs of the enterprise.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18765.html</guid>
  </item>
  <item>
    <title>Ways to Implement Secure, PCI-Compliant Access Controls</title>
    <pubDate>Wed, 24 Feb 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18763.html</link>
    <description>Many legacy systems are simply not aligned with current business needs. Many offer limited value in today's dynamic business and regulatory environment. Next-generation access solutions evolved from the need to manage a smaller group of high-performing or trusted users such as database administrators, users accessing credit card data, external auditors working remotely, and outsourced or other business partners.Many legacy systems are simply not aligned with current business needs. Many offer limited value in today's dynamic business and regulatory environment. Next-generation access solutions evolved from the need to manage a smaller group of high-performing or trusted users such as database administrators, users accessing credit card data, external auditors working remotely, and outsourced or other business partners.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18763.html</guid>
  </item>
  <item>
    <title>Retailers can be Helped by IT GRC systems to manage PCI compliance, reduce costs</title>
    <pubDate>Wed, 24 Feb 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18762.html</link>
    <description>With the requirements of payment processing security changing constantly, it can be difficult for merchants to keep up. Yet the consequences for not keeping up can be catastrophic - payment processing breaches can be tremendously expensive</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18762.html</guid>
  </item>
  <item>
    <title>Experts donot agree over security breach cause, solutions</title>
    <pubDate>Wed, 24 Feb 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18759.html</link>
    <description>More than a year after 100 million credit card numbers were stolen from Heartland Payment Systems, two industry experts disagreed over who was at fault. This information is currently protected by the Payment Card Industry Security Standards Council, which sets 12 specific goals to build and maintain secure networks. Compliance with PCI standards is mandatory for all companies storing or processing payment card identification. Heartland executives originally said they were compliant, but later disclosed that assessors incorrectly informed the company. In a report by NetworkWorld, Lieberman Software CEO Phil Lieberman said improved payment technology could be used to prevent future security breaches, which can be devastating to consumers' credit scores. This smart card technology would remove liability from merchants and processors, while minimizing card cloning.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18759.html</guid>
  </item>
  <item>
    <title>Chief Breaches and Blunders of 2009</title>
    <pubDate>Sun, 14 Feb 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18754.html</link>
    <description>From stolen devices and phishing attacks to buggy apps and human blunders, 2009 was another banner year for data breaches. According to the Privacy Rights Clearinghouse, over 345 million records containing sensitive data have been involved in incidents within the United States since January 2005. But last year, one single breach compromised 130 million records. In an effort to do better this year, let's recount some of the worst data breaches reported in 2009.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18754.html</guid>
  </item>
  <item>
    <title>Juniper Networks High-Performance Security Solutions Chosen by Tim Hortons</title>
    <pubDate>Sun, 14 Feb 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Articles/abstract18753.html</link>
    <description>One of North America's largest quick-service restaurant chains, Tim Hortons, reportedly has selected and deployed solutions from Juniper Networks security network infrastructure portfolio. Due to this deployment, Tim Hortons would now be able to connect more than 3,000 stores across Canada and the United States with the ability to support Payment Card Industry (PCI (News - Alert)) compliance, provide business continuity and transfer high volumes of information through a fast and secure environment for its business operations and retail transactions.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Articles/abstract18753.html</guid>
  </item>
  <item>
    <title>PCI Compliant Yesterday. Still Compliant Today?</title>
    <pubDate>Sun, 14 Feb 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18743.html</link>
    <description>This webcast talks about the need for automated solutions in Payment Card Idustry Data Security Standards compliance. Topics covered in this webcast include: Why PCI compliance is necessary, PCI DSS: Checklist vs. Best Practice, PCI compliance best practices.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18743.html</guid>
  </item>
  <item>
    <title>Better Security Through the PCI Data Security</title>
    <pubDate>Sun, 14 Feb 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18742.html</link>
    <description>The presenters walk through the basic tenets of the Payment Card Industry (PCI) data security standard, some misconceptions and the best way to tackle PCI compliance. For merchants of all levels, this webcast discusses how to protect credit card data and proactively detect vulnerabilities.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18742.html</guid>
  </item>
  <item>
    <title>Centrify Security Solutions for PCI Compliance</title>
    <pubDate>Sun, 14 Feb 2010 00:00:00 CST</pubDate>
    <link>http://www.compliancehome.com/resources/PCI/Webinars/abstract18741.html</link>
    <description>The attendee of this webcast will learn how Centrify helps corporate IT security managers address the key provisions of Sections 7, 8 and 10 of the PCI Data Security Standard for their UNIX and Linux systems.</description>
    <guid isPermaLink="false">http://www.compliancehome.com/resources/PCI/Webinars/abstract18741.html</guid>
  </item>
</channel>
</rss>
