PCI AND COMPLIANCE Articles
Deep theater defense
We all know perimeter firewalls are necessary but not sufficient. But what's the right strategy for building additional layers of security? Greg Machler dives in.
Claiming PCI or any other compliance - daily
Are you really PCI compliant? Or just PCI certified? There is a difference, according to Michael Gough.
13 essential steps to integrating control frameworks
How to merge multiple regulatory requirements under a rational, effective security and controls governance process
Heartland ramps up first end-to-end encryption
Heartland Payment Systems vowed to develop new security gear based on end-to-end encryption between itself and its merchants. That's now taking shape, but slowly.
Study: Advanced threats a growing problem for security
Research from Ponemon Institute finds more security managers are seeing advanced threats, but few feel they have the support and technology to deal with them
Security group stretching payment-card standards cycle to three years
The Payment Card Industry Security Standards Council Tuesday announced it will begin moving to a three-year cycle related to the main technical standards it issues for protection of sensitive payment-card information, allowing merchants and others more time to adopt them.
Data Protection: EnergySec's plan for critical infrastructure
Energy companies rely on IT infrastructure more than ever. Would-be cyber terrorists know it. A group called EnergySec hopes to be ready for what may come.
Study: Cost of data breach in U.S. is highest world wide
A global study of data breach costs conducted by the Ponemon Institute finds notification laws have dramatic impact on the price tag
Security pros, meet your new best friend
Executives in charge of information security should make friends with the CFO, who can give them a broad overview of corporate priorities and see to funding the most important IT projects that protect corporate data.
SaaS, Security and the Cloud: It's All About the Contract
Security practitioners have learned the hard way that contract negotiations are critical if their SaaS, cloud and security goals are to work. A report from CSO Perspectives and SaaScon 2010.
