<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.0.4" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Volubis - PCI DSS Compliance Experts</title>
	<link>http://www.volubis.com</link>
	<description>PCI and Data Security Compliance</description>
	<pubDate>Wed, 13 Jun 2007 05:51:59 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.4</generator>
	<language>en</language>
			<item>
		<title>Volubis acquired by The Aegenis Group</title>
		<link>http://www.volubis.com/2007/06/12/volubis-acquired-by-the-aegenis-group/</link>
		<comments>http://www.volubis.com/2007/06/12/volubis-acquired-by-the-aegenis-group/#comments</comments>
		<pubDate>Wed, 13 Jun 2007 05:51:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
	<category>PCI DSS</category>
		<guid isPermaLink="false">http://www.volubis.com/2007/06/12/volubis-acquired-by-the-aegenis-group/</guid>
		<description><![CDATA[We are happy to inform you that Volubis has been acquired by The Aegenis Group.  This combined force enables for a stronger approach towards all the services we once offered and extends them further.  Check out The Aegenis Group and what we can now offer.
The Aegenis Group is dedicated to helping companies navigate the choppy [...]]]></description>
			<content:encoded><![CDATA[<p>We are happy to inform you that Volubis has been acquired by <a href="http://aegenis.com/"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/aegenis.com');">The Aegenis Group</a>.  This combined force enables for a stronger approach towards all the services we once offered and extends them further.  Check out The Aegenis Group and what we can now offer.</p>
<blockquote><p>The Aegenis Group is dedicated to helping companies navigate the choppy waters of data security, information risk, and privacy regulation. The Aegenis Group believes that the ability to understand not just the regulatory mandates themselves, but their total impact on the business environment can act as a compelling tool for business enablement. From understanding the ways in which your products and services can protect sensitive data to making the right compliance decisions for your business environment, The Aegenis Group can assist your company in facing the risks associated with an increasingly complex landscape of the business world.</p></blockquote>
<!-- Social Bar BEGIN --><p style="padding-top:5px;"><span style="display:block;margin-left:auto;margin-right:auto;text-align:center;"><em>Bookmark to:</em><br /><a href="http://del.icio.us/post?url=http://www.volubis.com/2007/06/12/volubis-acquired-by-the-aegenis-group/&title=Volubis acquired by The Aegenis Group"target="_blank"  title="Add 'Volubis acquired by The Aegenis Group' to Del.icio.us" onclick="javascript:urchinTracker ('/outbound/article/del.icio.us');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/delicious.png" title="Add 'Volubis acquired by The Aegenis Group' to Del.icio.us" alt="Add 'Volubis acquired by The Aegenis Group' to Del.icio.us" /></a>&nbsp;<a href="http://digg.com/submit?phase=2&amp;url=http://www.volubis.com/2007/06/12/volubis-acquired-by-the-aegenis-group/&title=Volubis acquired by The Aegenis Group"target="_self"  title="Add 'Volubis acquired by The Aegenis Group' to digg" onclick="javascript:urchinTracker ('/outbound/article/digg.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/digg.png" title="Add 'Volubis acquired by The Aegenis Group' to digg" alt="Add 'Volubis acquired by The Aegenis Group' to digg" /></a>&nbsp;<a href="http://furl.net/storeIt.jsp?t=Volubis acquired by The Aegenis Group&amp;u=http://www.volubis.com/2007/06/12/volubis-acquired-by-the-aegenis-group/"target="_self"  title="Add 'Volubis acquired by The Aegenis Group' to FURL" onclick="javascript:urchinTracker ('/outbound/article/furl.net');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/furl.png" title="Add 'Volubis acquired by The Aegenis Group' to FURL" alt="Add 'Volubis acquired by The Aegenis Group' to FURL" /></a>&nbsp;<a href="http://blinklist.com/index.php?Action=Blink/addblink.php&amp;Name=Volubis acquired by The Aegenis Group&amp;Description=Volubis acquired by The Aegenis Group&amp;Url=http://www.volubis.com/2007/06/12/volubis-acquired-by-the-aegenis-group/"target="_self"  title="Add 'Volubis acquired by The Aegenis Group' to blinklist" onclick="javascript:urchinTracker ('/outbound/article/blinklist.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/blinklist.png" title="Add 'Volubis acquired by The Aegenis Group' to blinklist" alt="Add 'Volubis acquired by The Aegenis Group' to blinklist" /></a>&nbsp;<a href="http://user.my-tuts.com/tag-tutorial/?url=http://www.volubis.com/2007/06/12/volubis-acquired-by-the-aegenis-group/&title=Volubis acquired by The Aegenis Group"target="_self"  title="Add 'Volubis acquired by The Aegenis Group' to My-Tuts" onclick="javascript:urchinTracker ('/outbound/article/user.my-tuts.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/mytuts.png" title="Add 'Volubis acquired by The Aegenis Group' to My-Tuts" alt="Add 'Volubis acquired by The Aegenis Group' to My-Tuts" /></a>&nbsp;<a href="http://reddit.com/submit?url=http://www.volubis.com/2007/06/12/volubis-acquired-by-the-aegenis-group/&amp;title=Volubis acquired by The Aegenis Group"target="_self"  title="Add 'Volubis acquired by The Aegenis Group' to reddit" onclick="javascript:urchinTracker ('/outbound/article/reddit.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/reddit.png" title="Add 'Volubis acquired by The Aegenis Group' to reddit" alt="Add 'Volubis acquired by The Aegenis Group' to reddit" /></a>&nbsp;<a href="http://feedmelinks.com/categorize?from=toolbar&op=submit&name=Volubis acquired by The Aegenis Group&url=http://www.volubis.com/2007/06/12/volubis-acquired-by-the-aegenis-group/&version=0.7"target="_self"  title="Add 'Volubis acquired by The Aegenis Group' to Feed Me Links!" onclick="javascript:urchinTracker ('/outbound/article/feedmelinks.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/feedmelinks.png" title="Add 'Volubis acquired by The Aegenis Group' to Feed Me Links!" alt="Add 'Volubis acquired by The Aegenis Group' to Feed Me Links!" /></a>&nbsp;<a href="http://www.technorati.com/faves?add=http://www.volubis.com/2007/06/12/volubis-acquired-by-the-aegenis-group/"target="_self"  title="Add 'Volubis acquired by The Aegenis Group' to Technorati" onclick="javascript:urchinTracker ('/outbound/article/www.technorati.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/technorati.png" title="Add 'Volubis acquired by The Aegenis Group' to Technorati" alt="Add 'Volubis acquired by The Aegenis Group' to Technorati" /></a>&nbsp;<a href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.volubis.com/2007/06/12/volubis-acquired-by-the-aegenis-group/&t=Volubis acquired by The Aegenis Group"target="_self"  title="Add 'Volubis acquired by The Aegenis Group' to Yahoo My Web" onclick="javascript:urchinTracker ('/outbound/article/myweb2.search.yahoo.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/yahoo_myweb.png" title="Add 'Volubis acquired by The Aegenis Group' to Yahoo My Web" alt="Add 'Volubis acquired by The Aegenis Group' to Yahoo My Web" /></a>&nbsp;<a href="http://www.newsvine.com/_wine/save?u=http://www.volubis.com/2007/06/12/volubis-acquired-by-the-aegenis-group/&h=Volubis acquired by The Aegenis Group"target="_self"  title="Add 'Volubis acquired by The Aegenis Group' to Newsvine" onclick="javascript:urchinTracker ('/outbound/article/www.newsvine.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/newsvine.png" title="Add 'Volubis acquired by The Aegenis Group' to Newsvine" alt="Add 'Volubis acquired by The Aegenis Group' to Newsvine" /></a>&nbsp;</span></p>
<!-- Social Bar END -->]]></content:encoded>
			<wfw:commentRSS>http://www.volubis.com/2007/06/12/volubis-acquired-by-the-aegenis-group/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>RSA Presentation on PCI</title>
		<link>http://www.volubis.com/2006/10/06/rsa-presentation-on-pci/</link>
		<comments>http://www.volubis.com/2006/10/06/rsa-presentation-on-pci/#comments</comments>
		<pubDate>Fri, 06 Oct 2006 23:04:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
	<category>Events</category>
		<guid isPermaLink="false">http://www.volubis.com/2006/10/06/rsa-presentation-on-pci/</guid>
		<description><![CDATA[Michael Dahn will be a speaker at the upcoming RSA Security Conference.  The event will be held February 5-9, 2007 at The Moscone Center in San Francisco, California.
Session Track: Business Trends &#038; Impact
Scheduled Date: 2/7/2007
Scheduled Time: 9:10 AM - 10:20 AM
Session Title: Why Securing Payments Data Should be Your Top Security Priority
Other panelists will [...]]]></description>
			<content:encoded><![CDATA[<p>Michael Dahn will be a speaker at the upcoming <a href="http://www.rsaconference.com/2007/US/"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.rsaconference.com');">RSA Security Conference</a>.  The event will be held February 5-9, 2007 at The Moscone Center in San Francisco, California.</p>
<p>Session Track: <strong>Business Trends &#038; Impact<br />
</strong>Scheduled Date: <strong>2/7/2007</strong><br />
Scheduled Time: <strong>9:10 AM - 10:20 AM<br />
</strong>Session Title: <a href="https://cm.rsaconference.com/US07/catalog/profile.do?SESSION_ID=1103&#038;form=searchform&#038;ts=1160175429704"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/cm.rsaconference.com');"><strong>Why Securing Payments Data Should be Your Top Security Priority</strong></a></p>
<p>Other panelists will include:</p>
<ul>
<li>Chris Noell - President - TruComply</li>
<li>Mark Rasch - SVP and Chief Security Counsel - Solutionary</li>
<li>Hans Van Tilburg - Director, PCI Compliance - Visa International</li>
</ul>
<!-- Social Bar BEGIN --><p style="padding-top:5px;"><span style="display:block;margin-left:auto;margin-right:auto;text-align:center;"><em>Bookmark to:</em><br /><a href="http://del.icio.us/post?url=http://www.volubis.com/2006/10/06/rsa-presentation-on-pci/&title=RSA Presentation on PCI"target="_blank"  title="Add 'RSA Presentation on PCI' to Del.icio.us" onclick="javascript:urchinTracker ('/outbound/article/del.icio.us');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/delicious.png" title="Add 'RSA Presentation on PCI' to Del.icio.us" alt="Add 'RSA Presentation on PCI' to Del.icio.us" /></a>&nbsp;<a href="http://digg.com/submit?phase=2&amp;url=http://www.volubis.com/2006/10/06/rsa-presentation-on-pci/&title=RSA Presentation on PCI"target="_self"  title="Add 'RSA Presentation on PCI' to digg" onclick="javascript:urchinTracker ('/outbound/article/digg.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/digg.png" title="Add 'RSA Presentation on PCI' to digg" alt="Add 'RSA Presentation on PCI' to digg" /></a>&nbsp;<a href="http://furl.net/storeIt.jsp?t=RSA Presentation on PCI&amp;u=http://www.volubis.com/2006/10/06/rsa-presentation-on-pci/"target="_self"  title="Add 'RSA Presentation on PCI' to FURL" onclick="javascript:urchinTracker ('/outbound/article/furl.net');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/furl.png" title="Add 'RSA Presentation on PCI' to FURL" alt="Add 'RSA Presentation on PCI' to FURL" /></a>&nbsp;<a href="http://blinklist.com/index.php?Action=Blink/addblink.php&amp;Name=RSA Presentation on PCI&amp;Description=RSA Presentation on PCI&amp;Url=http://www.volubis.com/2006/10/06/rsa-presentation-on-pci/"target="_self"  title="Add 'RSA Presentation on PCI' to blinklist" onclick="javascript:urchinTracker ('/outbound/article/blinklist.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/blinklist.png" title="Add 'RSA Presentation on PCI' to blinklist" alt="Add 'RSA Presentation on PCI' to blinklist" /></a>&nbsp;<a href="http://user.my-tuts.com/tag-tutorial/?url=http://www.volubis.com/2006/10/06/rsa-presentation-on-pci/&title=RSA Presentation on PCI"target="_self"  title="Add 'RSA Presentation on PCI' to My-Tuts" onclick="javascript:urchinTracker ('/outbound/article/user.my-tuts.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/mytuts.png" title="Add 'RSA Presentation on PCI' to My-Tuts" alt="Add 'RSA Presentation on PCI' to My-Tuts" /></a>&nbsp;<a href="http://reddit.com/submit?url=http://www.volubis.com/2006/10/06/rsa-presentation-on-pci/&amp;title=RSA Presentation on PCI"target="_self"  title="Add 'RSA Presentation on PCI' to reddit" onclick="javascript:urchinTracker ('/outbound/article/reddit.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/reddit.png" title="Add 'RSA Presentation on PCI' to reddit" alt="Add 'RSA Presentation on PCI' to reddit" /></a>&nbsp;<a href="http://feedmelinks.com/categorize?from=toolbar&op=submit&name=RSA Presentation on PCI&url=http://www.volubis.com/2006/10/06/rsa-presentation-on-pci/&version=0.7"target="_self"  title="Add 'RSA Presentation on PCI' to Feed Me Links!" onclick="javascript:urchinTracker ('/outbound/article/feedmelinks.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/feedmelinks.png" title="Add 'RSA Presentation on PCI' to Feed Me Links!" alt="Add 'RSA Presentation on PCI' to Feed Me Links!" /></a>&nbsp;<a href="http://www.technorati.com/faves?add=http://www.volubis.com/2006/10/06/rsa-presentation-on-pci/"target="_self"  title="Add 'RSA Presentation on PCI' to Technorati" onclick="javascript:urchinTracker ('/outbound/article/www.technorati.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/technorati.png" title="Add 'RSA Presentation on PCI' to Technorati" alt="Add 'RSA Presentation on PCI' to Technorati" /></a>&nbsp;<a href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.volubis.com/2006/10/06/rsa-presentation-on-pci/&t=RSA Presentation on PCI"target="_self"  title="Add 'RSA Presentation on PCI' to Yahoo My Web" onclick="javascript:urchinTracker ('/outbound/article/myweb2.search.yahoo.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/yahoo_myweb.png" title="Add 'RSA Presentation on PCI' to Yahoo My Web" alt="Add 'RSA Presentation on PCI' to Yahoo My Web" /></a>&nbsp;<a href="http://www.newsvine.com/_wine/save?u=http://www.volubis.com/2006/10/06/rsa-presentation-on-pci/&h=RSA Presentation on PCI"target="_self"  title="Add 'RSA Presentation on PCI' to Newsvine" onclick="javascript:urchinTracker ('/outbound/article/www.newsvine.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/newsvine.png" title="Add 'RSA Presentation on PCI' to Newsvine" alt="Add 'RSA Presentation on PCI' to Newsvine" /></a>&nbsp;</span></p>
<!-- Social Bar END -->]]></content:encoded>
			<wfw:commentRSS>http://www.volubis.com/2006/10/06/rsa-presentation-on-pci/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>PCI Demystified article in (IN)SECURE Magazine</title>
		<link>http://www.volubis.com/2006/09/04/pci-demystified-article-in-insecure-magazine/</link>
		<comments>http://www.volubis.com/2006/09/04/pci-demystified-article-in-insecure-magazine/#comments</comments>
		<pubDate>Tue, 05 Sep 2006 04:41:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
	<category>PCI DSS</category>
		<guid isPermaLink="false">http://www.volubis.com/2006/09/04/pci-demystified-article-in-insecure-magazine/</guid>
		<description><![CDATA[Michael Dahn has an article in the latest issue of (IN)SECURE Magazine titled &#8220;Payment Card Industry Demystified&#8221; (PDF) (local copy).
Over the years the landscape of information security has changed from the need to implement perimeter protection to the concept of defense-in-depth and edge-security. Both of the latter concepts are a result of the changing landscape [...]]]></description>
			<content:encoded><![CDATA[<p>Michael Dahn has an article in the latest issue of <a href="http://www.insecuremag.com/"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.insecuremag.com');">(IN)SECURE Magazine</a> titled &#8220;Payment Card Industry Demystified&#8221; (<a href="http://www.insecuremagazine.com/INSECURE-Mag-8.pdf"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.insecuremagazine.com');">PDF</a>) (<a href="http://www.volubis.com/wp-content/uploads/2006/09/PCI_demystified.pdf"target="_blank"  >local copy</a>).</p>
<blockquote><p>Over the years the landscape of information security has changed from the need to implement perimeter protection to the concept of defense-in-depth and edge-security. Both of the latter concepts are a result of the changing landscape of fraud. In an effort to prevent fraud and reduce risk across the board, different industries have implemented their own set of compliance requirements.</p></blockquote>
<blockquote><p>On the surface the PCI DSS looks very detailed, especially when compared with other standards such as HIPAA, GLBA, and SOX. Underneath the clearly outlined requirements and audit procedures is a lengthy list of compensating controls, third-party systems, outsourcing, small data caveats, and that doesn’t even break the surface of the individual requirements and their intent. As PCI begins to gain critical mass and more companies begin to comply there is a need for clarity of vision and understanding for each part of the standard.</p>
<p>This article begins to demystify the Payment Card Industry Data Security Standard; explains the industry, its players, and how they relate; and explain the long list of nuances and differences in these definitions. Through detailed explanation the reader should have a much stronger understanding of the history, current landscape, risks, and best ways to mitigate those risks for your company or the companies you work with. This paper will not make you an expert on the payment card industry but it will give you a great start in beginning to understand the compliance process.</p></blockquote>
<!-- Social Bar BEGIN --><p style="padding-top:5px;"><span style="display:block;margin-left:auto;margin-right:auto;text-align:center;"><em>Bookmark to:</em><br /><a href="http://del.icio.us/post?url=http://www.volubis.com/2006/09/04/pci-demystified-article-in-insecure-magazine/&title=PCI Demystified article in (IN)SECURE Magazine"target="_blank"  title="Add 'PCI Demystified article in (IN)SECURE Magazine' to Del.icio.us" onclick="javascript:urchinTracker ('/outbound/article/del.icio.us');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/delicious.png" title="Add 'PCI Demystified article in (IN)SECURE Magazine' to Del.icio.us" alt="Add 'PCI Demystified article in (IN)SECURE Magazine' to Del.icio.us" /></a>&nbsp;<a href="http://digg.com/submit?phase=2&amp;url=http://www.volubis.com/2006/09/04/pci-demystified-article-in-insecure-magazine/&title=PCI Demystified article in (IN)SECURE Magazine"target="_self"  title="Add 'PCI Demystified article in (IN)SECURE Magazine' to digg" onclick="javascript:urchinTracker ('/outbound/article/digg.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/digg.png" title="Add 'PCI Demystified article in (IN)SECURE Magazine' to digg" alt="Add 'PCI Demystified article in (IN)SECURE Magazine' to digg" /></a>&nbsp;<a href="http://furl.net/storeIt.jsp?t=PCI Demystified article in (IN)SECURE Magazine&amp;u=http://www.volubis.com/2006/09/04/pci-demystified-article-in-insecure-magazine/"target="_self"  title="Add 'PCI Demystified article in (IN)SECURE Magazine' to FURL" onclick="javascript:urchinTracker ('/outbound/article/furl.net');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/furl.png" title="Add 'PCI Demystified article in (IN)SECURE Magazine' to FURL" alt="Add 'PCI Demystified article in (IN)SECURE Magazine' to FURL" /></a>&nbsp;<a href="http://blinklist.com/index.php?Action=Blink/addblink.php&amp;Name=PCI Demystified article in (IN)SECURE Magazine&amp;Description=PCI Demystified article in (IN)SECURE Magazine&amp;Url=http://www.volubis.com/2006/09/04/pci-demystified-article-in-insecure-magazine/"target="_self"  title="Add 'PCI Demystified article in (IN)SECURE Magazine' to blinklist" onclick="javascript:urchinTracker ('/outbound/article/blinklist.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/blinklist.png" title="Add 'PCI Demystified article in (IN)SECURE Magazine' to blinklist" alt="Add 'PCI Demystified article in (IN)SECURE Magazine' to blinklist" /></a>&nbsp;<a href="http://user.my-tuts.com/tag-tutorial/?url=http://www.volubis.com/2006/09/04/pci-demystified-article-in-insecure-magazine/&title=PCI Demystified article in (IN)SECURE Magazine"target="_self"  title="Add 'PCI Demystified article in (IN)SECURE Magazine' to My-Tuts" onclick="javascript:urchinTracker ('/outbound/article/user.my-tuts.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/mytuts.png" title="Add 'PCI Demystified article in (IN)SECURE Magazine' to My-Tuts" alt="Add 'PCI Demystified article in (IN)SECURE Magazine' to My-Tuts" /></a>&nbsp;<a href="http://reddit.com/submit?url=http://www.volubis.com/2006/09/04/pci-demystified-article-in-insecure-magazine/&amp;title=PCI Demystified article in (IN)SECURE Magazine"target="_self"  title="Add 'PCI Demystified article in (IN)SECURE Magazine' to reddit" onclick="javascript:urchinTracker ('/outbound/article/reddit.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/reddit.png" title="Add 'PCI Demystified article in (IN)SECURE Magazine' to reddit" alt="Add 'PCI Demystified article in (IN)SECURE Magazine' to reddit" /></a>&nbsp;<a href="http://feedmelinks.com/categorize?from=toolbar&op=submit&name=PCI Demystified article in (IN)SECURE Magazine&url=http://www.volubis.com/2006/09/04/pci-demystified-article-in-insecure-magazine/&version=0.7"target="_self"  title="Add 'PCI Demystified article in (IN)SECURE Magazine' to Feed Me Links!" onclick="javascript:urchinTracker ('/outbound/article/feedmelinks.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/feedmelinks.png" title="Add 'PCI Demystified article in (IN)SECURE Magazine' to Feed Me Links!" alt="Add 'PCI Demystified article in (IN)SECURE Magazine' to Feed Me Links!" /></a>&nbsp;<a href="http://www.technorati.com/faves?add=http://www.volubis.com/2006/09/04/pci-demystified-article-in-insecure-magazine/"target="_self"  title="Add 'PCI Demystified article in (IN)SECURE Magazine' to Technorati" onclick="javascript:urchinTracker ('/outbound/article/www.technorati.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/technorati.png" title="Add 'PCI Demystified article in (IN)SECURE Magazine' to Technorati" alt="Add 'PCI Demystified article in (IN)SECURE Magazine' to Technorati" /></a>&nbsp;<a href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.volubis.com/2006/09/04/pci-demystified-article-in-insecure-magazine/&t=PCI Demystified article in (IN)SECURE Magazine"target="_self"  title="Add 'PCI Demystified article in (IN)SECURE Magazine' to Yahoo My Web" onclick="javascript:urchinTracker ('/outbound/article/myweb2.search.yahoo.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/yahoo_myweb.png" title="Add 'PCI Demystified article in (IN)SECURE Magazine' to Yahoo My Web" alt="Add 'PCI Demystified article in (IN)SECURE Magazine' to Yahoo My Web" /></a>&nbsp;<a href="http://www.newsvine.com/_wine/save?u=http://www.volubis.com/2006/09/04/pci-demystified-article-in-insecure-magazine/&h=PCI Demystified article in (IN)SECURE Magazine"target="_self"  title="Add 'PCI Demystified article in (IN)SECURE Magazine' to Newsvine" onclick="javascript:urchinTracker ('/outbound/article/www.newsvine.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/newsvine.png" title="Add 'PCI Demystified article in (IN)SECURE Magazine' to Newsvine" alt="Add 'PCI Demystified article in (IN)SECURE Magazine' to Newsvine" /></a>&nbsp;</span></p>
<!-- Social Bar END -->]]></content:encoded>
			<wfw:commentRSS>http://www.volubis.com/2006/09/04/pci-demystified-article-in-insecure-magazine/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Digital Transactions names Volubis as PCI expert</title>
		<link>http://www.volubis.com/2006/08/14/digital-transactions-interviews-volubis-ceo/</link>
		<comments>http://www.volubis.com/2006/08/14/digital-transactions-interviews-volubis-ceo/#comments</comments>
		<pubDate>Mon, 14 Aug 2006 19:25:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
	<category>PCI DSS</category>
		<guid isPermaLink="false">http://www.volubis.com/2006/08/14/digital-transactions-interviews-volubis-ceo/</guid>
		<description><![CDATA[In recent articles Digital Transactions News, the electronic news source for covering the payment card industry, interviewed Volubis CEO Michael Dahn.
One interview addresses Dahn as a PCI expert and reports on the increating rate of compliance for merchants.
&#8220;For large organizations, they are facing a really complex system,&#8221; he says. Many aren’t aware, for example, of [...]]]></description>
			<content:encoded><![CDATA[<p>In recent articles Digital Transactions News, the electronic news source for covering the payment card industry, interviewed Volubis CEO Michael Dahn.</p>
<p>One interview addresses Dahn as a PCI expert and reports on the <a href="http://www.digitaltransactions.net/newsstory.cfm?newsID=1012"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.digitaltransactions.net');">increating rate of compliance for merchants</a>.</p>
<blockquote><p>&#8220;For large organizations, they are facing a really complex system,&#8221; he says. Many aren’t aware, for example, of the standard’s allowance for so-called compensating controls, which permit merchants to satisfy certain rules using less costly measures. One merchant, for example, met a requirement for file-integrity monitoring, which could have triggered huge software costs, by using “an open-source product that did not require them to incur a per-license fee,” making it cheaper to install on the company’s multiple servers, Dahn says.</p></blockquote>
<p>One <a href="http://www.digitaltransactions.net/newsstory.cfm?newsid=1032"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.digitaltransactions.net');">interview covered large point-of-sale (POS) merchants</a> that are seen as a large risk to the payment card industry.  They are not being addressed with the change in Visa USA&#8217;s merchant levels.</p>
<blockquote><p>With Visa USA this week introducing a revision of the volume bands by which it groups merchants for PCI compliance, the card association’s data-security rules now encompass all or most large brick-and-mortar retailers, forcing them to meet more stringent PCI validation requirements, including at the least self-assessments to certify compliance, says Michael Dahn, president of Volubis Inc., a San Francisco company that has contracted with Visa to help train PCI assessors and educate merchants on the standard. The change took effect July 18.</p></blockquote>
<!-- Social Bar BEGIN --><p style="padding-top:5px;"><span style="display:block;margin-left:auto;margin-right:auto;text-align:center;"><em>Bookmark to:</em><br /><a href="http://del.icio.us/post?url=http://www.volubis.com/2006/08/14/digital-transactions-interviews-volubis-ceo/&title=Digital Transactions names Volubis as PCI expert"target="_blank"  title="Add 'Digital Transactions names Volubis as PCI expert' to Del.icio.us" onclick="javascript:urchinTracker ('/outbound/article/del.icio.us');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/delicious.png" title="Add 'Digital Transactions names Volubis as PCI expert' to Del.icio.us" alt="Add 'Digital Transactions names Volubis as PCI expert' to Del.icio.us" /></a>&nbsp;<a href="http://digg.com/submit?phase=2&amp;url=http://www.volubis.com/2006/08/14/digital-transactions-interviews-volubis-ceo/&title=Digital Transactions names Volubis as PCI expert"target="_self"  title="Add 'Digital Transactions names Volubis as PCI expert' to digg" onclick="javascript:urchinTracker ('/outbound/article/digg.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/digg.png" title="Add 'Digital Transactions names Volubis as PCI expert' to digg" alt="Add 'Digital Transactions names Volubis as PCI expert' to digg" /></a>&nbsp;<a href="http://furl.net/storeIt.jsp?t=Digital Transactions names Volubis as PCI expert&amp;u=http://www.volubis.com/2006/08/14/digital-transactions-interviews-volubis-ceo/"target="_self"  title="Add 'Digital Transactions names Volubis as PCI expert' to FURL" onclick="javascript:urchinTracker ('/outbound/article/furl.net');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/furl.png" title="Add 'Digital Transactions names Volubis as PCI expert' to FURL" alt="Add 'Digital Transactions names Volubis as PCI expert' to FURL" /></a>&nbsp;<a href="http://blinklist.com/index.php?Action=Blink/addblink.php&amp;Name=Digital Transactions names Volubis as PCI expert&amp;Description=Digital Transactions names Volubis as PCI expert&amp;Url=http://www.volubis.com/2006/08/14/digital-transactions-interviews-volubis-ceo/"target="_self"  title="Add 'Digital Transactions names Volubis as PCI expert' to blinklist" onclick="javascript:urchinTracker ('/outbound/article/blinklist.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/blinklist.png" title="Add 'Digital Transactions names Volubis as PCI expert' to blinklist" alt="Add 'Digital Transactions names Volubis as PCI expert' to blinklist" /></a>&nbsp;<a href="http://user.my-tuts.com/tag-tutorial/?url=http://www.volubis.com/2006/08/14/digital-transactions-interviews-volubis-ceo/&title=Digital Transactions names Volubis as PCI expert"target="_self"  title="Add 'Digital Transactions names Volubis as PCI expert' to My-Tuts" onclick="javascript:urchinTracker ('/outbound/article/user.my-tuts.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/mytuts.png" title="Add 'Digital Transactions names Volubis as PCI expert' to My-Tuts" alt="Add 'Digital Transactions names Volubis as PCI expert' to My-Tuts" /></a>&nbsp;<a href="http://reddit.com/submit?url=http://www.volubis.com/2006/08/14/digital-transactions-interviews-volubis-ceo/&amp;title=Digital Transactions names Volubis as PCI expert"target="_self"  title="Add 'Digital Transactions names Volubis as PCI expert' to reddit" onclick="javascript:urchinTracker ('/outbound/article/reddit.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/reddit.png" title="Add 'Digital Transactions names Volubis as PCI expert' to reddit" alt="Add 'Digital Transactions names Volubis as PCI expert' to reddit" /></a>&nbsp;<a href="http://feedmelinks.com/categorize?from=toolbar&op=submit&name=Digital Transactions names Volubis as PCI expert&url=http://www.volubis.com/2006/08/14/digital-transactions-interviews-volubis-ceo/&version=0.7"target="_self"  title="Add 'Digital Transactions names Volubis as PCI expert' to Feed Me Links!" onclick="javascript:urchinTracker ('/outbound/article/feedmelinks.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/feedmelinks.png" title="Add 'Digital Transactions names Volubis as PCI expert' to Feed Me Links!" alt="Add 'Digital Transactions names Volubis as PCI expert' to Feed Me Links!" /></a>&nbsp;<a href="http://www.technorati.com/faves?add=http://www.volubis.com/2006/08/14/digital-transactions-interviews-volubis-ceo/"target="_self"  title="Add 'Digital Transactions names Volubis as PCI expert' to Technorati" onclick="javascript:urchinTracker ('/outbound/article/www.technorati.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/technorati.png" title="Add 'Digital Transactions names Volubis as PCI expert' to Technorati" alt="Add 'Digital Transactions names Volubis as PCI expert' to Technorati" /></a>&nbsp;<a href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.volubis.com/2006/08/14/digital-transactions-interviews-volubis-ceo/&t=Digital Transactions names Volubis as PCI expert"target="_self"  title="Add 'Digital Transactions names Volubis as PCI expert' to Yahoo My Web" onclick="javascript:urchinTracker ('/outbound/article/myweb2.search.yahoo.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/yahoo_myweb.png" title="Add 'Digital Transactions names Volubis as PCI expert' to Yahoo My Web" alt="Add 'Digital Transactions names Volubis as PCI expert' to Yahoo My Web" /></a>&nbsp;<a href="http://www.newsvine.com/_wine/save?u=http://www.volubis.com/2006/08/14/digital-transactions-interviews-volubis-ceo/&h=Digital Transactions names Volubis as PCI expert"target="_self"  title="Add 'Digital Transactions names Volubis as PCI expert' to Newsvine" onclick="javascript:urchinTracker ('/outbound/article/www.newsvine.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/newsvine.png" title="Add 'Digital Transactions names Volubis as PCI expert' to Newsvine" alt="Add 'Digital Transactions names Volubis as PCI expert' to Newsvine" /></a>&nbsp;</span></p>
<!-- Social Bar END -->]]></content:encoded>
			<wfw:commentRSS>http://www.volubis.com/2006/08/14/digital-transactions-interviews-volubis-ceo/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Presentation at InfraGard National Conference 2006</title>
		<link>http://www.volubis.com/2006/07/23/volubis-presents-at-infragard-national-conference-2006/</link>
		<comments>http://www.volubis.com/2006/07/23/volubis-presents-at-infragard-national-conference-2006/#comments</comments>
		<pubDate>Sun, 23 Jul 2006 07:08:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
	<category>Events</category>
		<guid isPermaLink="false">http://www.volubis.com/2006/07/23/volubis-presents-at-infragard-national-conference-2006/</guid>
		<description><![CDATA[Michael Dahn, CEO of Volubis, Inc., will be presenting at the InfraGard National Conference in Washington D.C.  His presentation will be in the Regulatory Compliance track with the title &#8220;Compliance Nation &#038; Credit Card Security&#8221;.  His bio is listed on the site and the presentation overview is listed here.
Research shows that today more [...]]]></description>
			<content:encoded><![CDATA[<p>Michael Dahn, CEO of Volubis, Inc., will be presenting at the <a href="http://www.infragardconferences.com/"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.infragardconferences.com');">InfraGard National Conference</a> in Washington D.C.  His presentation will be in the <a href="http://www.infragardconferences.com/pages/tracks_reg.html"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.infragardconferences.com');">Regulatory Compliance track</a> with the title <em>&#8220;Compliance Nation &#038; Credit Card Security&#8221;</em>.  His <a href="http://www.infragardconferences.com/pages/bios/Dahan.html"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.infragardconferences.com');">bio is listed</a> on the site and the presentation overview is listed here.</p>
<blockquote><p>Research shows that today more than ever information security budgets are allotted towards compliance. The variety of compliance requirements is a collection of alphabet soup and yet the number of security breaches continues to grow. In 2005, there were more publicized data security breaches than any year prior, and companies still struggle to understand the industry requirements. Everyone is looking to their neighbor to interpret and understand what they need to do to comply without focusing on how to stay secure. This presentation provides an overview of national and global information security compliance requirements and demystifies those specific to the Payment Card Industry (PCI) Data Security Standard (DSS). It will explain in clear terms what the intent is of each requirement and how to understand things such as intent of controls, scoping &#038; sampling, and compensating controls.</p></blockquote>
<!-- Social Bar BEGIN --><p style="padding-top:5px;"><span style="display:block;margin-left:auto;margin-right:auto;text-align:center;"><em>Bookmark to:</em><br /><a href="http://del.icio.us/post?url=http://www.volubis.com/2006/07/23/volubis-presents-at-infragard-national-conference-2006/&title=Presentation at InfraGard National Conference 2006"target="_blank"  title="Add 'Presentation at InfraGard National Conference 2006' to Del.icio.us" onclick="javascript:urchinTracker ('/outbound/article/del.icio.us');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/delicious.png" title="Add 'Presentation at InfraGard National Conference 2006' to Del.icio.us" alt="Add 'Presentation at InfraGard National Conference 2006' to Del.icio.us" /></a>&nbsp;<a href="http://digg.com/submit?phase=2&amp;url=http://www.volubis.com/2006/07/23/volubis-presents-at-infragard-national-conference-2006/&title=Presentation at InfraGard National Conference 2006"target="_self"  title="Add 'Presentation at InfraGard National Conference 2006' to digg" onclick="javascript:urchinTracker ('/outbound/article/digg.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/digg.png" title="Add 'Presentation at InfraGard National Conference 2006' to digg" alt="Add 'Presentation at InfraGard National Conference 2006' to digg" /></a>&nbsp;<a href="http://furl.net/storeIt.jsp?t=Presentation at InfraGard National Conference 2006&amp;u=http://www.volubis.com/2006/07/23/volubis-presents-at-infragard-national-conference-2006/"target="_self"  title="Add 'Presentation at InfraGard National Conference 2006' to FURL" onclick="javascript:urchinTracker ('/outbound/article/furl.net');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/furl.png" title="Add 'Presentation at InfraGard National Conference 2006' to FURL" alt="Add 'Presentation at InfraGard National Conference 2006' to FURL" /></a>&nbsp;<a href="http://blinklist.com/index.php?Action=Blink/addblink.php&amp;Name=Presentation at InfraGard National Conference 2006&amp;Description=Presentation at InfraGard National Conference 2006&amp;Url=http://www.volubis.com/2006/07/23/volubis-presents-at-infragard-national-conference-2006/"target="_self"  title="Add 'Presentation at InfraGard National Conference 2006' to blinklist" onclick="javascript:urchinTracker ('/outbound/article/blinklist.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/blinklist.png" title="Add 'Presentation at InfraGard National Conference 2006' to blinklist" alt="Add 'Presentation at InfraGard National Conference 2006' to blinklist" /></a>&nbsp;<a href="http://user.my-tuts.com/tag-tutorial/?url=http://www.volubis.com/2006/07/23/volubis-presents-at-infragard-national-conference-2006/&title=Presentation at InfraGard National Conference 2006"target="_self"  title="Add 'Presentation at InfraGard National Conference 2006' to My-Tuts" onclick="javascript:urchinTracker ('/outbound/article/user.my-tuts.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/mytuts.png" title="Add 'Presentation at InfraGard National Conference 2006' to My-Tuts" alt="Add 'Presentation at InfraGard National Conference 2006' to My-Tuts" /></a>&nbsp;<a href="http://reddit.com/submit?url=http://www.volubis.com/2006/07/23/volubis-presents-at-infragard-national-conference-2006/&amp;title=Presentation at InfraGard National Conference 2006"target="_self"  title="Add 'Presentation at InfraGard National Conference 2006' to reddit" onclick="javascript:urchinTracker ('/outbound/article/reddit.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/reddit.png" title="Add 'Presentation at InfraGard National Conference 2006' to reddit" alt="Add 'Presentation at InfraGard National Conference 2006' to reddit" /></a>&nbsp;<a href="http://feedmelinks.com/categorize?from=toolbar&op=submit&name=Presentation at InfraGard National Conference 2006&url=http://www.volubis.com/2006/07/23/volubis-presents-at-infragard-national-conference-2006/&version=0.7"target="_self"  title="Add 'Presentation at InfraGard National Conference 2006' to Feed Me Links!" onclick="javascript:urchinTracker ('/outbound/article/feedmelinks.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/feedmelinks.png" title="Add 'Presentation at InfraGard National Conference 2006' to Feed Me Links!" alt="Add 'Presentation at InfraGard National Conference 2006' to Feed Me Links!" /></a>&nbsp;<a href="http://www.technorati.com/faves?add=http://www.volubis.com/2006/07/23/volubis-presents-at-infragard-national-conference-2006/"target="_self"  title="Add 'Presentation at InfraGard National Conference 2006' to Technorati" onclick="javascript:urchinTracker ('/outbound/article/www.technorati.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/technorati.png" title="Add 'Presentation at InfraGard National Conference 2006' to Technorati" alt="Add 'Presentation at InfraGard National Conference 2006' to Technorati" /></a>&nbsp;<a href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.volubis.com/2006/07/23/volubis-presents-at-infragard-national-conference-2006/&t=Presentation at InfraGard National Conference 2006"target="_self"  title="Add 'Presentation at InfraGard National Conference 2006' to Yahoo My Web" onclick="javascript:urchinTracker ('/outbound/article/myweb2.search.yahoo.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/yahoo_myweb.png" title="Add 'Presentation at InfraGard National Conference 2006' to Yahoo My Web" alt="Add 'Presentation at InfraGard National Conference 2006' to Yahoo My Web" /></a>&nbsp;<a href="http://www.newsvine.com/_wine/save?u=http://www.volubis.com/2006/07/23/volubis-presents-at-infragard-national-conference-2006/&h=Presentation at InfraGard National Conference 2006"target="_self"  title="Add 'Presentation at InfraGard National Conference 2006' to Newsvine" onclick="javascript:urchinTracker ('/outbound/article/www.newsvine.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/newsvine.png" title="Add 'Presentation at InfraGard National Conference 2006' to Newsvine" alt="Add 'Presentation at InfraGard National Conference 2006' to Newsvine" /></a>&nbsp;</span></p>
<!-- Social Bar END -->]]></content:encoded>
			<wfw:commentRSS>http://www.volubis.com/2006/07/23/volubis-presents-at-infragard-national-conference-2006/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Encryption Requirements in PCI DSS</title>
		<link>http://www.volubis.com/2006/07/09/encryption-requirements-in-pci-dss/</link>
		<comments>http://www.volubis.com/2006/07/09/encryption-requirements-in-pci-dss/#comments</comments>
		<pubDate>Mon, 10 Jul 2006 01:03:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
	<category>PCI DSS</category>
	<category>Encryption</category>
		<guid isPermaLink="false">http://www.volubis.com/?p=10</guid>
		<description><![CDATA[Encryption has become a necessary part of data security. Best practices have us using encrypted protocols and tunnels, PCI DSS requires encryption of credit card data, and consumer privacy requirements mandate protection of personal information.
Within the PCI DSS encryption is required for the following items:

Wireless (Requirements 2.1.1, 4.1.1)
Non-console administrative access (Requirement 2.3)
Data at rest (Requirement [...]]]></description>
			<content:encoded><![CDATA[<p>Encryption has become a necessary part of data security. Best practices have us using encrypted protocols and tunnels, PCI DSS requires encryption of credit card data, and consumer privacy requirements mandate protection of personal information.</p>
<p>Within the PCI DSS encryption is required for the following items:</p>
<ul>
<li>Wireless (Requirements 2.1.1, 4.1.1)</li>
<li>Non-console administrative access (Requirement 2.3)</li>
<li>Data at rest (Requirement 3)</li>
<li>Data in transit (Requirement 4.1)</li>
<li>E-mail (Requirement 4.2)</li>
<li>Passwords in transit or stored (Requirement 8.4)</li>
</ul>
<p>This post outlines the requirements for each requirement but does not focus on compensating controls or implementation strategies.</p>
<p><strong>Wireless:</strong> Companies have two options for securing their wireless networks.   They can either implement WPA with proper authentication and encryption (think RADIUS authentication, individual certificates, and WPA2) or they can use WEP with another form of encryption (i.e. IPSec, VPN, or encrypted SSL).  WEP is insecure and should not be trusted as a protection mechanisms.  Tools such as <a href="http://sourceforge.net/projects/wepcrack"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/sourceforge.net');">wepcrack</a> exist that can determine a WEP encryption key in under an hour.</p>
<p><strong>Non-Console Access:</strong> This means the elimination of TELNET, FTP, R-services, and any other protocol used for administrative access.  Most companies struggle replacing TELNET with SSH, but they should also look to places where VNC is used for administrative access and FTP is used for batch administration.  Any plain text protocol needs to be replaced or encapsulated with an encrypted alternative.</p>
<p><strong>Data at Rest:</strong> This is the biggest requirement for data encryption throughout the PCI DSS.  This mandates three things:</p>
<ol>
<li>Industry accepted encryption algorithm with proper key length (i.e. AES at 128-bit)</li>
<li>Encryption key management</li>
<li>Encryption key rotation</li>
</ol>
<p>For some organizations a hardware security module (HSM) or tamper resistant security module (TRSM) are used to perform all the key management and rotation steps.  Other companies will opt to implement these requirements in their own software and they will need to work with a qualified assessor to determine if they are meeting each of the three key requirements.</p>
<p>Requirement 3 lists two alternatives to cardholder data encryption being Truncation and Hashing.  If you choose either of these alternatives you do not need to encrypt the data, although some companies find it helpful to store both the encrypted and hashed or truncated account numbers within the same data store.  (If you go the way of hashing it&#8217;s good security sense to &#8217;salt&#8217; your hash values.)</p>
<p><strong>Data in Transmission:</strong> Contrary to the wording cardholder data does not need to be encrypted when transmitted over private networks &#8212; only when traversing public networks.  So what is considered a public network?  The Internet, DMZ, and Wireless networks. Companies need to verify the cardholder data traversing public networks is encrypted (i.e. Encrypted SSL for Internet traffic, IPSec for DMZ connections, and WPA2 for wireless networks.)</p>
<p>If data is transmitted over a private network (i.e. Frame-relay, private T1, MPLS, VPN, etc.) the cardholder data does not need to be encrypted.</p>
<p><strong>E-Mail:</strong> Cardholder data should never be sent un-encrypted via e-mail. If the e-mail traverses a public network (as described above) it would need to be encrypted as per PCI DSS Requirement 4.1, which causes many companies to think they do not need to encrypt internal e-mails that contain credit card numbers.  The problem is that e-mail is static most of the time, either in personal mail folders on workstations or on the e-mail server itself.  If these locations contain un-encrypted credit card numbers they are considered data stores and must themselves be encrypted as per PCI DSS Requirement 3.</p>
<p>What is the solution? Deploy e-mail encryption software to all employees who will need to send and receive card card data, which will prevent un-encrypted data stores from being created.</p>
<p><strong>Encrypt Passwords:</strong> This requirement applies to all network, system, and application passwords that are stored.  Companies who use VNC and pcAnywhere must be cautious because these passwords are not stored encrypted.  Native pcAnywhere passwords and VNC passwords are stored in an easy to unscramble format.  Other than that, watch out for router passwords that are not store encrypted (think &#8217;service password-encryption&#8217;) and application level passwords.  Many companies implementing password encryption forget about application passwords that also need to be encrypted (or hashed).
</p>
<!-- Social Bar BEGIN --><p style="padding-top:5px;"><span style="display:block;margin-left:auto;margin-right:auto;text-align:center;"><em>Bookmark to:</em><br /><a href="http://del.icio.us/post?url=http://www.volubis.com/2006/07/09/encryption-requirements-in-pci-dss/&title=Encryption Requirements in PCI DSS"target="_blank"  title="Add 'Encryption Requirements in PCI DSS' to Del.icio.us" onclick="javascript:urchinTracker ('/outbound/article/del.icio.us');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/delicious.png" title="Add 'Encryption Requirements in PCI DSS' to Del.icio.us" alt="Add 'Encryption Requirements in PCI DSS' to Del.icio.us" /></a>&nbsp;<a href="http://digg.com/submit?phase=2&amp;url=http://www.volubis.com/2006/07/09/encryption-requirements-in-pci-dss/&title=Encryption Requirements in PCI DSS"target="_self"  title="Add 'Encryption Requirements in PCI DSS' to digg" onclick="javascript:urchinTracker ('/outbound/article/digg.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/digg.png" title="Add 'Encryption Requirements in PCI DSS' to digg" alt="Add 'Encryption Requirements in PCI DSS' to digg" /></a>&nbsp;<a href="http://furl.net/storeIt.jsp?t=Encryption Requirements in PCI DSS&amp;u=http://www.volubis.com/2006/07/09/encryption-requirements-in-pci-dss/"target="_self"  title="Add 'Encryption Requirements in PCI DSS' to FURL" onclick="javascript:urchinTracker ('/outbound/article/furl.net');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/furl.png" title="Add 'Encryption Requirements in PCI DSS' to FURL" alt="Add 'Encryption Requirements in PCI DSS' to FURL" /></a>&nbsp;<a href="http://blinklist.com/index.php?Action=Blink/addblink.php&amp;Name=Encryption Requirements in PCI DSS&amp;Description=Encryption Requirements in PCI DSS&amp;Url=http://www.volubis.com/2006/07/09/encryption-requirements-in-pci-dss/"target="_self"  title="Add 'Encryption Requirements in PCI DSS' to blinklist" onclick="javascript:urchinTracker ('/outbound/article/blinklist.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/blinklist.png" title="Add 'Encryption Requirements in PCI DSS' to blinklist" alt="Add 'Encryption Requirements in PCI DSS' to blinklist" /></a>&nbsp;<a href="http://user.my-tuts.com/tag-tutorial/?url=http://www.volubis.com/2006/07/09/encryption-requirements-in-pci-dss/&title=Encryption Requirements in PCI DSS"target="_self"  title="Add 'Encryption Requirements in PCI DSS' to My-Tuts" onclick="javascript:urchinTracker ('/outbound/article/user.my-tuts.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/mytuts.png" title="Add 'Encryption Requirements in PCI DSS' to My-Tuts" alt="Add 'Encryption Requirements in PCI DSS' to My-Tuts" /></a>&nbsp;<a href="http://reddit.com/submit?url=http://www.volubis.com/2006/07/09/encryption-requirements-in-pci-dss/&amp;title=Encryption Requirements in PCI DSS"target="_self"  title="Add 'Encryption Requirements in PCI DSS' to reddit" onclick="javascript:urchinTracker ('/outbound/article/reddit.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/reddit.png" title="Add 'Encryption Requirements in PCI DSS' to reddit" alt="Add 'Encryption Requirements in PCI DSS' to reddit" /></a>&nbsp;<a href="http://feedmelinks.com/categorize?from=toolbar&op=submit&name=Encryption Requirements in PCI DSS&url=http://www.volubis.com/2006/07/09/encryption-requirements-in-pci-dss/&version=0.7"target="_self"  title="Add 'Encryption Requirements in PCI DSS' to Feed Me Links!" onclick="javascript:urchinTracker ('/outbound/article/feedmelinks.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/feedmelinks.png" title="Add 'Encryption Requirements in PCI DSS' to Feed Me Links!" alt="Add 'Encryption Requirements in PCI DSS' to Feed Me Links!" /></a>&nbsp;<a href="http://www.technorati.com/faves?add=http://www.volubis.com/2006/07/09/encryption-requirements-in-pci-dss/"target="_self"  title="Add 'Encryption Requirements in PCI DSS' to Technorati" onclick="javascript:urchinTracker ('/outbound/article/www.technorati.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/technorati.png" title="Add 'Encryption Requirements in PCI DSS' to Technorati" alt="Add 'Encryption Requirements in PCI DSS' to Technorati" /></a>&nbsp;<a href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.volubis.com/2006/07/09/encryption-requirements-in-pci-dss/&t=Encryption Requirements in PCI DSS"target="_self"  title="Add 'Encryption Requirements in PCI DSS' to Yahoo My Web" onclick="javascript:urchinTracker ('/outbound/article/myweb2.search.yahoo.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/yahoo_myweb.png" title="Add 'Encryption Requirements in PCI DSS' to Yahoo My Web" alt="Add 'Encryption Requirements in PCI DSS' to Yahoo My Web" /></a>&nbsp;<a href="http://www.newsvine.com/_wine/save?u=http://www.volubis.com/2006/07/09/encryption-requirements-in-pci-dss/&h=Encryption Requirements in PCI DSS"target="_self"  title="Add 'Encryption Requirements in PCI DSS' to Newsvine" onclick="javascript:urchinTracker ('/outbound/article/www.newsvine.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/newsvine.png" title="Add 'Encryption Requirements in PCI DSS' to Newsvine" alt="Add 'Encryption Requirements in PCI DSS' to Newsvine" /></a>&nbsp;</span></p>
<!-- Social Bar END -->]]></content:encoded>
			<wfw:commentRSS>http://www.volubis.com/2006/07/09/encryption-requirements-in-pci-dss/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Green Sheet sceptical about PCI compliance</title>
		<link>http://www.volubis.com/2006/07/09/green-sheet-sceptical-about-pci-compliance/</link>
		<comments>http://www.volubis.com/2006/07/09/green-sheet-sceptical-about-pci-compliance/#comments</comments>
		<pubDate>Mon, 10 Jul 2006 00:32:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
	<category>PCI DSS</category>
		<guid isPermaLink="false">http://www.volubis.com/?p=9</guid>
		<description><![CDATA[A reporter from the Green Sheet, a magazine devoted to the payment card industry, made the following comments.  Many of these comments are based on common misunderstandings.   It is important to address and respond to each of these because without fully understanding PCI or the compliance process it is easy for someone [...]]]></description>
			<content:encoded><![CDATA[<p>A reporter from the Green Sheet, a magazine devoted to the payment card industry, <a href="http://www.greensheet.com/PriorIssues-/060602-/10.htm"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.greensheet.com');">made the following comments</a>.  Many of these comments are based on common misunderstandings.   It is important to address and respond to each of these because without fully understanding PCI or the compliance process it is easy for someone to criticize the process.</p>
<blockquote><p>In a recent <a href="http://www.americanbanker.com/"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.americanbanker.com');"><em>American Banker</em></a> article, Visa U.S.A. Chief Executive Officer John Philip Coghlan predicted that by the end of this year, more than 60% of the merchants accepting Visa bankcards will have adopted the <a href="http://www.visa.com/cisp/"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.visa.com');">Payment Card Industry (PCI) Data Security Standard</a>.</p>
<p>I risk spoiling my brand neutrality, but if 60% of Visa&#8217;s merchants are PCI compliant by year&#8217;s end, I&#8217;ll get a Visa tattoo, embed a radio frequency identification device in the back of my right hand and become the first human payment product. &#8220;Talk to the hand&#8221; will become my preferred payment parlance. Fun as this seems, I feel secure that by year&#8217;s end I will remain ink and chip free: I doubt that 60% of merchants will even know what PCI stands for by that time.</p></blockquote>
<p>I can empathize with the writer in that changing an industry can sometimes feel like parallel parking a large truck.  It may be slow and take careful attention to detail but it can be done.  Visa has stated at ETA and CEO John Coghlan have both given statistics that put compliance somewhere in the neighborhood of 60% by the end of the year.</p>
<p>Statistics are funny things in that they can be slanted in many ways.  The magic percentage number may apply to merchants, service providers, or both for that matter.  I would imagine that the merchant population is always increasing so the percentage would have to be based on the number of identified merchants and service providers in a certain year.  According to InfoMerchant.net there were <a href="http://www.infomerchant.net/creditcardprocessing/credit_card_terminals.html"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.infomerchant.net');">over 1.5 million terminals shipped in the US</a> in 2005 (some to replace old terminals and some new.)  The percentage compliant only shows a point in time but shows that the industry is slowly moving towards improving security.</p>
<p>The article explains that the &#8220;overlooked Level 4&#8243; merchants are such a large risk to the industry because they are using integrated point-of-sale (IPOS) units.</p>
<blockquote><p>Additionally, several IPOS systems can inappropriately store magnetic-stripe data, often due to merchant misuse or ignorance. Many IPOS systems connect to a processor via high-speed Internet connections, leaving them vulnerable to hackers.</p>
<p>&#8230; Our industry is most exposed within the Level 4 merchant category. &#8230;</p></blockquote>
<p>First, Level 4 merchants are not the only ones using IPOS systems; in fact most merchants use them.  One web site <a href="http://www.marketresearch.com/product/display.asp?productid=1268700&#038;g=1"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.marketresearch.com');">documents the difference</a> as such:</p>
<blockquote><p>A point-of-sale (POS) system can refer to many things depending on whom you ask. To some, it is a simple cash register or a standalone card swipe terminal that is connected to a phone line or store controller. To others, it is a PC-based system that integrates a cash drawer and a card reader that runs <a href="http://www.integratedpos.com/"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.integratedpos.com');">sophisticated software applications</a>. This report analyzes the PC-based POS system market.</p></blockquote>
<p>Second, there is nothing super technical about an IPOS other than it uses specific software that ties the credit card reader into a PC. What most people do not realize about the Level 4 definition is that it is not based on acceptance channel.  This means that unlike Level 2 and 3, which are based on &#8220;e-commerce transactions&#8221;, Level 4 is based on either e-commerce or brick-and-mortar transactions.</p>
<p>Does this mean there&#8217;s a loop-hole in the level definitions?  Maybe.  Most Level 4 merchants are small mom-n-pop shops but some are large retailers that do less than 6 million transactions per year (or 500,000 per month average) but do not have an e-commerce presence.  This means there are many small merchants and some very large merchants in the Level 4 definition.</p>
<p>The statement that hackers look for IPOS systems is partially correct, but the article makes it sound as if they are primarily used at Level 4 merchants.  The story should have explained that hackers are targeting retail stores more than e-commerce stores.  This would more clearly explain that Level 2 and/or Level 3 should not be based on acceptance channel (i.e. e-commerce vs brick-and-mortar).</p>
<p>The article provides the following recommendations:</p>
<blockquote><p>I urge Visa and MasterCard to focus their efforts on this cross section of merchants, and I encourage all acquirers to register all known third parties that represent this merchant group. And I hope everyone in the industry seriously addresses this demographic. The PCI requirements for Level 4 merchants are to pass a self-assessment questionnaire and to pass a quarterly network scan from a qualified independent vendor.</p></blockquote>
<p>This is exactly what Visa and MasterCard have been doing.  CISP, the precursor to PCI, was introduced in 2000 and has been slowly expanding, based on changing risk, from e-commerce systems to the back-end systems down to the POS itself.   In December of 2004, Visa posted to its <a href="http://www.visa.com/cisp/"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/www.visa.com');">web site</a> the <a href="http://usa.visa.com/business/accepting_visa/ops_risk_management/cisp_payment_applications.html"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/usa.visa.com');">Payment Application Best Practices</a> (PABP), which it plans to make a required part of PCI by the end of this year.  The PABP applies to all types of payment applications and their compliance with data security standards will directly impact all merchants regardless of level definition (in fact, most Level 4 merchants only store credit card data in their POS systems so a PABP validated POS may make them compliant right away.)   But this too will take time, because even once the secure version of the application is available the merchant will have to implement it in their environment.</p>
<p>Visa and the acquirers are registering third-party service providers all the time and have been since 2000.  One of the required items on the report on compliance (ROC) is that the assessor or auditor provide a list of any third party vendors and what access they have to cardholder data.</p>
<p>The acquirers are addressing compliance using a risk model.   Level 1 merchants are a higher risk than Level 4 merchants.   The retort to that is that many Level 4 merchants add up to much more than the few Level 1 merchants and thus are a higher risk.  This is not true.</p>
<p>Yes, Level 4 merchants are compromised more often than Level 1 merchants.  Yes, there are more Level 4 merchants, but individually they store fewer credit card numbers.  What people do not know is that it takes a whole lot of Level 4 merchants being compromised to equal one Level 1 merchant or service provider hack that results in 10-20 million credit card numbers being compromised.   Also, part of the risk equation is consumer confidence, which is affected much more by a Level 1 compromise than by several Level 4 compromises.</p>
<p>The article makes the following recommendations that are already in place.</p>
<ul>
<li>Require merchants with dial-up, stand-alone terminals and no other connectivity or card number storage capacity to verify accordingly with an attestation statement. Then exempt them from further compliance-related activity.</li>
<li>Impose a due date for compliance on merchants processing more than 20,000 transactions yearly, regardless of processing method.</li>
<li>Provide an Association certification for all acquirers engaged in enterprise-wide cardholder security programs. Advertise these acquirers&#8217; compliance and significance.</li>
</ul>
<p>Merchants with terminals that dial directly to the acquirer and do not store credit card data have only one compliance requirement to meet: securely storing the paper receipts that print the full credit card number.   If their copy has a truncated card number then there is no other compliance requirements.</p>
<p>Due dates have already been set and passed.   Every merchant should have been compliant by September 30, 2004.   The due date was extended for some merchants, but currently all merchants and service providers need to be compliant.</p>
<p>Qualified information security companies are already working with the top acquirers and processors, and have been for some time, rolling out &#8220;enterprise-wide cardholder security programs&#8221;.   They are working with their entire merchant base to get them compliant.   Also, the acquirers have to send reports to the card associations on a regular basis to report the compliance status of their merchant population.
</p>
<!-- Social Bar BEGIN --><p style="padding-top:5px;"><span style="display:block;margin-left:auto;margin-right:auto;text-align:center;"><em>Bookmark to:</em><br /><a href="http://del.icio.us/post?url=http://www.volubis.com/2006/07/09/green-sheet-sceptical-about-pci-compliance/&title=Green Sheet sceptical about PCI compliance"target="_blank"  title="Add 'Green Sheet sceptical about PCI compliance' to Del.icio.us" onclick="javascript:urchinTracker ('/outbound/article/del.icio.us');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/delicious.png" title="Add 'Green Sheet sceptical about PCI compliance' to Del.icio.us" alt="Add 'Green Sheet sceptical about PCI compliance' to Del.icio.us" /></a>&nbsp;<a href="http://digg.com/submit?phase=2&amp;url=http://www.volubis.com/2006/07/09/green-sheet-sceptical-about-pci-compliance/&title=Green Sheet sceptical about PCI compliance"target="_self"  title="Add 'Green Sheet sceptical about PCI compliance' to digg" onclick="javascript:urchinTracker ('/outbound/article/digg.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/digg.png" title="Add 'Green Sheet sceptical about PCI compliance' to digg" alt="Add 'Green Sheet sceptical about PCI compliance' to digg" /></a>&nbsp;<a href="http://furl.net/storeIt.jsp?t=Green Sheet sceptical about PCI compliance&amp;u=http://www.volubis.com/2006/07/09/green-sheet-sceptical-about-pci-compliance/"target="_self"  title="Add 'Green Sheet sceptical about PCI compliance' to FURL" onclick="javascript:urchinTracker ('/outbound/article/furl.net');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/furl.png" title="Add 'Green Sheet sceptical about PCI compliance' to FURL" alt="Add 'Green Sheet sceptical about PCI compliance' to FURL" /></a>&nbsp;<a href="http://blinklist.com/index.php?Action=Blink/addblink.php&amp;Name=Green Sheet sceptical about PCI compliance&amp;Description=Green Sheet sceptical about PCI compliance&amp;Url=http://www.volubis.com/2006/07/09/green-sheet-sceptical-about-pci-compliance/"target="_self"  title="Add 'Green Sheet sceptical about PCI compliance' to blinklist" onclick="javascript:urchinTracker ('/outbound/article/blinklist.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/blinklist.png" title="Add 'Green Sheet sceptical about PCI compliance' to blinklist" alt="Add 'Green Sheet sceptical about PCI compliance' to blinklist" /></a>&nbsp;<a href="http://user.my-tuts.com/tag-tutorial/?url=http://www.volubis.com/2006/07/09/green-sheet-sceptical-about-pci-compliance/&title=Green Sheet sceptical about PCI compliance"target="_self"  title="Add 'Green Sheet sceptical about PCI compliance' to My-Tuts" onclick="javascript:urchinTracker ('/outbound/article/user.my-tuts.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/mytuts.png" title="Add 'Green Sheet sceptical about PCI compliance' to My-Tuts" alt="Add 'Green Sheet sceptical about PCI compliance' to My-Tuts" /></a>&nbsp;<a href="http://reddit.com/submit?url=http://www.volubis.com/2006/07/09/green-sheet-sceptical-about-pci-compliance/&amp;title=Green Sheet sceptical about PCI compliance"target="_self"  title="Add 'Green Sheet sceptical about PCI compliance' to reddit" onclick="javascript:urchinTracker ('/outbound/article/reddit.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/reddit.png" title="Add 'Green Sheet sceptical about PCI compliance' to reddit" alt="Add 'Green Sheet sceptical about PCI compliance' to reddit" /></a>&nbsp;<a href="http://feedmelinks.com/categorize?from=toolbar&op=submit&name=Green Sheet sceptical about PCI compliance&url=http://www.volubis.com/2006/07/09/green-sheet-sceptical-about-pci-compliance/&version=0.7"target="_self"  title="Add 'Green Sheet sceptical about PCI compliance' to Feed Me Links!" onclick="javascript:urchinTracker ('/outbound/article/feedmelinks.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/feedmelinks.png" title="Add 'Green Sheet sceptical about PCI compliance' to Feed Me Links!" alt="Add 'Green Sheet sceptical about PCI compliance' to Feed Me Links!" /></a>&nbsp;<a href="http://www.technorati.com/faves?add=http://www.volubis.com/2006/07/09/green-sheet-sceptical-about-pci-compliance/"target="_self"  title="Add 'Green Sheet sceptical about PCI compliance' to Technorati" onclick="javascript:urchinTracker ('/outbound/article/www.technorati.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/technorati.png" title="Add 'Green Sheet sceptical about PCI compliance' to Technorati" alt="Add 'Green Sheet sceptical about PCI compliance' to Technorati" /></a>&nbsp;<a href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.volubis.com/2006/07/09/green-sheet-sceptical-about-pci-compliance/&t=Green Sheet sceptical about PCI compliance"target="_self"  title="Add 'Green Sheet sceptical about PCI compliance' to Yahoo My Web" onclick="javascript:urchinTracker ('/outbound/article/myweb2.search.yahoo.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/yahoo_myweb.png" title="Add 'Green Sheet sceptical about PCI compliance' to Yahoo My Web" alt="Add 'Green Sheet sceptical about PCI compliance' to Yahoo My Web" /></a>&nbsp;<a href="http://www.newsvine.com/_wine/save?u=http://www.volubis.com/2006/07/09/green-sheet-sceptical-about-pci-compliance/&h=Green Sheet sceptical about PCI compliance"target="_self"  title="Add 'Green Sheet sceptical about PCI compliance' to Newsvine" onclick="javascript:urchinTracker ('/outbound/article/www.newsvine.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/newsvine.png" title="Add 'Green Sheet sceptical about PCI compliance' to Newsvine" alt="Add 'Green Sheet sceptical about PCI compliance' to Newsvine" /></a>&nbsp;</span></p>
<!-- Social Bar END -->]]></content:encoded>
			<wfw:commentRSS>http://www.volubis.com/2006/07/09/green-sheet-sceptical-about-pci-compliance/feed/</wfw:commentRSS>
		</item>
		<item>
		<title>Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update</title>
		<link>http://www.volubis.com/2006/07/08/hello-world/</link>
		<comments>http://www.volubis.com/2006/07/08/hello-world/#comments</comments>
		<pubDate>Sat, 08 Jul 2006 22:44:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
	<category>PCI DSS</category>
		<guid isPermaLink="false"></guid>
		<description><![CDATA[Much of the work we have done recently has been in the area of PCI DSS compliance audit and education.  If you are interested in assistance with your internal audit or want an educated defense against your external auditors, email us for more information.

Bookmark to:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;
]]></description>
			<content:encoded><![CDATA[<p>Much of the work we have done recently has been in the area of <a href="http://en.wikipedia.org/wiki/Payment_Card_Industry"target="_blank"  onclick="javascript:urchinTracker ('/outbound/article/en.wikipedia.org');">PCI</a> DSS compliance audit and education.  If you are interested in assistance with your internal audit or want an educated defense against your external auditors, <a href="mailto:info@volubis.com">email us for more information</a>.
</p>
<!-- Social Bar BEGIN --><p style="padding-top:5px;"><span style="display:block;margin-left:auto;margin-right:auto;text-align:center;"><em>Bookmark to:</em><br /><a href="http://del.icio.us/post?url=http://www.volubis.com/2006/07/08/hello-world/&title=Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update"target="_blank"  title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Del.icio.us" onclick="javascript:urchinTracker ('/outbound/article/del.icio.us');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/delicious.png" title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Del.icio.us" alt="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Del.icio.us" /></a>&nbsp;<a href="http://digg.com/submit?phase=2&amp;url=http://www.volubis.com/2006/07/08/hello-world/&title=Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update"target="_self"  title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to digg" onclick="javascript:urchinTracker ('/outbound/article/digg.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/digg.png" title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to digg" alt="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to digg" /></a>&nbsp;<a href="http://furl.net/storeIt.jsp?t=Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update&amp;u=http://www.volubis.com/2006/07/08/hello-world/"target="_self"  title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to FURL" onclick="javascript:urchinTracker ('/outbound/article/furl.net');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/furl.png" title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to FURL" alt="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to FURL" /></a>&nbsp;<a href="http://blinklist.com/index.php?Action=Blink/addblink.php&amp;Name=Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update&amp;Description=Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update&amp;Url=http://www.volubis.com/2006/07/08/hello-world/"target="_self"  title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to blinklist" onclick="javascript:urchinTracker ('/outbound/article/blinklist.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/blinklist.png" title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to blinklist" alt="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to blinklist" /></a>&nbsp;<a href="http://user.my-tuts.com/tag-tutorial/?url=http://www.volubis.com/2006/07/08/hello-world/&title=Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update"target="_self"  title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to My-Tuts" onclick="javascript:urchinTracker ('/outbound/article/user.my-tuts.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/mytuts.png" title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to My-Tuts" alt="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to My-Tuts" /></a>&nbsp;<a href="http://reddit.com/submit?url=http://www.volubis.com/2006/07/08/hello-world/&amp;title=Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update"target="_self"  title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to reddit" onclick="javascript:urchinTracker ('/outbound/article/reddit.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/reddit.png" title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to reddit" alt="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to reddit" /></a>&nbsp;<a href="http://feedmelinks.com/categorize?from=toolbar&op=submit&name=Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update&url=http://www.volubis.com/2006/07/08/hello-world/&version=0.7"target="_self"  title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Feed Me Links!" onclick="javascript:urchinTracker ('/outbound/article/feedmelinks.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/feedmelinks.png" title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Feed Me Links!" alt="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Feed Me Links!" /></a>&nbsp;<a href="http://www.technorati.com/faves?add=http://www.volubis.com/2006/07/08/hello-world/"target="_self"  title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Technorati" onclick="javascript:urchinTracker ('/outbound/article/www.technorati.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/technorati.png" title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Technorati" alt="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Technorati" /></a>&nbsp;<a href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.volubis.com/2006/07/08/hello-world/&t=Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update"target="_self"  title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Yahoo My Web" onclick="javascript:urchinTracker ('/outbound/article/myweb2.search.yahoo.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/yahoo_myweb.png" title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Yahoo My Web" alt="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Yahoo My Web" /></a>&nbsp;<a href="http://www.newsvine.com/_wine/save?u=http://www.volubis.com/2006/07/08/hello-world/&h=Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update"target="_self"  title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Newsvine" onclick="javascript:urchinTracker ('/outbound/article/www.newsvine.com');"><img src="http://www.volubis.com/wp-content/plugins/social_bar/newsvine.png" title="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Newsvine" alt="Add 'Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Update' to Newsvine" /></a>&nbsp;</span></p>
<!-- Social Bar END -->]]></content:encoded>
			<wfw:commentRSS>http://www.volubis.com/2006/07/08/hello-world/feed/</wfw:commentRSS>
		</item>
	</channel>
</rss>
