controlgap.com

Posts about:

pci (5)

If You Take Credit Cards By Phone or Mail - You Need to Read About Visa's October Mandate | blog | Control Gap

PCI Rules Aren't the Only Ones You Need to Comply With

Most organizations concerned with payment compliance are focused on the PCI Data Security Standard (DSS), but PCI is only part of the story. Every card brand and payment association has their own operating rules and regulations that also need to be followed. Many of these rules and regulations fly below the radar of most people and organizations. However, sometimes these rule changes have far reaching impacts.

Read More

Understanding P2PE, NESA, E2EE, and PCI Compliance | blog,pci | Control Gap

Compliance simplification, what most people call “scope reduction”, can have huge benefits in terms of saving time, effort, headaches, and money. Merchants desire ways to simplify their PCI compliance as do the card brands, acquirers, and processors. When the PCI Council announced P2PE in 2011, there was an immediate and huge demand for approved P2PE solutions. It wasn’t that merchants wanted P2PE, rather they wanted the massive compliance simplification and risk reduction that P2PE promised to provide. QSAs and ISAs hoped for clear assessment requirements to make their merchant PCI DSS assessments simpler and less ambiguous. Late in 2016, the PCI Council announced NESA (Non-listed Encryption Assessments) and there was again an immediate and huge demand for this. The problem is that the demand is based on perception not understanding.

Read More

7 Things You Can Do To Deal With The Recent Format Preserving Encryption (FPE) Compromise | blog,pci,cryptography | Control Gap

Barely a year after NIST approved Format-Preserving Encryption (FPE) based on AES they've issued a news release that one of the approved modes has been broken. Since FPE is actively deployed within the payment industry this will have implications for payment security and users of this technology. But how bad is the problem? And if you happen to be affected, what can you do?

Read More

What The CIA WikiLeaks Dump Has In Common With PCI Compliance | blog,pci | Control Gap

In recent news, WikiLeaks exposed a huge trove of CIA documents.  Journalists and bloggers will of course have a field day with this and the general public will be spectators to another ongoing drama. From our perspective, thankfully, it sounds like WikiLeaks intends to work with vendors to fix vulnerabilities which will hopefully spare everyone from a shooting gallery of zero-day exploitation.

Read More

4 FAQs The PCI Security Standards Council Renamed in 2016

Anyone who relies on the PCI FAQ site for guidance may have noticed some changes in the last few months. In fact if you bookmarked some of the links you’ll have discovered that several went completely missing. The council periodically revises and clarifies the content of FAQs; however, this time they altered several of the questions which changed the permalinks. The main thrust of the change was to move away from the misleading term “Scope reduction”. You can still search on the “article number” to find your favorite FAQ, or you may need to use the search page options for “Most Recently Updated” under featured FAQ articles.

Read More

PCI Announces NESA - A Stepping Stone To P2PE | blog,pci | Control Gap

Earlier this month the PCI Security Standards Council published a new document as part of the Point-to-Point Encryption (P2PE) program. This initial guidance Assessment Guidance for Non-Listed Encryption Solutions introduces a new path into the P2PE solution space. This new initiative introduces the idea of a standardized way of reporting the strengths and weaknesses of solutions that don't fully meet P2PE requirements. The council is expected to provide more information over the next 3-4 months including a standardized report template that will be called a Non-Listed Encryption Solution Assessment or NESA.

Read More