Sunday, 13 May 2007

PCI News for PCI News sake

I am starting to feel that article writers are publishing PCI pieces just for the sake of filling out their quota.
This article outlines what PCI Self Assessment Questionnaire is and the need to complete it with the writer offering his own firm's services to do it I guess.
In this article the writer seems to be going for the "point out the obvious" award for the week. The title of the piece being "PCI Standard Drives Some CISO's Work This Year". I guess the "some CISO's" part of the title refers to the companies who are actually undertaking a PCI project this Year! His next article will be along the lines of "Smoking is bad for your health".

Saturday, 12 May 2007

PCI is just too hard..why FD CISO may not be 100% correct

This article over on SearchSecurity.com gauges the reaction to comments from First Data CISO Phil Mellinger, that PCI DSS compliance should essentially be made easier to attain, in order to get more merchants compliant.

It would be nice if a lot of things that were hard or essential, were made easier to achieve. Life would be so much better.

Time to board the PCI Ship

Yet another TJX related item on the web, highlighting the need to get with the program.

If you received a gift card of a high value from a shady character they could have been involved in the TJX breach. Read on to find out how Credit Card fraud of the TJX scale helps the gift card business boom.

Saturday, 5 May 2007

Sun is just giving it away...

Sun recently announced they would give away their Encryption Key Software. Read on a little further before you rush to take up this free offer, as it is only the the APIs they are preparing to share, "...which are how the KMS talks to an encryption device."

So everything else is gonna cost ya. Could this be a cunning way to promote the sale of more Sun hardware?

The KMS standard is still very much work in progress and this could turn into another classic betamax and vhs or even the more current HD-DVD vs Bluray battle.

Thursday, 3 May 2007

How much does a data breach cost.

Estimates Put TJX Fiasco at $4.5 Billion. And thats the optimistic number.
The Ponemon Institute, a think tank focused on record privacy and data protection, expects the TJX breach costs to be even higher. They cite costs in the range of $182.00 per record, based on research from November 2006 of the cost of breaches incurred in 31 separate incidents. For TJX, this translates to $8.6 billion.

The TJX data security breach: 10-K filing shows IAM and compliance mistakes

This article goes into some detail on how TJX didn't quite come up to scratch with compliance, and questions their internal security controls .
It again raises the question of how did the secret keys get compromised if data at rest was being encrypted, with the compromise going back to 2005 but not being discovered until December 2006.

Tuesday, 1 May 2007

Fraud in the Airline industry and plugging the gap

Very interesting article discussing the effect of fraud in the Airline industry based on responses to a survey of UK airlines. PCI features as the number 1 security requirement to meet. You'll need to register to the site.