<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PCI Guard Dog</title>
	<atom:link href="http://pciguarddog.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://pciguarddog.com</link>
	<description>Protecting Your Liability... Every Day</description>
	<lastBuildDate>Sat, 17 Apr 2010 00:11:42 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Breaking Down Subrequirement 1.1</title>
		<link>http://pciguarddog.com/blog/2010/04/16/breaking-subrequirement-1-1/</link>
		<comments>http://pciguarddog.com/blog/2010/04/16/breaking-subrequirement-1-1/#comments</comments>
		<pubDate>Fri, 16 Apr 2010 23:21:05 +0000</pubDate>
		<dc:creator>Desirea Herrera</dc:creator>
				<category><![CDATA[PCI-DSS Explained]]></category>

		<guid isPermaLink="false">http://pciguarddog.com/?p=43</guid>
		<description><![CDATA[The first requirement of PCI DSS is part of a 2 requirements directed at building and maintaining a secure network. Requirement 1: Install and maintain a firewall configuration to protect cardholder data. This requirement is broken down into 4 subrequirements of which 2 of them are broken down into further subrequirements.  All the subrequirements are directed towards installing and maintaining a firewall for protection. ]]></description>
			<content:encoded><![CDATA[<p>The first requirement of PCI DSS is part of a 2 requirements directed at building and maintaining a secure network. Requirement 1: Install and maintain a firewall configuration to protect cardholder data. This requirement is broken down into 4 subrequirements of which 2 of them are broken down into further subrequirements.  All the subrequirements are directed towards installing and maintaining a firewall for protection. </p>
<p>The first subrequirement is 1.1 defined as establishing firewalls and routers configuration standards based on Subrequirement 1.1&#8217;s subrequirements.  Firewalls and routers control outside access into the network and what information goes out of the network.  They also control access privileges allows to groups of users.  To better understand how networks work, watch the following 3d videos. While the movies are somewhat old, they give a basic understanding of network routers/switches and firewalls. Pay particular attention to the section on routers and firewalls at the top of the TCP/IP stack.</p>
<p><span class="youtube">
<iframe title="YouTube video player" class="youtube-player" type="text/html" width="425" height="344" src="http://www.youtube.com/embed/x9XWxD6cJuY?color1=d6d6d6&amp;color2=f0f0f0&amp;border=0&amp;fs=1&amp;hl=en&amp;modestbranding=1&amp;loop=&amp;showinfo=0&amp;iv_load_policy=3&amp;showsearch=0&amp;rel=1" frameborder="0" allowfullscreen></iframe>
</span><p><a href="http://www.youtube.com/watch?v=x9XWxD6cJuY">www.youtube.com/watch?v=x9XWxD6cJuY</a></p></p>
<p>You&#8217;ll note in the above video that the router and switches movie the informational packets around on the internal company network. These routers and switches must be correctly configured to grant or deny access to certain portions of the network. They can be located inside the network and just outside the network.</p>
<p>You should also note the Network Interface or Proxy (also known as a Proxy Server). The packet content is inspected as it goes into and out of the internal network. If you saw the unacceptable address which is &#8220;summarily&#8221; dealt with, the information regarding unacceptable addresses must be configured by a systems administrator for the proxy server. This would fall under this subrequirement 1.1.</p>
<p>The firewall is another layer that looks at the IP (information) packets to examine the content. Towards the end of the presentation, the firewall is configured for ports 80 and 25. The ports are similar to doors. Some doors are open and other doors are closed.  Configuring which doors are open and closed is up to a systems administrator or network administrator. The same goes for the internal firewall policeman.</p>
<p>Firewalls and routers can either be software based and/or hardware based. This simply means that they are either physical plugged in hardware which probably requries some configuration and/or software based or both. While this is all very well, configuring them is the core of Requirement 1.1.  The requirement clearly states a &#8220;standard&#8221; or basically a policy for configuring the firewalls and routers within a secure network. A company needs policies and procedures in place to have staff correctly configure the routers and firewalls to work as a cohesive unit in a network. It also supplies documentation that substantiates a company&#8217;s procedures.</p>
<p>It&#8217;s important to note that  a QSA (Qualified Security Assessor) will ask for documentation and diagrams of the firewall/router and network configurations. This helps them determine the scope of the network that must be compliant and what policies and procedures are being followed. The documentation itself is a requirement as well as the network configuration. The QSA will test the network against the documentation as well as security scans and tests.</p>
<p>In my next post, I&#8217;ll begin detailing the rest of Subrequirement 1.1.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-spaced shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.shareaholic.com/api/share/?title=Breaking+Down+Subrequirement+1.1&amp;link=http://pciguarddog.com/blog/2010/04/16/breaking-subrequirement-1-1/&amp;notes=The%20first%20requirement%20of%20PCI%20DSS%20is%20part%20of%20a%202%20requirements%20directed%20at%20building%20and%20maintaining%20a%20secure%20network.%20Requirement%201%3A%20Install%20and%20maintain%20a%20firewall%20configuration%20to%20protect%20cardholder%20data.%20This%20requirement%20is%20broken%20down%20into%204%20subrequirements%20of%20which%202%20of%20them%20are%20broken%20down%20into%20further%20subrequirements.%20%20All%20the%20subrequirements%20are%20directed%20towards%20installing%20and%20maintaining%20a%20firewall%20for%20protection.%20&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=219&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://pciguarddog.com/blog/2010/04/16/breaking-subrequirement-1-1/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://www.shareaholic.com/api/share/?title=Breaking+Down+Subrequirement+1.1&amp;link=http://pciguarddog.com/blog/2010/04/16/breaking-subrequirement-1-1/&amp;notes=The%20first%20requirement%20of%20PCI%20DSS%20is%20part%20of%20a%202%20requirements%20directed%20at%20building%20and%20maintaining%20a%20secure%20network.%20Requirement%201%3A%20Install%20and%20maintain%20a%20firewall%20configuration%20to%20protect%20cardholder%20data.%20This%20requirement%20is%20broken%20down%20into%204%20subrequirements%20of%20which%202%20of%20them%20are%20broken%20down%20into%20further%20subrequirements.%20%20All%20the%20subrequirements%20are%20directed%20towards%20installing%20and%20maintaining%20a%20firewall%20for%20protection.%20&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=2&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.shareaholic.com/api/share/?title=Breaking+Down+Subrequirement+1.1&amp;link=http://pciguarddog.com/blog/2010/04/16/breaking-subrequirement-1-1/&amp;notes=The%20first%20requirement%20of%20PCI%20DSS%20is%20part%20of%20a%202%20requirements%20directed%20at%20building%20and%20maintaining%20a%20secure%20network.%20Requirement%201%3A%20Install%20and%20maintain%20a%20firewall%20configuration%20to%20protect%20cardholder%20data.%20This%20requirement%20is%20broken%20down%20into%204%20subrequirements%20of%20which%202%20of%20them%20are%20broken%20down%20into%20further%20subrequirements.%20%20All%20the%20subrequirements%20are%20directed%20towards%20installing%20and%20maintaining%20a%20firewall%20for%20protection.%20&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=5&amp;tags=&amp;ctype=" rel="nofollow" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="http://www.shareaholic.com/api/share/?title=Breaking+Down+Subrequirement+1.1&amp;link=http://pciguarddog.com/blog/2010/04/16/breaking-subrequirement-1-1/&amp;notes=The%20first%20requirement%20of%20PCI%20DSS%20is%20part%20of%20a%202%20requirements%20directed%20at%20building%20and%20maintaining%20a%20secure%20network.%20Requirement%201%3A%20Install%20and%20maintain%20a%20firewall%20configuration%20to%20protect%20cardholder%20data.%20This%20requirement%20is%20broken%20down%20into%204%20subrequirements%20of%20which%202%20of%20them%20are%20broken%20down%20into%20further%20subrequirements.%20%20All%20the%20subrequirements%20are%20directed%20towards%20installing%20and%20maintaining%20a%20firewall%20for%20protection.%20&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=52&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-plaxo">
			<a href="http://www.shareaholic.com/api/share/?title=Breaking+Down+Subrequirement+1.1&amp;link=http://pciguarddog.com/blog/2010/04/16/breaking-subrequirement-1-1/&amp;notes=The%20first%20requirement%20of%20PCI%20DSS%20is%20part%20of%20a%202%20requirements%20directed%20at%20building%20and%20maintaining%20a%20secure%20network.%20Requirement%201%3A%20Install%20and%20maintain%20a%20firewall%20configuration%20to%20protect%20cardholder%20data.%20This%20requirement%20is%20broken%20down%20into%204%20subrequirements%20of%20which%202%20of%20them%20are%20broken%20down%20into%20further%20subrequirements.%20%20All%20the%20subrequirements%20are%20directed%20towards%20installing%20and%20maintaining%20a%20firewall%20for%20protection.%20&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=44&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Plaxo">Share this on Plaxo</a>
		</li>
		<li class="shr-twitter">
			<a href="http://www.shareaholic.com/api/share/?title=Breaking+Down+Subrequirement+1.1&amp;link=http://pciguarddog.com/blog/2010/04/16/breaking-subrequirement-1-1/&amp;notes=The%20first%20requirement%20of%20PCI%20DSS%20is%20part%20of%20a%202%20requirements%20directed%20at%20building%20and%20maintaining%20a%20secure%20network.%20Requirement%201%3A%20Install%20and%20maintain%20a%20firewall%20configuration%20to%20protect%20cardholder%20data.%20This%20requirement%20is%20broken%20down%20into%204%20subrequirements%20of%20which%202%20of%20them%20are%20broken%20down%20into%20further%20subrequirements.%20%20All%20the%20subrequirements%20are%20directed%20towards%20installing%20and%20maintaining%20a%20firewall%20for%20protection.%20&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=%24%7Btitle%7D+-+%24%7Bshort_link%7D+via+%40Shareaholic&amp;service=7&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://www.shareaholic.com/api/share/?title=Breaking+Down+Subrequirement+1.1&amp;link=http://pciguarddog.com/blog/2010/04/16/breaking-subrequirement-1-1/&amp;notes=The%20first%20requirement%20of%20PCI%20DSS%20is%20part%20of%20a%202%20requirements%20directed%20at%20building%20and%20maintaining%20a%20secure%20network.%20Requirement%201%3A%20Install%20and%20maintain%20a%20firewall%20configuration%20to%20protect%20cardholder%20data.%20This%20requirement%20is%20broken%20down%20into%204%20subrequirements%20of%20which%202%20of%20them%20are%20broken%20down%20into%20further%20subrequirements.%20%20All%20the%20subrequirements%20are%20directed%20towards%20installing%20and%20maintaining%20a%20firewall%20for%20protection.%20&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=54&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul><div style="clear: both;"></div><div class="shr-getshr" style="visibility:hidden;font-size:10px !important"><a target="_blank" href="http://www.shareaholic.com/?src=pub">Get Shareaholic</a></div><div style="clear: both;"></div></div>

<div class="su-linkbox" id="post-43-linkbox"><div class="su-linkbox-label">Link to this post!</div><div class="su-linkbox-field"><input type="text" value="&lt;a href=&quot;http://pciguarddog.com/blog/2010/04/16/breaking-subrequirement-1-1/&quot;&gt;Breaking Down Subrequirement 1.1&lt;/a&gt;" onclick="javascript:this.select()" readonly="readonly" style="width: 100%;" /></div></div>]]></content:encoded>
			<wfw:commentRss>http://pciguarddog.com/blog/2010/04/16/breaking-subrequirement-1-1/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Lack of Database Storage Does Not Make an Application PA DSS Compliant</title>
		<link>http://pciguarddog.com/blog/2010/04/06/lack-database-storage-application-pa-dss-compliant/</link>
		<comments>http://pciguarddog.com/blog/2010/04/06/lack-database-storage-application-pa-dss-compliant/#comments</comments>
		<pubDate>Tue, 06 Apr 2010 21:53:11 +0000</pubDate>
		<dc:creator>Desirea Herrera</dc:creator>
				<category><![CDATA[PA-DSS]]></category>

		<guid isPermaLink="false">http://pciguarddog.com/?p=33</guid>
		<description><![CDATA[A question came up on an email list about PA DSS software. There is still a lot of confusion about what it takes for an application to be PA DSS certified and what organizations need to have their software certified. Hopefully, I can clear up some of the confusion with this post.

]]></description>
			<content:encoded><![CDATA[<p>A question came up on an email list about PA DSS software. There is still a lot of confusion about what it takes for an application to be PA DSS certified and what organizations need to have their software certified. Hopefully, I can clear up some of the confusion with this post.</p>
<p>PA DSS stands for Payment Applicatin Data Security Standard. In July 2010 all merchants using a third party payment application must be using a PA DSS certified application. Be aware that all merchants must currently be PCI Compliant which includes other methods and procedures to attain. Simply using a PA DSS certified application does not make a merchant PCI compliant.</p>
<p>Any application licensed for use by a third party that collects , processes or stores card data is in scope of PA DSS. Getting compliant with PA DSS means that application vendor has followed standard security implementations outlined by OWASP. It also means the specific version has been tested in a &#8220;laboratory&#8221; by a PA DSS QSA certified by the PCI Security Standards Council. </p>
<p>There is confusion about what organizations must certify their applications, particularly open source vendors. The key is in the wording; Software vendors and others that develop secure payment applications that are <em>sold, distributed, or licensed to third parties. </em>While open source vendors do not sell their applications, they are distributed and licensed to third parties. Quite often the application is also drastically altered by third part developers for their clients.</p>
<p>The first key component is to not store sensitive information after authorization. While some applications might store the data then delete it after authorization, the QSA testing procedure centers around determining if that data has been deleted and is unrecoverable either through debug or log files.  A QSA might try to generate error conditions that cause error logs to be saved on a server where they can be extracted by other means.  Any and all historical data that may retain the credit card data must be deleted.  If credit card data is stored, it must be protected. Expired data must be securely purged from the system. </p>
<p>The point being that even if an application does not store credit card data inside a database, it does not mean that the data is not stored somewhere. There are other requirements for PA DSS and we will cover them in future installments herre on PCI Guard Dog.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-spaced shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.shareaholic.com/api/share/?title=Lack+of+Database+Storage+Does+Not+Make+an+Application+PA+DSS+Compliant&amp;link=http://pciguarddog.com/blog/2010/04/06/lack-database-storage-application-pa-dss-compliant/&amp;notes=A%20question%20came%20up%20on%20an%20email%20list%20about%20PA%20DSS%20software.%20There%20is%20still%20a%20lot%20of%20confusion%20about%20what%20it%20takes%20for%20an%20application%20to%20be%20PA%20DSS%20certified%20and%20what%20organizations%20need%20to%20have%20their%20software%20certified.%20Hopefully%2C%20I%20can%20clear%20up%20some%20of%20the%20confusion%20with%20this%20post.%0D%0A%0D%0A&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=219&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://pciguarddog.com/blog/2010/04/06/lack-database-storage-application-pa-dss-compliant/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://www.shareaholic.com/api/share/?title=Lack+of+Database+Storage+Does+Not+Make+an+Application+PA+DSS+Compliant&amp;link=http://pciguarddog.com/blog/2010/04/06/lack-database-storage-application-pa-dss-compliant/&amp;notes=A%20question%20came%20up%20on%20an%20email%20list%20about%20PA%20DSS%20software.%20There%20is%20still%20a%20lot%20of%20confusion%20about%20what%20it%20takes%20for%20an%20application%20to%20be%20PA%20DSS%20certified%20and%20what%20organizations%20need%20to%20have%20their%20software%20certified.%20Hopefully%2C%20I%20can%20clear%20up%20some%20of%20the%20confusion%20with%20this%20post.%0D%0A%0D%0A&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=2&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.shareaholic.com/api/share/?title=Lack+of+Database+Storage+Does+Not+Make+an+Application+PA+DSS+Compliant&amp;link=http://pciguarddog.com/blog/2010/04/06/lack-database-storage-application-pa-dss-compliant/&amp;notes=A%20question%20came%20up%20on%20an%20email%20list%20about%20PA%20DSS%20software.%20There%20is%20still%20a%20lot%20of%20confusion%20about%20what%20it%20takes%20for%20an%20application%20to%20be%20PA%20DSS%20certified%20and%20what%20organizations%20need%20to%20have%20their%20software%20certified.%20Hopefully%2C%20I%20can%20clear%20up%20some%20of%20the%20confusion%20with%20this%20post.%0D%0A%0D%0A&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=5&amp;tags=&amp;ctype=" rel="nofollow" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="http://www.shareaholic.com/api/share/?title=Lack+of+Database+Storage+Does+Not+Make+an+Application+PA+DSS+Compliant&amp;link=http://pciguarddog.com/blog/2010/04/06/lack-database-storage-application-pa-dss-compliant/&amp;notes=A%20question%20came%20up%20on%20an%20email%20list%20about%20PA%20DSS%20software.%20There%20is%20still%20a%20lot%20of%20confusion%20about%20what%20it%20takes%20for%20an%20application%20to%20be%20PA%20DSS%20certified%20and%20what%20organizations%20need%20to%20have%20their%20software%20certified.%20Hopefully%2C%20I%20can%20clear%20up%20some%20of%20the%20confusion%20with%20this%20post.%0D%0A%0D%0A&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=52&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-plaxo">
			<a href="http://www.shareaholic.com/api/share/?title=Lack+of+Database+Storage+Does+Not+Make+an+Application+PA+DSS+Compliant&amp;link=http://pciguarddog.com/blog/2010/04/06/lack-database-storage-application-pa-dss-compliant/&amp;notes=A%20question%20came%20up%20on%20an%20email%20list%20about%20PA%20DSS%20software.%20There%20is%20still%20a%20lot%20of%20confusion%20about%20what%20it%20takes%20for%20an%20application%20to%20be%20PA%20DSS%20certified%20and%20what%20organizations%20need%20to%20have%20their%20software%20certified.%20Hopefully%2C%20I%20can%20clear%20up%20some%20of%20the%20confusion%20with%20this%20post.%0D%0A%0D%0A&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=44&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Plaxo">Share this on Plaxo</a>
		</li>
		<li class="shr-twitter">
			<a href="http://www.shareaholic.com/api/share/?title=Lack+of+Database+Storage+Does+Not+Make+an+Application+PA+DSS+Compliant&amp;link=http://pciguarddog.com/blog/2010/04/06/lack-database-storage-application-pa-dss-compliant/&amp;notes=A%20question%20came%20up%20on%20an%20email%20list%20about%20PA%20DSS%20software.%20There%20is%20still%20a%20lot%20of%20confusion%20about%20what%20it%20takes%20for%20an%20application%20to%20be%20PA%20DSS%20certified%20and%20what%20organizations%20need%20to%20have%20their%20software%20certified.%20Hopefully%2C%20I%20can%20clear%20up%20some%20of%20the%20confusion%20with%20this%20post.%0D%0A%0D%0A&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=%24%7Btitle%7D+-+%24%7Bshort_link%7D+via+%40Shareaholic&amp;service=7&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://www.shareaholic.com/api/share/?title=Lack+of+Database+Storage+Does+Not+Make+an+Application+PA+DSS+Compliant&amp;link=http://pciguarddog.com/blog/2010/04/06/lack-database-storage-application-pa-dss-compliant/&amp;notes=A%20question%20came%20up%20on%20an%20email%20list%20about%20PA%20DSS%20software.%20There%20is%20still%20a%20lot%20of%20confusion%20about%20what%20it%20takes%20for%20an%20application%20to%20be%20PA%20DSS%20certified%20and%20what%20organizations%20need%20to%20have%20their%20software%20certified.%20Hopefully%2C%20I%20can%20clear%20up%20some%20of%20the%20confusion%20with%20this%20post.%0D%0A%0D%0A&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=54&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul><div style="clear: both;"></div><div class="shr-getshr" style="visibility:hidden;font-size:10px !important"><a target="_blank" href="http://www.shareaholic.com/?src=pub">Get Shareaholic</a></div><div style="clear: both;"></div></div>

<div class="su-linkbox" id="post-33-linkbox"><div class="su-linkbox-label">Link to this post!</div><div class="su-linkbox-field"><input type="text" value="&lt;a href=&quot;http://pciguarddog.com/blog/2010/04/06/lack-database-storage-application-pa-dss-compliant/&quot;&gt;Lack of Database Storage Does Not Make an Application PA DSS Compliant&lt;/a&gt;" onclick="javascript:this.select()" readonly="readonly" style="width: 100%;" /></div></div>]]></content:encoded>
			<wfw:commentRss>http://pciguarddog.com/blog/2010/04/06/lack-database-storage-application-pa-dss-compliant/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Understanding PCI Compliance in 4 Easy Steps</title>
		<link>http://pciguarddog.com/blog/2010/04/02/parts-pci-compliance/</link>
		<comments>http://pciguarddog.com/blog/2010/04/02/parts-pci-compliance/#comments</comments>
		<pubDate>Fri, 02 Apr 2010 00:45:21 +0000</pubDate>
		<dc:creator>Desirea Herrera</dc:creator>
				<category><![CDATA[PCI Compliance Info]]></category>
		<category><![CDATA[Guard Dog Says]]></category>

		<guid isPermaLink="false">http://pciguarddog.com/?p=24</guid>
		<description><![CDATA[Understanding PCI Compliance can be broken down into 4 simple parts. Each part pertains to the organizations, individuals and their roles within compliancy.]]></description>
			<content:encoded><![CDATA[<p>After yet another discussion about PCI Compliance and the issues pertaining to it with yet another client with little knowledge, I decided to try to break down compliancy in a clear direct manner. I hope this helps.</p>
<p>As mentioned in my previous post, the PCI Security Standards Council was founded by 5 major card brands: Visa, MasterCard, JCP, Discover and American Express. It was based on their separate programs as I mentioned.  The PCI SSC was founded to develop the standards by which everyone would measure how securely they would be keeping credit card holder data. Card Holder Data (chd) as it is known in the industry consists not only of the credit card number but the magnetic stripe data held on the card and the code on the back of the card.<strong> </strong></p>
<p><strong>Part One: Determine Your Organization&#8217;s Role </strong></p>
<p>The first part is to understand your organization&#8217;s role within PCI. Since most organizations can become members of the PCI SSC, they can participate in developing the standards by which compliancy is measured.</p>
<p> The Credit Card Brands determine the level of requirements for compliance under their own individual companies. Currently merchants are divided into 4 groups, Levels 1-4. However, each of the Credit Card Brands use different numbers to determine which level a merchant or service provider may fall within those levels.  All service providers and merchants should be sure to read over the individual Credit Card Brand company programs to understand which level they fall under.</p>
<p>Acquiring Banks are tasked with ensuring that their merchants are compliant with the credit card brand program requirements. They can be stringent or not depending on the bank. Some banks even have stricter requirements.</p>
<p>Service Providers fall in the same area as merchants as both must be compliant.  Service Providers offer services to help the merchant through collecting, storing, processing, and transmitting card holder data.</p>
<p>Merchants are those organizations offering goods and services for cash or credit. They hold merchant accounts at Acquiring Banks. When a data breech occurs, the merchant is the first one responsible.</p>
<p><strong>Part Two: Determine Your Organization&#8217;s Scope</strong></p>
<p>If your organization stores, processes and/or transmit card holder data on any of it&#8217;s computers, equipment or people, your organization is within scope. Just because card data is not processed on a computer does not mean it is not in scope. If a person writes down a card number, that process falls within PCI Compliance and requires training and policies in place to handle that data. Writing a card number on a piece of paper constitutes storage.</p>
<p>Some organizations would argue that they are not storing any data in a database, just sending the data forward to a payment gateway. However, if the data passes through a computer program, it is vulnerable. The reason is that error and debug log files are prone to saving that data into a flat file which is a target by hackers. If the software handles the card holder data, it&#8217;s in scope.</p>
<p>Many of the companies working towards compliancy focus first on narrowing the scope by isolating networks handling card holder data from other networks. They also limit the number of people allowed to handled card holder data.</p>
<p><strong>Part Three: Separating Development Roles Between People</strong></p>
<p>This part of developing a pci compliant environment isn&#8217;t mentioned much around the internet. It&#8217;s still important. It&#8217;s also why the single web developer will not be developing pci compliant ecommerce websites.  The development requirements for networks and software require multiple people. The person who develops the software must be using a development network while the testers and the deployment developers must also use separate networks and machines. The key is to have different people double checking the work.</p>
<p><strong>Part Four: Monitoring Continuancy</strong></p>
<p>Once everything is done, people are of the mindset that they are compliant and do not have to do anything else. This is not the case. PCI Compliance is an ongoing process requiring monitoring and fixing of systems as soon as a problem occurs. It requires servers being patched on a timely basis, and software to be continually tested and upgraded as needed. The consequences are harsh. If a company is out of compliance at the time of a breech, fines, forensic costs and legal fees go into the 10s of thousands of dollars monthly. Compliance is an ongoing process not a once a year event.</p>
<p>I hope this brief overview helps everyone out. It&#8217;s a start towards understanding your responsibilities under PCI Compliance.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-spaced shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.shareaholic.com/api/share/?title=Understanding+PCI+Compliance+in+4+Easy+Steps&amp;link=http://pciguarddog.com/blog/2010/04/02/parts-pci-compliance/&amp;notes=Understanding%20PCI%20Compliance%20can%20be%20broken%20down%20into%204%20simple%20parts.%20Each%20part%20pertains%20to%20the%20organizations%2C%20individuals%20and%20their%20roles%20within%20compliancy.&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=219&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://pciguarddog.com/blog/2010/04/02/parts-pci-compliance/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://www.shareaholic.com/api/share/?title=Understanding+PCI+Compliance+in+4+Easy+Steps&amp;link=http://pciguarddog.com/blog/2010/04/02/parts-pci-compliance/&amp;notes=Understanding%20PCI%20Compliance%20can%20be%20broken%20down%20into%204%20simple%20parts.%20Each%20part%20pertains%20to%20the%20organizations%2C%20individuals%20and%20their%20roles%20within%20compliancy.&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=2&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.shareaholic.com/api/share/?title=Understanding+PCI+Compliance+in+4+Easy+Steps&amp;link=http://pciguarddog.com/blog/2010/04/02/parts-pci-compliance/&amp;notes=Understanding%20PCI%20Compliance%20can%20be%20broken%20down%20into%204%20simple%20parts.%20Each%20part%20pertains%20to%20the%20organizations%2C%20individuals%20and%20their%20roles%20within%20compliancy.&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=5&amp;tags=&amp;ctype=" rel="nofollow" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="http://www.shareaholic.com/api/share/?title=Understanding+PCI+Compliance+in+4+Easy+Steps&amp;link=http://pciguarddog.com/blog/2010/04/02/parts-pci-compliance/&amp;notes=Understanding%20PCI%20Compliance%20can%20be%20broken%20down%20into%204%20simple%20parts.%20Each%20part%20pertains%20to%20the%20organizations%2C%20individuals%20and%20their%20roles%20within%20compliancy.&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=52&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-plaxo">
			<a href="http://www.shareaholic.com/api/share/?title=Understanding+PCI+Compliance+in+4+Easy+Steps&amp;link=http://pciguarddog.com/blog/2010/04/02/parts-pci-compliance/&amp;notes=Understanding%20PCI%20Compliance%20can%20be%20broken%20down%20into%204%20simple%20parts.%20Each%20part%20pertains%20to%20the%20organizations%2C%20individuals%20and%20their%20roles%20within%20compliancy.&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=44&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Plaxo">Share this on Plaxo</a>
		</li>
		<li class="shr-twitter">
			<a href="http://www.shareaholic.com/api/share/?title=Understanding+PCI+Compliance+in+4+Easy+Steps&amp;link=http://pciguarddog.com/blog/2010/04/02/parts-pci-compliance/&amp;notes=Understanding%20PCI%20Compliance%20can%20be%20broken%20down%20into%204%20simple%20parts.%20Each%20part%20pertains%20to%20the%20organizations%2C%20individuals%20and%20their%20roles%20within%20compliancy.&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=%24%7Btitle%7D+-+%24%7Bshort_link%7D+via+%40Shareaholic&amp;service=7&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://www.shareaholic.com/api/share/?title=Understanding+PCI+Compliance+in+4+Easy+Steps&amp;link=http://pciguarddog.com/blog/2010/04/02/parts-pci-compliance/&amp;notes=Understanding%20PCI%20Compliance%20can%20be%20broken%20down%20into%204%20simple%20parts.%20Each%20part%20pertains%20to%20the%20organizations%2C%20individuals%20and%20their%20roles%20within%20compliancy.&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=54&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul><div style="clear: both;"></div><div class="shr-getshr" style="visibility:hidden;font-size:10px !important"><a target="_blank" href="http://www.shareaholic.com/?src=pub">Get Shareaholic</a></div><div style="clear: both;"></div></div>

<div class="su-linkbox" id="post-24-linkbox"><div class="su-linkbox-label">Link to this post!</div><div class="su-linkbox-field"><input type="text" value="&lt;a href=&quot;http://pciguarddog.com/blog/2010/04/02/parts-pci-compliance/&quot;&gt;Understanding PCI Compliance in 4 Easy Steps&lt;/a&gt;" onclick="javascript:this.select()" readonly="readonly" style="width: 100%;" /></div></div>]]></content:encoded>
			<wfw:commentRss>http://pciguarddog.com/blog/2010/04/02/parts-pci-compliance/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>PCI Security Standards Council Founding Members</title>
		<link>http://pciguarddog.com/blog/2010/03/31/pci-security-standards-council-founding-members/</link>
		<comments>http://pciguarddog.com/blog/2010/03/31/pci-security-standards-council-founding-members/#comments</comments>
		<pubDate>Wed, 31 Mar 2010 23:56:02 +0000</pubDate>
		<dc:creator>Desirea Herrera</dc:creator>
				<category><![CDATA[PCI Compliance Info]]></category>
		<category><![CDATA[PCI SSC]]></category>

		<guid isPermaLink="false">http://pciguarddog.com/?p=16</guid>
		<description><![CDATA[Payment Card Industry Data Security Standard is the collective result of the 5 corporate brands including VISA, MasterCard, American Express, Discover and Japan Credit Bureau. It was founded in 2004 as a result of the combining of each company's security programs. The goal of the Payment Card Industry Security Standards Council is to add protection to card holder data that is stored, processed and/or transmitted within a merchant's software, networks, and personnel. ]]></description>
			<content:encoded><![CDATA[<p>Payment Card Industry Data Security Standard is the collective result of the 5 corporate brands including VISA, MasterCard, American Express, Discover and Japan Credit Bureau. It was founded in 2004 as a result of the combining of each company&#8217;s security programs. The goal of the Payment Card Industry Security Standards Council is to add protection to card holder data that is stored, processed and/or transmitted within a merchant&#8217;s software, networks, and personnel.</p>
<p>Visa&#8217;s program, Card Information Security Program or CISP was mandated by Visa in 2001. The program now centers around PCI DSS Compliance and compliance validation based on their own set of criteria. Members include financial institutions, merchants and service providers participating in the Visa payment system. Fines are levied against members who are found to be non-compliant at the time of data breach.  Wording on the website vaguely implies that that Visa may waive the fines if they are compliant at the time of breech but also further stipulates that members can prevent fines by staying compliant at all times.</p>
<p>The MasterCard SDP Program (Site Data Protection) was announced in 2001 with the goal of helping acquiring banks and merchants with their online systems.  SDP was a service offered by MasterCard rather than referring other companies to supply the service. Currently the program focuses on PCI DSS Compliance.  Acquiring banks verify PCI Compliance with each merchant depending on their level.</p>
<p>American Express Data Security Operating Policy was first implemented in 2002. American Express supports PCI DSS Compliance as a measure of minimum security. Note that upon perusing documenation, American Express indicates that a Level 4 merchant with another card logo acquirer may have a different level with American Express. Each company payment solution is separate from every other payment card.</p>
<p>The Discover Information Security &amp; Compliance (DISC) program was developed prior to PCI Security Standards Council of which Discover is a founding member. The program designates Discover&#8217;s roles and responsibilities in regards to PCI DSS Compliance. Again, the company determines which members must be PCI compliant, determines validation and reporting requirements, enforces compliance and responds to data compromises.  This sums up what each company is doing in regards to PCI DSS Compliance.</p>
<p>The JCB Data Security Program was started at the JCB International, a company based in Asian countries. The documentation on their website is slight. It focuses on &#8220;recommending&#8221; that a company use their program and become PCI DSS Compliant. The wording might be reflective of a different culture from European and American cultures but the intent is the same. They develop requirements for compliance with the PCI DSS. And again. the acquiring banks where merchant accounts are established are in charge of enforcing the requirements on the merchants. </p>
<p>These 5 major card brands started the PCI Security Standards Council which develops the standards of card holder data security. While the standards council develops the standards to which they all agree, each company has somewhat different requirements for compliance to the standards. Levels 1-4 merchants are defined somewhat differently by each company and require careful review. If a merchant accepts more than one brand, each brand&#8217;s compliancy requirements must be met to continue accepting that brand of credit card.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-spaced shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.shareaholic.com/api/share/?title=PCI+Security+Standards+Council+Founding+Members&amp;link=http://pciguarddog.com/blog/2010/03/31/pci-security-standards-council-founding-members/&amp;notes=Payment%20Card%20Industry%20Data%20Security%20Standard%20is%20the%20collective%20result%20of%20the%205%20corporate%20brands%20including%20VISA%2C%20MasterCard%2C%20American%20Express%2C%20Discover%20and%20Japan%20Credit%20Bureau.%20It%20was%20founded%20in%202004%20as%20a%20result%20of%20the%20combining%20of%20each%20company%27s%20security%20programs.%20The%20goal%20of%20the%20Payment%20Card%20Industry%20Security%20Standards%20Council%20is%20to%20add%20protection%20to%20card%20holder%20data%20that%20is%20stored%2C%20processed%20and%2For%20transmitted%20within%20a%20merchant%27s%20software%2C%20networks%2C%20and%20personnel.%20&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=219&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://pciguarddog.com/blog/2010/03/31/pci-security-standards-council-founding-members/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://www.shareaholic.com/api/share/?title=PCI+Security+Standards+Council+Founding+Members&amp;link=http://pciguarddog.com/blog/2010/03/31/pci-security-standards-council-founding-members/&amp;notes=Payment%20Card%20Industry%20Data%20Security%20Standard%20is%20the%20collective%20result%20of%20the%205%20corporate%20brands%20including%20VISA%2C%20MasterCard%2C%20American%20Express%2C%20Discover%20and%20Japan%20Credit%20Bureau.%20It%20was%20founded%20in%202004%20as%20a%20result%20of%20the%20combining%20of%20each%20company%27s%20security%20programs.%20The%20goal%20of%20the%20Payment%20Card%20Industry%20Security%20Standards%20Council%20is%20to%20add%20protection%20to%20card%20holder%20data%20that%20is%20stored%2C%20processed%20and%2For%20transmitted%20within%20a%20merchant%27s%20software%2C%20networks%2C%20and%20personnel.%20&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=2&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.shareaholic.com/api/share/?title=PCI+Security+Standards+Council+Founding+Members&amp;link=http://pciguarddog.com/blog/2010/03/31/pci-security-standards-council-founding-members/&amp;notes=Payment%20Card%20Industry%20Data%20Security%20Standard%20is%20the%20collective%20result%20of%20the%205%20corporate%20brands%20including%20VISA%2C%20MasterCard%2C%20American%20Express%2C%20Discover%20and%20Japan%20Credit%20Bureau.%20It%20was%20founded%20in%202004%20as%20a%20result%20of%20the%20combining%20of%20each%20company%27s%20security%20programs.%20The%20goal%20of%20the%20Payment%20Card%20Industry%20Security%20Standards%20Council%20is%20to%20add%20protection%20to%20card%20holder%20data%20that%20is%20stored%2C%20processed%20and%2For%20transmitted%20within%20a%20merchant%27s%20software%2C%20networks%2C%20and%20personnel.%20&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=5&amp;tags=&amp;ctype=" rel="nofollow" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="http://www.shareaholic.com/api/share/?title=PCI+Security+Standards+Council+Founding+Members&amp;link=http://pciguarddog.com/blog/2010/03/31/pci-security-standards-council-founding-members/&amp;notes=Payment%20Card%20Industry%20Data%20Security%20Standard%20is%20the%20collective%20result%20of%20the%205%20corporate%20brands%20including%20VISA%2C%20MasterCard%2C%20American%20Express%2C%20Discover%20and%20Japan%20Credit%20Bureau.%20It%20was%20founded%20in%202004%20as%20a%20result%20of%20the%20combining%20of%20each%20company%27s%20security%20programs.%20The%20goal%20of%20the%20Payment%20Card%20Industry%20Security%20Standards%20Council%20is%20to%20add%20protection%20to%20card%20holder%20data%20that%20is%20stored%2C%20processed%20and%2For%20transmitted%20within%20a%20merchant%27s%20software%2C%20networks%2C%20and%20personnel.%20&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=52&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-plaxo">
			<a href="http://www.shareaholic.com/api/share/?title=PCI+Security+Standards+Council+Founding+Members&amp;link=http://pciguarddog.com/blog/2010/03/31/pci-security-standards-council-founding-members/&amp;notes=Payment%20Card%20Industry%20Data%20Security%20Standard%20is%20the%20collective%20result%20of%20the%205%20corporate%20brands%20including%20VISA%2C%20MasterCard%2C%20American%20Express%2C%20Discover%20and%20Japan%20Credit%20Bureau.%20It%20was%20founded%20in%202004%20as%20a%20result%20of%20the%20combining%20of%20each%20company%27s%20security%20programs.%20The%20goal%20of%20the%20Payment%20Card%20Industry%20Security%20Standards%20Council%20is%20to%20add%20protection%20to%20card%20holder%20data%20that%20is%20stored%2C%20processed%20and%2For%20transmitted%20within%20a%20merchant%27s%20software%2C%20networks%2C%20and%20personnel.%20&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=44&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Plaxo">Share this on Plaxo</a>
		</li>
		<li class="shr-twitter">
			<a href="http://www.shareaholic.com/api/share/?title=PCI+Security+Standards+Council+Founding+Members&amp;link=http://pciguarddog.com/blog/2010/03/31/pci-security-standards-council-founding-members/&amp;notes=Payment%20Card%20Industry%20Data%20Security%20Standard%20is%20the%20collective%20result%20of%20the%205%20corporate%20brands%20including%20VISA%2C%20MasterCard%2C%20American%20Express%2C%20Discover%20and%20Japan%20Credit%20Bureau.%20It%20was%20founded%20in%202004%20as%20a%20result%20of%20the%20combining%20of%20each%20company%27s%20security%20programs.%20The%20goal%20of%20the%20Payment%20Card%20Industry%20Security%20Standards%20Council%20is%20to%20add%20protection%20to%20card%20holder%20data%20that%20is%20stored%2C%20processed%20and%2For%20transmitted%20within%20a%20merchant%27s%20software%2C%20networks%2C%20and%20personnel.%20&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=%24%7Btitle%7D+-+%24%7Bshort_link%7D+via+%40Shareaholic&amp;service=7&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://www.shareaholic.com/api/share/?title=PCI+Security+Standards+Council+Founding+Members&amp;link=http://pciguarddog.com/blog/2010/03/31/pci-security-standards-council-founding-members/&amp;notes=Payment%20Card%20Industry%20Data%20Security%20Standard%20is%20the%20collective%20result%20of%20the%205%20corporate%20brands%20including%20VISA%2C%20MasterCard%2C%20American%20Express%2C%20Discover%20and%20Japan%20Credit%20Bureau.%20It%20was%20founded%20in%202004%20as%20a%20result%20of%20the%20combining%20of%20each%20company%27s%20security%20programs.%20The%20goal%20of%20the%20Payment%20Card%20Industry%20Security%20Standards%20Council%20is%20to%20add%20protection%20to%20card%20holder%20data%20that%20is%20stored%2C%20processed%20and%2For%20transmitted%20within%20a%20merchant%27s%20software%2C%20networks%2C%20and%20personnel.%20&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=54&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul><div style="clear: both;"></div><div class="shr-getshr" style="visibility:hidden;font-size:10px !important"><a target="_blank" href="http://www.shareaholic.com/?src=pub">Get Shareaholic</a></div><div style="clear: both;"></div></div>

<div class="su-linkbox" id="post-16-linkbox"><div class="su-linkbox-label">Link to this post!</div><div class="su-linkbox-field"><input type="text" value="&lt;a href=&quot;http://pciguarddog.com/blog/2010/03/31/pci-security-standards-council-founding-members/&quot;&gt;PCI Security Standards Council Founding Members&lt;/a&gt;" onclick="javascript:this.select()" readonly="readonly" style="width: 100%;" /></div></div>]]></content:encoded>
			<wfw:commentRss>http://pciguarddog.com/blog/2010/03/31/pci-security-standards-council-founding-members/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Guard Dog has arrived.</title>
		<link>http://pciguarddog.com/blog/2010/03/30/hello-world/</link>
		<comments>http://pciguarddog.com/blog/2010/03/30/hello-world/#comments</comments>
		<pubDate>Tue, 30 Mar 2010 18:56:16 +0000</pubDate>
		<dc:creator>Desirea Herrera</dc:creator>
				<category><![CDATA[Guard Dog Says]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Welcome to Pciguarddog.com.
We&#8217;re getting ready to bring the information you need to get your clients PCI Compliant within their budget and within your abilities. We&#8217;ll review shopping carts, payment gateways, servers and provide you with news, events and updates under the PCI Compliance race.




		
			Blog this on Blogger
		
		
			Subscribe to the comments for this post?
		
		
			Share this on [...]]]></description>
			<content:encoded><![CDATA[<p>Welcome to <a href="http://pciguarddog.com/">Pciguarddog.com</a>.</p>
<p>We&#8217;re getting ready to bring the information you need to get your clients PCI Compliant within their budget and within your abilities. We&#8217;ll review shopping carts, payment gateways, servers and provide you with news, events and updates under the PCI Compliance race.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-spaced shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.shareaholic.com/api/share/?title=PCI+Guard+Dog+has+arrived.&amp;link=http://pciguarddog.com/blog/2010/03/30/hello-world/&amp;notes=Welcome%20to%20Pciguarddog.com.%0D%0A%0D%0AWe%27re%20getting%20ready%20to%20bring%20the%20information%20you%20need%20to%20get%20your%20clients%20PCI%20Compliant%20within%20their%20budget%20and%20within%20your%20abilities.%20We%27ll%20review%20shopping%20carts%2C%20payment%20gateways%2C%20servers%20and%20provide%20you%20with%20news%2C%20events%20and%20updates%20under%20the%20PCI%20Compliance%20race.&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=219&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://pciguarddog.com/blog/2010/03/30/hello-world/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://www.shareaholic.com/api/share/?title=PCI+Guard+Dog+has+arrived.&amp;link=http://pciguarddog.com/blog/2010/03/30/hello-world/&amp;notes=Welcome%20to%20Pciguarddog.com.%0D%0A%0D%0AWe%27re%20getting%20ready%20to%20bring%20the%20information%20you%20need%20to%20get%20your%20clients%20PCI%20Compliant%20within%20their%20budget%20and%20within%20your%20abilities.%20We%27ll%20review%20shopping%20carts%2C%20payment%20gateways%2C%20servers%20and%20provide%20you%20with%20news%2C%20events%20and%20updates%20under%20the%20PCI%20Compliance%20race.&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=2&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.shareaholic.com/api/share/?title=PCI+Guard+Dog+has+arrived.&amp;link=http://pciguarddog.com/blog/2010/03/30/hello-world/&amp;notes=Welcome%20to%20Pciguarddog.com.%0D%0A%0D%0AWe%27re%20getting%20ready%20to%20bring%20the%20information%20you%20need%20to%20get%20your%20clients%20PCI%20Compliant%20within%20their%20budget%20and%20within%20your%20abilities.%20We%27ll%20review%20shopping%20carts%2C%20payment%20gateways%2C%20servers%20and%20provide%20you%20with%20news%2C%20events%20and%20updates%20under%20the%20PCI%20Compliance%20race.&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=5&amp;tags=&amp;ctype=" rel="nofollow" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="http://www.shareaholic.com/api/share/?title=PCI+Guard+Dog+has+arrived.&amp;link=http://pciguarddog.com/blog/2010/03/30/hello-world/&amp;notes=Welcome%20to%20Pciguarddog.com.%0D%0A%0D%0AWe%27re%20getting%20ready%20to%20bring%20the%20information%20you%20need%20to%20get%20your%20clients%20PCI%20Compliant%20within%20their%20budget%20and%20within%20your%20abilities.%20We%27ll%20review%20shopping%20carts%2C%20payment%20gateways%2C%20servers%20and%20provide%20you%20with%20news%2C%20events%20and%20updates%20under%20the%20PCI%20Compliance%20race.&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=52&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-plaxo">
			<a href="http://www.shareaholic.com/api/share/?title=PCI+Guard+Dog+has+arrived.&amp;link=http://pciguarddog.com/blog/2010/03/30/hello-world/&amp;notes=Welcome%20to%20Pciguarddog.com.%0D%0A%0D%0AWe%27re%20getting%20ready%20to%20bring%20the%20information%20you%20need%20to%20get%20your%20clients%20PCI%20Compliant%20within%20their%20budget%20and%20within%20your%20abilities.%20We%27ll%20review%20shopping%20carts%2C%20payment%20gateways%2C%20servers%20and%20provide%20you%20with%20news%2C%20events%20and%20updates%20under%20the%20PCI%20Compliance%20race.&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=44&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Plaxo">Share this on Plaxo</a>
		</li>
		<li class="shr-twitter">
			<a href="http://www.shareaholic.com/api/share/?title=PCI+Guard+Dog+has+arrived.&amp;link=http://pciguarddog.com/blog/2010/03/30/hello-world/&amp;notes=Welcome%20to%20Pciguarddog.com.%0D%0A%0D%0AWe%27re%20getting%20ready%20to%20bring%20the%20information%20you%20need%20to%20get%20your%20clients%20PCI%20Compliant%20within%20their%20budget%20and%20within%20your%20abilities.%20We%27ll%20review%20shopping%20carts%2C%20payment%20gateways%2C%20servers%20and%20provide%20you%20with%20news%2C%20events%20and%20updates%20under%20the%20PCI%20Compliance%20race.&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=%24%7Btitle%7D+-+%24%7Bshort_link%7D+via+%40Shareaholic&amp;service=7&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://www.shareaholic.com/api/share/?title=PCI+Guard+Dog+has+arrived.&amp;link=http://pciguarddog.com/blog/2010/03/30/hello-world/&amp;notes=Welcome%20to%20Pciguarddog.com.%0D%0A%0D%0AWe%27re%20getting%20ready%20to%20bring%20the%20information%20you%20need%20to%20get%20your%20clients%20PCI%20Compliant%20within%20their%20budget%20and%20within%20your%20abilities.%20We%27ll%20review%20shopping%20carts%2C%20payment%20gateways%2C%20servers%20and%20provide%20you%20with%20news%2C%20events%20and%20updates%20under%20the%20PCI%20Compliance%20race.&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=54&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul><div style="clear: both;"></div><div class="shr-getshr" style="visibility:hidden;font-size:10px !important"><a target="_blank" href="http://www.shareaholic.com/?src=pub">Get Shareaholic</a></div><div style="clear: both;"></div></div>

<div class="su-linkbox" id="post-1-linkbox"><div class="su-linkbox-label">Link to this post!</div><div class="su-linkbox-field"><input type="text" value="&lt;a href=&quot;http://pciguarddog.com/blog/2010/03/30/hello-world/&quot;&gt;PCI Guard Dog has arrived.&lt;/a&gt;" onclick="javascript:this.select()" readonly="readonly" style="width: 100%;" /></div></div>]]></content:encoded>
			<wfw:commentRss>http://pciguarddog.com/blog/2010/03/30/hello-world/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

