Mostrando entradas con la etiqueta PCI DSS. Mostrar todas las entradas
Mostrando entradas con la etiqueta PCI DSS. Mostrar todas las entradas

domingo, 9 de agosto de 2020

PCI Compliant: ¿sus APIs necesitan de esta certificación PCI DSS?

 ¿Qué es la certificación PCI DSS?

PCI DSS (PaymentCardIndustry – Data Security Standard) es un estándar de seguridad de alto nivel, indicado para todo el ecosistema de empresas que graban o procesan datos de tarjetas de crédito y débito – cubriendo desde dispositivos electrónicos, hasta aplicaciones e infraestructuras.

Este estándar fue establecido por PCI Security Standards Council (PCI SSC), formado por las grandes compañías de tarjetas, para tornar el ecosistema de pagos electrónicos más seguro y garantizar la adhesión y confianza de los clientes.

 

¿Mis APIs necesitan estar PCI compliant?

Cualquier empresa que acepta pagos con tarjeta de crédito/débito, procesando o almacenando datos de estas tarjetas, es indicada para tener la certificación PCI DSS. Este escenario es cada vez más común, principalmente para empresas involucradas en sectores como MercadoMinorista, Servicios Financieros y proveedores de tecnología.

En el caso que sus APIs trafiquen alguna información relacionada a tarjetas de pagos, entonces es muy importante que usted y los colaboradores técnicos involucrados en la sustentación de estas APIs cumplan los requerimientos y posean la certificación PCI.

Más.. 


Fuente: sensedia.com

 



viernes, 19 de enero de 2018

¿Cómo afecta la nueva versión del Top Ten de OWASP el cumplimiento de PCI DSS v3.2?

Dentro de la comunidad de seguridad de la información, el proyecto OWASP (The Open Web Application Security Project - https://www.owasp.org) tiene un amplio reconocimiento debido a sus aportes en pro de la mejora de los controles para la protección de aplicaciones web. Uno de sus proyectos más importantes es el “OWASP Top Ten Project” (https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project), que, de forma periódica, lista los 10 riesgos más críticos en este tipo de aplicaciones. Este listado se establece con base en múltiples propuestas de firmas especializadas en seguridad de aplicaciones y de entrevistas a más de 500 individuos, cuyos datos son seleccionados y priorizados de acuerdo con estimaciones consensuadas de explotabilidad, detectabilidad e impacto, tanto técnico como al negocio. 

Figura 1. Variables para el cálculo del riesgo en aplicaciones (Fuente: OWASP)

La versión más reciente de este listado - OWASP Top 10 2017  https://www.owasp.org/images/7/72/OWASP_Top_10-2017_%28en%29.pdf.pdf - fue publicada el 20 de noviembre de 2017. Esta nueva versión, a diferencia de su predecesora, la versión 2013 (https://www.owasp.org/images/5/5f/OWASP_Top_10_-_2013_Final_-_Espa%C3%B1ol.pdf), ha tenido en cuenta el impacto de nuevas tecnologías en la industria y los cambios de arquitectura en aplicaciones web, tales como el uso de microservicios escritos en node.js y Spring Boot y el uso de marcos de trabajo web basados en JavaScript (Angular, Bootstrap, Electron y React).

De acuerdo con ello, la priorización de riesgos en esta nueva versión 2017 ha quedado de la siguiente manera, en comparación con la versión del 2013:


 Figura 2. Comparativo de los riesgos del OWASP Top Ten de 2013 y de 2017 (Fuente: OWASP)


Como se puede observar, se han priorizado tres nuevos riesgos (A4, A8 y A10), dos han sido fusionados (A4 y A7 del 2013 en el A5 de 2017) y dos han sido retirados (A8 y A10 del 2013) debido al bajo porcentaje de aplicaciones afectadas hoy en día. Todo lo anterior demuestra que, a pesar del gran esfuerzo realizado para la protección de la infraestructura de aplicaciones web, las amenazas constantemente van evolucionando, quizás más rápido que la propia tecnología.



Fuente: blog.isecauditors.com

martes, 9 de abril de 2013

New PCI Guidance for Mobile Payments

New merchant guidance from the Payment Card Industry Security Standards Council addresses card data protection for mobile devices used to accept payments, an area that poses increasing risks.
Banking institutions, as card issuers and acquirers, should use the guidance when assisting merchants with end-to-end mobile transaction security, says Steve Kenneally, who works in the Center for Regulatory Compliance at the American Bankers Association. 

New PCI Guidance for Mobile Payments 

 "Shining a spotlight on the need to improve payment security is always a great idea," he says. "Providing specific recommendations on how to achieve a higher level of security is even better."
As payments acquirers, banking institutions work with merchants to ensure the payment environment is secure, Kenneally says. "We expect the PCI guidelines to become one more tool that acquirers can use to increase merchant security," he adds.
Among mobile security considerations addressed in the PCI Council's new guidance are:
  • Risks associated with account data entry on mobile devices, account data residing or stored on the devices and account data transmitted through mobile devices;
  • Steps merchants should follow to ensure the physical and transactional security of mobile devices used for payment acceptance; and
  • Guidelines for components involved in payment acceptance, such as hardware, software, the use of payment acceptance solutions and customer relationship considerations.

Mobile for Payment Acceptance

"The PCI guidelines recognize that some of the qualities that make mobile acceptance so attractive to merchants, also make it attractive to fraudsters," Kenneally says. "The applications are simple to obtain, easy to use and, by definition, are easy to transport. It may be easier just to steal a merchant's phone or tablet, rather than hacking into the system. You can't say that about a gas pump or checkout line at the supermarket." 
More...

Fuente: www.bankinfosecurity.com

 

lunes, 10 de diciembre de 2012

Profesional de la Industria de Tarjetas de Pago - PCIP

El pasado mes de septiembre, el PCI SSC publicó los requisitos para su nuevo programa PCIP - Payment Card Industry Profesional es decir, Profesional de la Industria de Tarjetas de Pago que viene a cubrir el espacio que no cubren los QSA, ASV, ISA, PFI y QIR… es decir, básicamente consultoras/es que no trabajen en QSAC (compañías homologadas por el Council).
Esta credencial (que permite usar las siglas en las firmas y el logotipo correspondiente) tiene una gran ventaja y es que no depende de la empresa en la que el profesional trabaje, es decir, es personal y puede “viajar” con la persona si esta cambia de compañía, siempre que cumpla con los requisitos de renovación establecidos, lógicamente.

Fundamentalmente los requisitos para obtener la acreditación (pdf) son:
  1. Abonar la cuota correspondiente [995 USD por la solicitud]
  2. Aprobar el examen (se realiza online en las instalaciones de Pearson VUE y no se puede llevar ningún tipo de material de apoyo)  [395 USD por los derechos de examen]
  3. Tener al menos 2 años de experiencia y no haber tenido alguna conducta en el pasado que el Council considere incompatible con la acreditación.
Por cierto, si eres QSA o ISA solo tienes que cumplir con el primer punto, puesto que los restantes los has tenido que cumplir previamente.

Esto quiere decir que esta acreditación tiene un coste inicial de 1.390 USD y decimos inicial porque, si quieres recibir la formación diseñada al efecto, hay que añadir, otros 1.250 USD, es decir, nos iríamos a 2.640 USD. Por suerte, el mantenimiento no es muy caro, el mantenimiento solo cuesta 99 USD y los éxamenes de renovación (que son bienales) cuestan los mencionados 395 USD.
Para  finalizar, mencionar que el examen consta de 60 preguntas de elección múltiple, de momento, sólo en inglés y el tiempo para responderlo es de 90 minutos (1,5 minutos por pregunta).

Fuente:  http://blog.enplusone.com/

viernes, 16 de noviembre de 2012

Information Supplement: PCI DSS Risk Assessment Guidelines - November 2012

WAKEFIELD, Mass., November 16, 2012 —The PCI Security Standards Council (PCI SSC), a global, open industry standards body providing management of the Payment Card Industry Data Security Standard (PCI DSS), PIN Transaction Security (PTS) requirements and the Payment Application Data Security Standard (PA-DSS), today released the PCI DSS Risk Assessment Guidelines Information Supplement, a product of the PCI Risk Assessment Special Interest Group (SIG). Organizations planning and performing a risk assessment in accordance with PCI DSS 12.1.2 can use the information supplement to help identify threats and the associated vulnerabilities that could jeopardize the security of payment card data.





Objective
The objective of this document is to provide supplemental guidance and recommendations for performing a risk assessment in accordance with PCI DSS Requirement 12.1.2. A risk assessment, as required in the PCI DSS, is a formal process used by organizations to identify threats and vulnerabilities that could negatively impact the security of cardholder data.
 
This document does not replace, supersede, or extend any PCI DSS requirements; rather it provides guidance for organizations to identify, analyze, and document the risks that may affect their cardholder data environment (CDE).
 
Intended Audience
This guidance is intended for any organization that stores, processes, or transmits cardholder data (CHD). Examples include merchants, service providers, acquirers (merchant banks), and issuers. The intended audience includes large, medium, or small organizations
 
 
 

jueves, 13 de octubre de 2011

2011 Verizon Payment Card Industry Compliance Report

This report analyzes findings from actual Payment Card Industry (PCI) Data Security Standard (DSS) assessments conducted by Verizon’s team of Qualified Security Assessors (QSAs).

The report describes where these organizations stand in terms of overall compliance with the DSS and presents analysis around which specific requirements are most and least often in place during the assessment process. Furthermore, we overlay this assessment- centric data with findings from Verizon’s Investigative Response services to provide a unique risk-centric perspective on the compliance process. In a section new to this year’s edition, significance tests are conducted to examine the relationship (or lack thereof) between various organizational practices and initial compliance scores.

  • - Essentially unchanged from last year, only 21 percent of organizations were fully compliant at the time of their Initial Report on Compliance (IROC). This is interesting, since most were validated to be in compliance during their prior assessment. What causes this erosion over the course of the year?
  • - Also similar to our prior report, organizations met an average of 78 percent of all test procedures at the IROC stage, with some variation in compliance scores. For instance, about 20 percent of organizations passed less than half of the DSS requirements, while 60 percent scored above the 80 percent mark.
  • -  Organizations struggled most with the following PCI requirements: 3 (protect stored cardholder data), 10 (track and monitor access), 11 (regularly test systems and processes), and 12 (maintain security policies).
  • -  PCI Requirements 4 (encrypt transmissions over public networks), 5 (use and update anti-virus), 7 (restrict access to need-to- know), and 9 (restrict physical access) showed the highest implementation levels
  • -  Organizations do not appear to be prioritizing their compliance efforts based on the PCI DSS Prioritized Approach published by the PCI Security Standards Council—even less so than in the previous year.
  • -  A mini-study comparing governance practices to the initial compliance score suggests that the way organizations approach compliance significantly factors into their success.
  • -  Once again, organizations that suffered data breaches were much less likely to be compliant than a normal population of PCI clients.
  • - Analysis of the top threat actions leading to the compromise of payment card data continues to exhibit strong coverage within scope of the PCI DSS. For most of them, multiple layers of relevant controls exist across the standard.

Download


Link relacionado:
- Verizon PCI report finds firms struggling to maintain compliance
- Informe anual de PCI: la seguridad es un proceso







lunes, 9 de mayo de 2011

Las empresas que cumplen con los requerimientos PCI DSS sufren menos violaciones de datos

A pesar de ello, la mayoría de los profesionales no considera que el cumplimiento tenga un efecto positivo en la seguridad de su información

Imperva, compañía con foco en la protección de datos y sitios web, y distribuido en el mercado ibérico por Exclusive Networks, junto al Instituto Ponemon, ha dado a conocer los resultados de su segundo estudio relativo al impacto del Estándar de Seguridad de Datos para la Industria de Tarjetas de Pago (PCI DSS -Payment Card Industry’s Data Security Standards-).
El informe sobre Tendencias de Cumplimento PCI DSS -realizado en 2011 a 670 profesionales de multinacionales norteamericanas especializadas en seguridad TI- revela cómo el cumplimiento con PCI-DSS tiene un impacto positivo en la seguridad y protección de datos de las empresas.
En este sentido, y como principal conclusión se desprende que si bien una buena parte de las organizaciones que cumplen con el estándar PCI sufren menores violaciones, o no las padecen, la mayoría de los profesionales no percibe aún que PCI-DSS pueda suponer un elemento favorable en lo concerniente a la seguridad de la información.

Cumplimiento del estándar: una buena medida para reducir violaciones
Así las cosas, según el estudio, el 64% de las empresas que reconoce acatar el estándar PCI-DSS confirma no haber sufrido transgresiones relativas a los datos asociados a sus tarjetas de crédito en los últimos dos años, mientras que sólo el 38 % de las compañías que no cumplen pudieron afirmar lo mismo.
Cuando se trata de violaciones de datos globales (incidentes generales o relativos a la información contenida en la tarjeta de crédito), el 63% de las organizaciones que se encuentran en conformidad con el estándar no padeció más que una única violación de sus datos, en comparación con el 22% de las compañías que no lo acogen. Cabe destacar también que el 26% de las empresas que no lo ejecutan fueron víctimas de más de cinco delitos en el mismo período de tiempo.
Una percepción cínica sobre PCI-DSS A pesar de que la evidencia indica lo contrario, el 88% de los encuestados confirma no estar de acuerdo con que el cumplimiento de PCI-DSS pueda encerrar un efecto positivo en lo relativo al número de transgresiones experimentadas, y sólo el 39% cita la mejora en la seguridad de los datos como una de las propuestas de valor -contenida en PCI DSS- para los negocios.
De hecho, únicamente el 33% cree que el gasto destinado a cumplir con PCI-DSS queda cubierto por el beneficio que supone para la organización. El cumplimiento aumenta, a pesar de todo
El informe también recoge que dos tercios de los encuestados han logrado el cumplimiento sustancial con PCI-DSS. Esta cifra contrasta con la obtenida en el Estudio sobre Tendencias de Cumplimiento PCI DSS de 2009, cuando el número de participantes que confirmaba este hecho correspondía únicamente a la mitad de los profesionales preguntados, mientras que aproximadamente el 25% de los encuestados afirmaba que no había alcanzado nivel de cumplimiento alguno. En 2011, únicamente el 16% de las organizaciones sondeadas testifica no haberlo hecho.

Fuente:  NewsLetter E.Security 09 / 05 / 2011


miércoles, 27 de abril de 2011

Report: PCI DSS Compliance Trends Study, 2011

Imperva and The Ponemon Institute have completed a second study on the impact of the Payment Card Industry’s (PCI) Data Security Standards (DSS).







The 2011 PCI DSS Compliance Trends Study surveyed 670 US and multinational IT security practitioners on how efforts to comply with PCI-DSS affect an organization’s data protection and security. This report is essential for any organization attempting to comply PCI and wants to benchmark their efforts with their peers.

This year's report shows that:
  • - The majority of PCI compliant organizations suffer fewer or no breaches, most practitioners still do not perceive the mandate to have a positive impact on data security.
  • - About 64 percent of PCI-DSS compliant organizations reported suffering no data breaches involving credit card data over the past two years, while only 38 percent of non-compliant organizations reported suffering no breaches involving credit card data over the same period.
  • - Certain technologies are adopted more quickly than others to comply with PCI. For example, code review saw the biggest decline in adoption.

Download


 Link relacionado:
PCI's Impact on Security Quantified





 

jueves, 10 de marzo de 2011

Metasploit 3.6 Aims for Compliance

The Metasploit vulnerability testing framework is out with a major update this week, providing new capabilities to help enterprises ensure security compliance.
Metasploit is available in three versions, Express, Pro and Open Source edition, and all three benefit from new features and capabilities. Metasploit Pro users gain a new PCI compliance capability that is intended to help organizations validate their readiness for the new PCI-DSS (Payment Card Industry Data Security Standard) 2.0 requirements.
"The Metasploit Pro PCI-DSS 2.0 report is designed to be used an appendix to a comprehensive report," HD Moore, Rapid7 Chief Security Officer and Metasploit chief architect told InternetNews.com. "Instead of providing a full list of pass/fail items, it is focused on known fail conditions based on the results of the penetration test."



Visto en esecurityplanet.com






martes, 2 de noviembre de 2010

Las novedades de PCI DSS 2.0 en SIC

En el número de Noviembre de SIC, y coincidiendo con la publicación de las versión 2.0 de PCI DSS, publicamos un artículo donde Miguel ángel Domínguez analiza al detalle todas las novedades de la nueva norma: mejoras, detalles y ampliaciones (pocas estas últimas) se han incorporado en la nueva versión y todo aquel que esté trabajando en su implantación y cumplimiento por dicha norma (y que no pueda asistir a la 2ª Jornada sobre Seguridad en Medios de Pago, que organizamos el próximo 10 de noviembre), sin duda encontrará muy interesante.




El artículo completo

martes, 26 de octubre de 2010

80% of web applications can't pass a PCI audit

During recent in-depth security reviews of almost 3,000 applications, it was discovered that over 80% of web applications don't comply with the OWASP Top 10 list of critical web application errors and subsequently couldn't pass a PCI compliance audit. Obviously, application security still has a long way to go. It's overly simplistic, but being in compliance with regulations like PCI provides a good baseline of security. You can still be hacked if you are in compliance with PCI or HIPAA or anything else, but the chances that your organization will find itself in the news because of a breach are significantly reduced.  There are far easier targets.

It was also discovered that over 80% of third-party code failed security tests. According to the report, anywhere from 30-70% of internally developed applications are comprised of third-party components. That number should clarify the danger of insecure third-party code just as much as Siemens Stuxnet did (probably the most famous to date example of a vulnerability resulting from insecure third-party code).

What will seem like common-sense after you hear it...open-source software is more secure than either its in-house or commercial brethren. A lot. A whopping 93% of open source applications did not pose a potential security risk. Apparently many eyes (and many testers) can help to create more secure software.

As we’ve repeatedly seen over the past couple of years, Cross-Site Scripting remains main web application vulnerability. The report notes that a full 51% of the vulnerabilities discovered in these applications was Cross-Site Scripting.

Something of a  bright spot, though...the average time for organizations to fix security defects has now shrunk from 36-82 days to 12-19. That's a significant drop. At least it's a start...and a good one, at that.

http://www.darkreading.com/security_monitoring/security/app-security/showArticle.jhtml?articleID=227...


Visto en HP


sábado, 23 de octubre de 2010

Check PCI Compliance - VMware Compliance Checker

Check the compliance of your IT infrastructure against specific standards and best practices that are applicable for the environment. The Compliance Checker is a free, downloadable, fully-functional product for checking compliance of your environment to help you ensure that it remains secure and compliant.
Compliance Checker for PCI DSS v1.2 is a free, downloadable tool that provides a real-time compliance check for multiple Microsoft Windows servers and desktops against PCI DSS v1.2 requirements. The tool collects data from these servers and desktops and produces a detailed summary of which requirements are met and which ones are not. This summary of PCI DSS v1.2 compliance can be used to drive a remediation/mitigation strategy and help prepare for audits.

Download



jueves, 21 de octubre de 2010

2010 PCI Compliance Report - Just Released (Verizon)



VERIZON 2010 PAYMENT CARD INDUSTRY COMPLIANCE REPORT
A study conducted by the Verizon PCI and RISK Intelligence teams

Quick Summary
This report analyzes findings from actual Payment Card Industry Data Security Standard (PCI DSS) assessments conducted by Verizon’s team of Qualified Security Assessors (QSAs). The report examines the progress of organizations toward the goal of compliance and includes topics such as how and why some seem to struggle more than others. Also presented are statistics around which PCI DSS requirements and sub-requirements are most and least often in place (or compensated for) during the assessment process. Finally, the report overlays PCI assessment data with findings from Verizon’s Investigative Response services to provide a unique risk-centric slant on the compliance process.


Download (PDF - EN, 29 Pag)


viernes, 3 de septiembre de 2010

Insecure Magazine # 27 (Septiembre 2010)



Contenido

  • - Review: BlockMaster SafeStick secure USB flash drive
  • - The devil is in the details: Securing the enterprise against the cloud
  • - Cybercrime may be on the rise, but authentication evolves to defeat it
  • - Learning from bruteforcers
  • - PCI DSS v1.3: Vital to the emerging demand for virtualization and cloud security
  • - Security testing - the key to software quality
  • - A brief history of security and the mobile enterprise
  • - Payment card security: Risk and control assessments
  • - Security as a process: Does your security team fuzz?
  • - Book review: Designing Network Security, 2nd Edition
  • - Intelligent security: Countering sophisticated fraud

Download

jueves, 3 de diciembre de 2009

GreenSQL - Free database firewall protects PostgreSQL and MySQL


Version 1.2 of GreenSQL is now able to protect PostgreSQL as well as MySQL. GreenSQL is designed to protect databases against SQL injection attacks and other unauthorised changes, in a similar fashion to a firewall protecting a network against TCP/IP outside attacks. The new version also provides a graphical user interface for monitoring the database firewall.

GreenSQL is run as a proxy between applications and database servers. It actively analyses the incoming SQL commands and can then act on the results according to the selected mode. Simulation mode blocks nothing but records the analysis in GreenSQL's own database and notifies the administrator of suspicious queries. Blocking mode on the other hand uses the database and it's heuristic engine to find and block suspicious queries.
GreenSQL sits as a proxy between the application and the database




A learning mode allows fine tuning of the engine and an active protection mode allow administrators to automatically block SQL queries that the database firewall hasn't seen before. The database firewall detects the risk of a query by analysing it's access to sensitive tables, presence of comments, empty passwords and 'or' tokens in the query or expressions that always return true (such as 1=1). It is also sensitive to administrative commands, commands that change the structure of the database or ones that access system files. A whitelist allows these "illegal" queries to be processed.

GreenSQL is available as binaries to download for CentOS 5.4, Debian 5.0, Fedora 12, Ubuntu 8.10 and 9.04, and as GPL2 licensed source code.


Visto en h-online.com

lunes, 9 de noviembre de 2009

Web Application Security Scanner Evaluation Criteria Version 1.0


Web Application Security Scanners are automated tools to test web applications for common security problems such as Cross-Site Scripting, SQL Injection, Directory Traversal, insecure configurations, and remote command execution vulnerabilities. These tools crawl a web application and locate application layer vulnerabilities and weaknesses, either by manipulating HTTP messages or by inspecting them for suspicious attributes.
A large number of web application scanning tools are available, both commercial and open source. Effective use of these tools is an important part of a thorough web application security assessment, and regular security scans are required to comply with security requirements such as section 6.6 of the Payment Card Industry Data Security Standard (PCI-DSS).
The Web Application Security Scanner Evaluation Criteria (WASSEC) is a set of guidelines to evaluate web application scanners on their ability to effectively test web applications and identify vulnerabilities. It covers areas such as crawling, parsing, session handling, testing, and reporting.

The goal of the WASSEC is to create a vendor-neutral document to help guide web application security professionals during web application scanner evaluations. This document provides a comprehensive list of features that should be considered when conducting a web application security scanner evaluation. Different users will place varying levels of importance on each feature, and the WASSEC provides the user with the flexibility to take this comprehensive list of potential scanner features, narrow it down to a shorter list of features that are important to the user, assign weights to each feature, and conduct a formal evaluation to determine which scanning solution best meets the user's needs.
The aim of this document is not to define a list of requirements that all web application security scanners must provide in order to be considered a "complete" scanner, and evaluating specific products and providing the results of such an evaluation is outside the scope of the WASSEC project. Instead, this project provides the tools and documentation to enable anyone to evaluate web application security scanners and choose the product that best fits their needs. NIST Special Publication 500-269, "Software Assurance Tools: Web Application Security Scanner Functional Specification Version 1.0", contains minimal requirements for mandatory and optional web application scanner features. This document can be found at https://samate.nist.gov.

TABLE OF CONTENTS
Introduction
Contributors
Evaluation Criteria
1. Protocol Support
2. Authentication
3. Session Management
4. Crawling
5. Parsing
6. Testing
7. Command and Control
8. Reporting
Appendix A: Advice for Conducting a Scanner Evaluation
Appendix B: License


Download - Web Application Security Scanner Evaluation Criteria Version 1.0

Download the Evaluation Spreadsheet

List of Web Application Security Scanners



Post relacionado:
-WASC - Consorcio de Seguridad de Aplicaciones Web - The Web Application Security Consortium)

viernes, 27 de marzo de 2009

Realtime Nexus Digital Library

Realtime Nexus Digital Library is the the world's leading source of free, expert technology ebooks and guides.
Realtime eBooks and guides are published in "real-time", offering the most timely knowledge on many IT topics.
IT professionals may download any of the publications offered in our library at no charge, and all publications are available in PDF format.
Publications - Featured Publications for Security and Compliance:
    The Administrator Shortcut Guide to Email Protection
    The Administrator Shortcut Guide to User Management and Provisioning
    The Definitive Guide to Information Theft Prevention
    The Definitive Guide to Controlling Malware, Spyware, Phishing, and Spam
    The Definitive Guide to Securing Windows in the Enterprise
    The Definitive Guide to Security Inside the Perimeter
    The Definitive Guide to Exchange Disaster Recovery and Availability
    The Definitive Guide to Active Directory Troubleshooting and Auditing
    The Definitive Guide to Email Management and Security
    The Definitive Guide to Identity Management
    The Definitive Guide to Service-Oriented Systems Management
    The Essentials Series: The Business Imperatives of Compliance in the UK
    The Essentials Series: Eliminating Administrator Rights
    The Essentials Series: Email-Centric Data Loss Prevention
    The Essentials Series: Enterprise Identity and Access Management
    The Essentials Series: IT Compliance
    The Essentials Series: IT Compliance - Volume Two
    The Essentials Series: Managing Access to Privileged Accounts
    The Essentials Series: Modern Malware Threats and Countermeasures
    The Essentials Series: Messaging and Web Security
    The Essentials Series: Messaging and Web Security - Volume Two
    The Essentials Series: Messaging and Web Security - Volume Three
    The Essentials Series: Security Information Management
    The Essentials Series: Selecting the Right Network Threat Management Solution
    The Essentials Series: PCI Compliance
    The Essentials Series: Understanding and Responding to Network Threats
    The Essentials Series: Virtual Security Concerns & Solutions
    The Shortcut Guide to Automating Network Management and Compliance
    The Shortcut Guide to Business Security Measures Using SSL
    The Shortcut Guide to Certificates in the Enterprise
    The Shortcut Guide to Extended Validation of SSL Certificates
    The Shortcut Guide to Managing Certificate Lifecycles
    The Shortcut Guide to Network Compliance and Security
    The Shortcut Guide to Prioritizing Security Spending
    The Shortcut Guide to Protecting Business Internet Usage
    The Shortcut Guide to Securing Automated File Transfers
    The Tips and Tricks Guide to Software Security Assurance
    The Tips and Tricks Guide to Secure Content Appliances
    The Tips and Tricks Guide to Secure Messaging 

Descarga de libros (Requiere registro)

miércoles, 28 de enero de 2009

PCI Compliance for dummies (Free Book)


Download this Free Book: Get the Facts on PCI Compliance and Learn How to Comply with the PCI Data Security Standard

Complying with the PCI Data Security Standard may seem like a daunting task for merchants. This book is a quick guide to understanding how to protect cardholder data and comply with the requirements of PCI - from surveying the standard's requirements to detailing steps for verifying compliance.

PCI Compliance for Dummies arms you with the facts, in plain English, and shows you how to achieve PCI Compliance. In this book you will discover:

  • - What the Payment Card Industry Data Security Standard (PCI DSS) is all about
  • - The 12 Requirements of the PCI Standard
  • - How to comply with PCI
  • - 10 Best-Practices for PCI Compliance
  • - How QualysGuard PCI simplifies PCI compliance
Contact Information

Download