<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PCI DSS Compliance &#38; QSA Services by 7Safe</title>
	<atom:link href="http://pci-dss.7safe.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://pci-dss.7safe.com</link>
	<description>7Safe provide PCI DSS compliance services as a PCI QSA (Qualified Security Assessor) together with PCI &#38; Secure Coding training and PAN scanning (7Seec).</description>
	<lastBuildDate>Fri, 02 Sep 2011 15:56:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>To panic or not to panic…</title>
		<link>http://pci-dss.7safe.com/to-panic-or-not-to-panic%e2%80%a6/</link>
		<comments>http://pci-dss.7safe.com/to-panic-or-not-to-panic%e2%80%a6/#comments</comments>
		<pubDate>Thu, 01 Sep 2011 16:59:05 +0000</pubDate>
		<dc:creator>7Safe Limited</dc:creator>
				<category><![CDATA[News & Events]]></category>
		<category><![CDATA[barclaycard]]></category>
		<category><![CDATA[payment card security]]></category>

		<guid isPermaLink="false">http://pci-dss.7safe.com/?p=834</guid>
		<description><![CDATA[Recently, there has been a lot of hype in information security circles around the advanced persistent threat (APT) and the advanced evasion technique (AET), partly due to the high profile breaches we have seen this year. I will not offer a definition here as many industry experts have done an extremely good job of it [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, there has been a lot of hype in information security circles around the advanced persistent threat (APT) and the advanced evasion technique (AET), partly due to the high profile breaches we have seen this year. I will not offer a definition here as many industry experts have done an extremely good job of it (for example, see http://www.antievasion.com/faq) and I do not dispute the fact that these threats exist and sophisticated techniques are now being employed.</p>
<p>However, let’s remember one thing: AETs depend on a vulnerable system inside the target environment.</p>
<p>Let’s be clear, criminals generally don’t need to resort to APT and AET to infiltrate a vulnerable environment: The Verizon DBIR 2011 states that 87% of attacks could be prevented using simple, proactive measures.</p>
<p>APTs (through AETs) are likely to target organisations where they would achieve the most financial or political gain. In my book, this means that the first step would be to understand what the critical assets are and the second one to understand the infrastructure deployed for those critical assets. Predictably, as you may expect it coming from me, the third step should be to protect the assets based on a risk assessment reflecting the organisation’s risk appetite.</p>
<p>So whilst it is a good idea to check whether your intrusion prevention appliances are or will be anti-evasion ready and capable of receiving current AET patches and security updates continuously and dynamically (and again, a lot of good research has been done in this area), look inside first&#8230; Have you fixed the basics?</p>
<p>Author: Neira Jones, Head of Payment Security &#8211; Barclaycard </p>
]]></content:encoded>
			<wfw:commentRss>http://pci-dss.7safe.com/to-panic-or-not-to-panic%e2%80%a6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Payment Security Event : Reducing PCI Risk with a New Approach</title>
		<link>http://pci-dss.7safe.com/payment-security-event-reducing-pci-risk-with-a-new-approach/</link>
		<comments>http://pci-dss.7safe.com/payment-security-event-reducing-pci-risk-with-a-new-approach/#comments</comments>
		<pubDate>Wed, 31 Aug 2011 16:30:27 +0000</pubDate>
		<dc:creator>7Safe Limited</dc:creator>
				<category><![CDATA[News & Events]]></category>

		<guid isPermaLink="false">http://pci-dss.7safe.com/?p=829</guid>
		<description><![CDATA[7Safe is excited to announce another eagerly anticipated technology-focused PCI security event in collaboration with leading card acquirer, Barclaycard, on 29th September 2011 in London. Over 200 attendees are predicted to attend to hear valuable insights into Barclaycard’s new Risk Reduction Programme, a valid alternative to the traditional PCI DSS methodology. Practical and interactive applications [...]]]></description>
			<content:encoded><![CDATA[<p>7Safe is excited to announce another eagerly anticipated technology-focused PCI security event in collaboration with leading card acquirer, Barclaycard, on 29<sup>th</sup> September 2011 in London.</p>
<p>Over 200 attendees are predicted to attend to hear valuable insights into Barclaycard’s new Risk Reduction Programme, a valid alternative to the traditional PCI DSS methodology.</p>
<p>Practical and interactive applications of innovative technologies will be demonstrated and explored to help reduce risk and fraud as part of the programme. Furthermore, integral reasons for adopting the Risk Reduction Programme will be presented by 7Safe’s Dan Haagman who will engage the audience to explain key business benefits for merchants, and the common issues that underpin managing compliance.</p>
<p>With a fantastic line up of further speakers including Visa, MasterCard, American Express, and the PCI SSC, the event will provide an exciting opportunity for you to gain knowledge and network with fellow attendees.</p>
<p>Merchants are invited to join us at One Drummond Street, London from 9.30am – 4.00pm on Wednesday 29<sup>th</sup> September.</p>
<p>Pre-register: <a href="mailto:marketing@7safe.com">marketing@7safe.com</a>. This event is free but registration is required. Book now to avoid disappointment.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://pci-dss.7safe.com/payment-security-event-reducing-pci-risk-with-a-new-approach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SENIOR PCI CONSULTANT</title>
		<link>http://pci-dss.7safe.com/senior-pci-consultant/</link>
		<comments>http://pci-dss.7safe.com/senior-pci-consultant/#comments</comments>
		<pubDate>Fri, 20 May 2011 11:30:55 +0000</pubDate>
		<dc:creator>7Safe Limited</dc:creator>
				<category><![CDATA[News & Events]]></category>
		<category><![CDATA[PCI Consultancy]]></category>
		<category><![CDATA[Senior PCI Consultant]]></category>

		<guid isPermaLink="false">http://pci-dss.7safe.com/?p=821</guid>
		<description><![CDATA[This is a great opportunity for an experienced QSA to join our evolving PCI consultancy and undertake security audits and compliance assessments for a wide range of blue chip merchants and service providers.  We offer independent expert advice and pragmatic solutions through establishing long-term partnerships with our clients in order to help them meet their transformation [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>This is a great opportunity for an experienced QSA to join our evolving PCI consultancy and undertake security audits and compliance assessments for a wide range of blue chip merchants and service providers. </p>
<p>We offer independent expert advice and pragmatic solutions through establishing long-term partnerships with our clients in order to help them meet their transformation challenges with confidence.</p>
<p><a href="http://www.corporate.7safe.com/senior-pci-consultant">Find out more about this exciting opportunity </a></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://pci-dss.7safe.com/senior-pci-consultant/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>“Security Matters” is almost here to bring you Interactive Insights into Risk-Management</title>
		<link>http://pci-dss.7safe.com/%e2%80%9csecurity-matters%e2%80%9d-is-almost-here-to-bring-you-interactive-insights-into-risk-management/</link>
		<comments>http://pci-dss.7safe.com/%e2%80%9csecurity-matters%e2%80%9d-is-almost-here-to-bring-you-interactive-insights-into-risk-management/#comments</comments>
		<pubDate>Thu, 12 May 2011 13:30:29 +0000</pubDate>
		<dc:creator>7Safe Limited</dc:creator>
				<category><![CDATA[News & Events]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[risks]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://pci-dss.7safe.com/?p=811</guid>
		<description><![CDATA[7Safe are set to collaborate with Barclaycard at this year’s exciting “Security Matters” event on Thursday 30th June, with a theme expanding on  “Knowing the Risks” to a very significant anticipated audience who will be keen for answers and to interact.  With speakers including Dan Haagman, (7Safe Co-Founder and Director), Neira Jones (Head of Payment Card [...]]]></description>
			<content:encoded><![CDATA[<p>7Safe are set to collaborate with Barclaycard at this year’s exciting “Security Matters” event on Thursday 30th June, with a theme expanding on  “Knowing the Risks” to a very significant anticipated audience who will be keen for answers and to interact. </p>
<p>With speakers including Dan Haagman, (7Safe Co-Founder and Director), Neira Jones (Head of Payment Card Security, Barclaycard), Stanley Skoglund (Senior Vice President, Visa Europe) and Jeremy King (European Managing Director, PCI SSC), many customers have already pre-booked.</p>
<p>“Security Matters” will be using innovative voting technology to enable instant “pulse taking” on topics such as eDiscovery and risk prioritisation.  Results of the surveys will be instant and go live on Twitter.</p>
<p>Additionally, the day will provide a range of new, innovative and award winning technologies that can help you keep your information assets safe.</p>
<p>Customer, prospects and partners are welcome to join us for a highly informative, interactive and thought provoking day at The Royal College of Surgeons from 9.30am-2.00pm in London on Thursday 30th June.</p>
<p>Pre-register: <a href="mailto:marketing@7safe.com">marketing@7safe.com</a> This event is free but registration is required.</p>
]]></content:encoded>
			<wfw:commentRss>http://pci-dss.7safe.com/%e2%80%9csecurity-matters%e2%80%9d-is-almost-here-to-bring-you-interactive-insights-into-risk-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS version 2.0 released – What it means to our clients</title>
		<link>http://pci-dss.7safe.com/pci-dss-version-2-0-released-%e2%80%93-what-it-means-to-our-clients/</link>
		<comments>http://pci-dss.7safe.com/pci-dss-version-2-0-released-%e2%80%93-what-it-means-to-our-clients/#comments</comments>
		<pubDate>Fri, 05 Nov 2010 15:53:03 +0000</pubDate>
		<dc:creator>7Safe Limited</dc:creator>
				<category><![CDATA[News & Events]]></category>

		<guid isPermaLink="false">http://pci-dss.7safe.com/?p=735</guid>
		<description><![CDATA[The Payment Card Industry Data Security Standard (PCI DSS) is a global standard applies to all organisations that either store, process or transmit payment card data. On October 28th 2010 the Payment Card Industry Security Standards Council (“the Council”) published its latest version of the standard known as PCI DSS v2.0. PCI DSS v2.0 communicates [...]]]></description>
			<content:encoded><![CDATA[<p>The Payment Card Industry Data Security Standard (PCI DSS) is a global standard applies to all organisations that either store, process or transmit payment card data. On October 28th 2010 the Payment Card Industry Security Standards Council (“the Council”) published its latest version of the standard known as PCI DSS v2.0.</p>
<p>PCI DSS v2.0 communicates the Council’s intention to provide effective and efficient data security standards that, when implemented correctly, will protect payment card data.</p>
<p>The good news for organisations that are compliant with the existing standard PCI DSS v1.2.1 is that the changes made within v2.0 do not represent a step change in control requirements, simply evolution that recognises the maturity of the existing standard.</p>
<p>What the new standard does provide is additional flexibility in some areas, additional guidance in others and a reducing in duplication. In short, the new standard helps organisations bring some economies to their PCI DSS compliance through greater clarity.</p>
<div class="liststandout">
<ol>
<li>The lifecycle for the new standard has been extended from 2 to 3 years.</li>
<li>There is additional guidance to assist organisations in identifying and documenting the scope of their payment card environments. As a result, 7Safe has seen a marked increase in demand for <a style="text-decoration:underline" href="http://penetration-testing.7safe.com/card-holder-data-search/">7Seec (7Safe’s payment card discovery tool)</a> to assist our clients in discovering the locations of unprotected Primary Account Numbers (PANs).</li>
<li>Recognition of virtualisation technologies and how these should be treated.</li>
<li>Additional guidance on the sampling to be undertaken by an assessor.</li>
<li>Provided additional instructions for the content of the Report on Compliance (RoC). This is the report issued by the independent PCI Council approved qualified security assessor (QSA).</li>
<li>Clarifications and additional guidance for the testing procedures for each of the 12 requirements.</li>
</ol>
</div>
<p>The good news is that the intent of each requirement has not changed and therefore the underlying control structure implemented by organisations for compliance is not expected to change significantly. Secure technology, policies, procedures and practices to protect payment card data will continue to be required.<br />
Organisations can assert their compliance with the PCI DSS v2.0 with effect from January 2011. For those organisations who are currently working with PCI DSS v1.2.1 they can continue to do so until December 2011. After this date, all organisations will be required to assert compliance with the PCI DSS v2.0.</p>
<p>“Greater clarity, recognition of evolving technologies, improved guidance, and extended lifecycle”*. &#8230; that&#8217;s the sign of a mature standard &#8211; something that business can plan and embed into their regular commercial activities.<br />
Early transition to PCI DSS v2.0 is likely to be the best option for most organisations. Naturally, all new 7Safe engagements undertaken from this stage onwards will focus on v2.0 and for those who are “mid-journey”, our PCI Consultancy team will / have been in touch to discuss how the transition will affect current and on-going works.<br />
*Michael Christodoulides &#8211; 5th November 2011</p>
]]></content:encoded>
			<wfw:commentRss>http://pci-dss.7safe.com/pci-dss-version-2-0-released-%e2%80%93-what-it-means-to-our-clients/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>About the 7Safe / Barclaycard Partnership</title>
		<link>http://pci-dss.7safe.com/about-the-7safe-barclaycard-partnership/</link>
		<comments>http://pci-dss.7safe.com/about-the-7safe-barclaycard-partnership/#comments</comments>
		<pubDate>Fri, 05 Nov 2010 14:34:15 +0000</pubDate>
		<dc:creator>7Safe Limited</dc:creator>
				<category><![CDATA[News & Events]]></category>

		<guid isPermaLink="false">http://pci-dss.7safe.com/?p=695</guid>
		<description><![CDATA[7Safe and Barclaycard are PCI DSS partners who operate together under contract for driving PCI compliance throughout the UK and Europe. Our PCI partnership developed out of years of collaborative work in investigating online (e-commerce) credit card fraud through forensic and technical investigations. The partnership evolved into the PCI compliance space where 7Safe is now [...]]]></description>
			<content:encoded><![CDATA[<p>7Safe and Barclaycard are PCI DSS partners who operate together under contract for driving PCI compliance throughout the UK and Europe. Our PCI partnership developed out of years of collaborative work in investigating online (e-commerce) credit card fraud through forensic and technical investigations. The partnership evolved into the PCI compliance space where 7Safe is now proud to work with Barclaycard Merchants and Service Providers in the provision of PCI QSA services. The two organisations collaborate on research into payment card fraud and the field of the Payment Card Industry Data Security Standard. This site is dedicated to the output of such work and brings industry news, commentary and research to a portal for our joint customers to benefit from in the area of PCI compliance.</p>
<p><a href="http://pci-dss.7safe.com/wp-content/uploads/2010/11/7safe_logo_rgb_web-2.png"></a></p>
<h3><a href="http://pci-dss.7safe.com/wp-content/uploads/2010/11/7safe_logo_rgb_web-2.png"><img title="7safe_logo_rgb_web 2" src="http://pci-dss.7safe.com/wp-content/uploads/2010/11/7safe_logo_rgb_web-2.png" alt="" width="191" height="68" /></a></h3>
<h3>7Safe – Professional QSA Consultancy Services</h3>
<p>7Safe is a leading Information Security firm based in Cambridge and London, UK and operates in the PCI DSS space for the provision of QSA Consultancy, Incident Investigation (QFI/QIRA) and PCI Compliance software (7Seec).</p>
<h3><a href="http://pci-dss.7safe.com/wp-content/uploads/2010/11/barclaycard.jpg"><img title="barclaycard" src="http://pci-dss.7safe.com/wp-content/uploads/2010/11/barclaycard.jpg" alt="" width="218" height="115" /></a></h3>
<h3>Barclaycard – Leading Payment Card Security</h3>
<p><a href="http://pci-dss.7safe.com/wp-content/uploads/2010/11/barclaycard.jpg"></a>Barclaycard as an acquiring bank is industry leading in the field of PCI DSS with operations that drive compliance through its Merchant / Service Provider base and a key focus on reducing credit card fraud in the industry.</p>
<h2> </h2>
]]></content:encoded>
			<wfw:commentRss>http://pci-dss.7safe.com/about-the-7safe-barclaycard-partnership/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Barclaycard &amp; 7Safe PCI DSS Partnership</title>
		<link>http://pci-dss.7safe.com/barclaycard-partnership/</link>
		<comments>http://pci-dss.7safe.com/barclaycard-partnership/#comments</comments>
		<pubDate>Thu, 04 Nov 2010 18:08:53 +0000</pubDate>
		<dc:creator>7Safe Limited</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://pci-dss.7safe.com/?p=666</guid>
		<description><![CDATA[Leading acquirer Barclaycard and PCI QSA consultancy 7Safe have formed a partnership in the area of PCI DSS to assist Barclaycard merchants and Service Providers to reach and maintain PCI DSS compliance and to promote payment security best practice throughout the industry. Both Barclaycard and 7Safe are passionate about driving down credit card fraud through: [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://pci-dss.7safe.com/images/barclaycardpartnership.jpg" alt="" width="400" height="115" /></p>
<p>Leading acquirer Barclaycard and PCI QSA consultancy 7Safe have formed a partnership in the area of PCI DSS to assist Barclaycard merchants and Service Providers to reach and maintain PCI DSS compliance and to promote payment security best practice throughout the industry. Both Barclaycard and 7Safe are passionate about driving down credit card fraud through: implementing PCI DSS, promoting payment security and investigating fraud through forensics / incident response when it occurs.</p>
<p>Our teams share the same business ethics towards payment security and risk management. We work very closely together as an Acquirer / QSA Consultancy to help our clients manage their payment security risk, help them understand and implement the Payment Card Industry Data Security Standard (PCI DSS) and eventually achieve and maintain compliance. To that end, our teams work together in the following ways through:</p>
<div class="liststandout">
<ul>
<li>daily activity when 7Safe&#8217;s teams are &#8220;in the field&#8221;  working on compliance programmes</li>
<li>weekly localised working whereby key people from 7Safe have desks with the Barclaycard payment security team</li>
<li>regular strategic work in terms of industry events surrounding the PCI DSS</li>
<li>research and best practice knowledge share and guidance development to share with the PCI community</li>
<li>handling breaches of cardholder data security together for merchants and Service providers</li>
</ul>
</div>
<p>As part of this partnership, 7Safe offers preferential rates to Barclaycard customers.<br />
The result of the above is a very effective relationship that benefits our joint client base in a “joined up” manner with the focus on reducing and mitigating the risks of card data security compromises.</p>
<p><img class="alignnone" src="http://pci-dss.7safe.com/images/barclaycard-7safesm.jpg" alt="" width="385" height="282" /></p>
<p>Neira Jones &#8211; Head of Payment Security, Global Payment Acceptance, Barclaycard<br />
<em>“7Safe has over the years built a very close relationship with the Barclaycard team in the area of PCI DSS specifically and payment security generally. This has effectively helped us reduce the risk of data breaches and support our merchants in their payment security journey.”</em></p>
<p><em>“…We value our partnership which includes the provision of PCI DSS compliance and consultancy services to Barclaycard clients..”</em> Dan Haagman – Director of Information Security Services (PCI DSS, Pen Testing, Incident Response &amp; Security Assessments), 7Safe</p>
<h2>PCI DSS Events – Acquirer &amp; QSA Combine</h2>
<p>7Safe and Barclaycard, as part of their partnership and drive for reduced risk in the payment card industry, hold regular knowledge share and community events on a planned quarterly basis. You do not need to be a Barclaycard or 7Safe client to attend such meetings which are typically held in the City of London.;</p>
<p>For further information, please <a href="http://pci-dss.7safe.com/contact/">contact 7Safe’s PCI QSA Consultancy team</a> or <a href="http://www.barclaycard.co.uk/pcidss">visit Barclaycard</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://pci-dss.7safe.com/barclaycard-partnership/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Policies – Assisting our clients with PCI DSS Documentation</title>
		<link>http://pci-dss.7safe.com/pci-policies/</link>
		<comments>http://pci-dss.7safe.com/pci-policies/#comments</comments>
		<pubDate>Tue, 19 Oct 2010 12:47:32 +0000</pubDate>
		<dc:creator>7Safe Limited</dc:creator>
				<category><![CDATA[PCI Policies]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[PCI documentation]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[PCI policies]]></category>
		<category><![CDATA[PCI policy]]></category>

		<guid isPermaLink="false">http://pci-dss.7safe.com/?p=205</guid>
		<description><![CDATA[7Safe’s PCI policy suite is written by our in-house PCI DSS QSA team and designed to assist 		organisations with their customised documentation for achieving PCI compliance.]]></description>
			<content:encoded><![CDATA[<p>From our work over the years in the PCI industry, 7Safe has been requested countless times to provide clients with a starting policy suite to help along the journey of PCI compliance.</p>
<h2>PCI Policy Suite</h2>
<p>As Qualified Security Assessors (QSAs) 7Safe has therefore established best practice PCI policy templates to assist our clients with the task of PCI policy completion for PCI DSS compliance. The suite of PCI policies came about through 7Safe clients requiring us to write or customise PCI policy documentation sets during their PCI compliance programme. We believe it is far more cost effective to offer a suite of pre-written documents that can then be customised to each client thus saving time and lowering the cost of compliance.</p>
<h2>Customised PCI Policy Templates</h2>
<p><a href="http://pci-dss.7safe.com/pdf/7safe-pci-dss-policy-sample.pdf" target="_blank"><img class="size-thumbnail wp-image-757 alignleft" title="Download sample PCI policy" src="http://pci-dss.7safe.com/wp-content/uploads/2010/10/pdficon-150x150.png" alt="" width="54" height="54" /></a></p>
<div style="padding-top: 6px; float: left;">
<p><strong><a href="http://pci-dss.7safe.com/pdf/7safe-pci-dss-policy-sample.pdf"  target="_blank">DOWNLOAD A SAMPLE POLICY</a></strong></p>
</div>
<div style="float: left; width: 100%;">
<p>PCI Policy templates, once purchased, are distributed through a secure electronic transfer mechanism. The selection of PCI policy templates available is as follows:</p>
<h2>Customised PCI Policy Templates</h2>
<p>PCI Policy templates, once purchased, are distributed through a secure electronic transfer mechanism. The selection of PCI policy templates available is as follows:</p>
</div>
<div class="liststandout">
<ol>
<li>Acceptable Use Policy</li>
<li>Antivirus and Malware Policy</li>
<li>Audit Policy</li>
<li>Cardholder Data Protection Policy</li>
<li>Data Access Control Policy</li>
<li>Data Retention and Disposal Policy</li>
<li>Device Usage Policy</li>
<li>Employee Background Checks Policy</li>
<li>File Integrity Monitoring Policy</li>
<li>Firewall &amp; Router Policy</li>
<li>Information Security Policy</li>
<li>Initial Configuration Policy</li>
<li>Intrusion Detection Policy</li>
<li>Logging and monitoring Policy</li>
<li>Media Protection and Management Policy</li>
<li>Network Access Policy</li>
<li>Password and Account Management Policy</li>
<li>Patching Policy</li>
<li>Payment Application (Software) Development Policy</li>
<li>PCI DSS Policy List</li>
<li>Physical Access Policy</li>
<li>Roles and Responsibilities Policy</li>
<li>Security Awareness Policy</li>
<li>Security Testing Policy</li>
<li>Security Testing Tools Policy</li>
<li>Third Parties Management Policy</li>
<li>Time Management Policy</li>
<li>Wireless Policy (for wireless allowed)</li>
<li>Wireless Policy (for wireless denied)</li>
</ol>
</div>
]]></content:encoded>
			<wfw:commentRss>http://pci-dss.7safe.com/pci-policies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is the Payment Card Industry DSS?</title>
		<link>http://pci-dss.7safe.com/pci_overview/</link>
		<comments>http://pci-dss.7safe.com/pci_overview/#comments</comments>
		<pubDate>Mon, 11 Oct 2010 13:51:17 +0000</pubDate>
		<dc:creator>7Safe Limited</dc:creator>
				<category><![CDATA[PCI QSA Services]]></category>

		<guid isPermaLink="false">http://pci-dss.7safe.com/?p=147</guid>
		<description><![CDATA[What is the PCI DSS and how do QSA firms successfully bring clients through to securing payment card storage, transactions and processing to achieve PCI compliance.]]></description>
			<content:encoded><![CDATA[<p>The Payment Card Industry Data Security Standard (PCI DSS) is a set of requirements developed to reduce credit card fraud and increase data security. This industry standard affects every company that deals with (stores, processes of transmits) card payment transactions. The PCI DSS requires companies to:</p>
<div class="liststandout">
<ul>
<li> Build and Maintain a Secure Network</li>
<li> Protect Card Holder Data</li>
<li> Maintain a vulnerability management Programme</li>
<li> Implement Strong Access Control Measures</li>
<li> Regular Monitor and Test Networks</li>
<li> Maintain an Information Security Policy</li>
</ul>
</div>
<div class="liststandout">
<div style="text-align: center;">
<h3><span style="font-size: 17px; color: #fff;">Who does PCI DSS affect?</span></h3>
<p>Anyone who;<br />
<span style="font-size: 25px; padding-bottom: 5px;">stores</span><br />
<span style="font-size: 25px; padding-bottom: 5px;">processes</span><br />
<span style="font-size: 25px; padding-bottom: 5px;">or transmits</span></p>
<p>&#8230; card holder data, including Merchants and Service Providers.</p>
</div>
</div>
<h2>Objective, Vendor-neutral PCI consultancy</h2>
<p>As we have engaged in PCI compliance projects over the years, it has become very apparent how some providers of PCI consultancy and audit use the PCI Security Standard to leverage third party product sales.</p>
<p>7Safe&#8217;s PCI DSS team have strategically set out to remain vendor neutral.  Our team therefore only provides or recommends what is absolutely necessary to your core PCI compliance programme including;</p>
<p><span class="wordlisthead">Consultancy</span></p>
<div class="wordlistpara">the provision of PCI QSA consultancy for scope, gap, remediation support and audit</div>
<p><span class="wordlisthead">Cardholder Data Search</span></p>
<div class="wordlistpara">it is crucial that any organisation searches for the presence of unprotected cardholder data. Our team uses its un-house build &#8220;7Seec&#8221; to search for PANs. This is a commercially available tool, but will only be offered as a potential discovery solution to help you find unencrypted PANs and to maintain compliance.</div>
<p><span class="wordlisthead">PCI Penetration Testing</span></p>
<div class="wordlistpara">importantly, 7Safe&#8217;s pen testing team are PCI trained and as a result they use their knowledge of PCI DSS to provide clear, concise input into PCI compliance programmes. Moreover, our QSA team trust the output of such work and know that a full and thorough PCI penetration test has been undertaken.</div>
<p><span class="wordlisthead">PCI ASV Scanning Service</span></p>
<div class="wordlistpara">despite being experts in vulnerability assessment and having the co-founder of Nessus working within the business, 7Safe has chosen to partner with industry-leading ASV solutions provider Qualys to ensure that we can offer our clients access to the best ASV in the market place for to satisfy the requirements of the standard.</div>
<h2>PCI vs Pragmatic Business</h2>
<p>7Safe is a PCI DSS QSA (Qualified Security Assessor) and undertakes PCI compliance audits in addition to assisting organisations become and maintain compliance with the standard. We have learned over the years however, that it is a consulting team&#8217;s wider skill set that is also important to set the standard in context of the wider organisation and work closely with our clients to ensure that we take a pragmatic view of how organisational change needs to be undertaken. There is a significant danger that a lack of consultancy experience in the field of PCI can result in ineffective spend and un-necessary risk being introduced from a wider perspective.</p>
<p>Our QSA team therefore draws upon the advice from other departments within 7Safe such as the PCI QFI team (who handle breaches of Payment Card data) and our Penetration Testing / Web Application Security department for advice and guidance where complex situations may arise. This team approach, coupled with strong project management experience adds tremendous value to each project and client alike.</p>
<h2>PCI DSS &#8211; Staying Current</h2>
<p>Critical to the success of any PCI compliance business is knowing the industry and staying close to changes. 7Safe is proud to work very closely with the PCI Security Standards Council, the Card Schemes and the UK Acquiring Banks through both our QSA work, partnerships and QFI (breach of credit card data) activity. We regularly attend PCI council community meetings and have regular updates / knowledge share with the Card Schemes and Acquirers.</p>
<h2>Core Payment Card Industry DSS Principles and Requirements</h2>
<p><a onclick="toggle('1');return false;" href="javascript:;">Build and Maintain a Secure Network<em>&#8230;View Requirements</em></a></p>
<div id="1" style="display: none;">
<p><strong>Requirement 1:</strong> Install and maintain a firewall configuration to protect cardholder data<br />
<strong>Requirement 2: </strong>Do not use vendor-supplied defaults for system passwords and other security parameters</p>
</div>
<p><a onclick="toggle('2');return false;" href="javascript:;">Protect Cardholder Data<em>&#8230;View Requirements</em></a></p>
<div id="2" style="display: none;">
<p><strong>Requirement 3:</strong> Protect stored cardholder data<br />
<strong>Requirement 4:</strong> Encrypt transmission of cardholder data across open, public networks</p>
</div>
<p><a onclick="toggle('3');return false;" href="javascript:;">Maintain a Vulnerability Management Program<em>&#8230;View Requirements</em></a></p>
<div id="3" style="display: none;">
<p><strong>Requirement 5:</strong> Use and regularly update anti-virus software<br />
<strong>Requirement 6</strong>: Develop and maintain secure systems and applications</p>
</div>
<p><a onclick="toggle('4');return false;" href="javascript:;">Implement Strong Access Control Measures<em>&#8230;View Requirements</em></a></p>
<div id="4" style="display: none;">
<p><strong>Requirement 7:</strong> Restrict access to cardholder data by business need-to-know<br />
<strong>Requirement 8:</strong> Assign a unique ID to each person with computer access<br />
<strong>Requirement 9:</strong> Restrict physical access to cardholder data</p>
</div>
<p><a onclick="toggle('5');return false;" href="javascript:;">Regularly Monitor and Test Networks<em>&#8230;View Requirements</em></a></p>
<div id="5" style="display: none;">
<p><strong>Requirement 10:</strong> Track and monitor all access to network resources and cardholder data<br />
<strong>Requirement 11:</strong> Regularly test security systems and processes</p>
</div>
<p><a onclick="toggle('6');return false;" href="javascript:;">Maintain an Information Security Policy<em>&#8230;View Requirements</em></a></p>
<div id="6" style="display: none;">
<p><strong>Requirement 12</strong>: Maintain a policy that addresses information security</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://pci-dss.7safe.com/pci_overview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Achieving PCI Compliance</title>
		<link>http://pci-dss.7safe.com/pci_compliance/</link>
		<comments>http://pci-dss.7safe.com/pci_compliance/#comments</comments>
		<pubDate>Sun, 10 Oct 2010 18:06:18 +0000</pubDate>
		<dc:creator>7Safe Limited</dc:creator>
				<category><![CDATA[PCI QSA Services]]></category>

		<guid isPermaLink="false">http://pci-dss.7safe.com/?p=97</guid>
		<description><![CDATA[7Safe’s successful PCI compliance programmes are broken down into distinct deliverables ranging from PCI DSS scope to gap analysis, remediation support and full audit.]]></description>
			<content:encoded><![CDATA[<h2>PCI Consultancy</h2>
<p>Most organisations required to achieve and maintain PCI compliance can successfully follow a standard process, which is shown graphically below. The following sections explain this route towards PCI DSS audit and describe how 7Safe supports its clients through the PCI compliance initiative.</p>
<p><img class="alignnone" src="http://pci-dss.7safe.com/images/pci-consultancy.jpg" alt="" width="396" height="55" /></p>
<div>
<div style="position: relative; text-align: center; line-height: 15px; width: 87px; font-family: Arial,Helvetica,sans-serif; float: left; color: #6caedf; font-size: 10px; margin-right: 2px; border: #6caedf 1px solid; padding: 5px;">Identify everything in the organisation which is required to achieve PCI compliance and how to reduce this to a manageable quantity.</div>
<div style="position: relative; text-align: center; line-height: 15px; width: 85px; font-family: Arial,Helvetica,sans-serif; float: left; color: #6caedf; font-size: 10px; margin-right: 2px; border: #6caedf 1px solid; padding: 5px;">Compare current practices/systems to what is required for PCI compliance and produce a list of work to be completed.</div>
<div style="position: relative; text-align: center; line-height: 15px; width: 87px; font-family: Arial,Helvetica,sans-serif; float: left; color: #6caedf; font-size: 10px; margin-right: 2px; border: #6caedf 1px solid; padding: 5px;">Implement changes as laid out in the list of work to be completed</div>
<div style="position: relative; text-align: center; line-height: 15px; width: 87px; font-family: Arial,Helvetica,sans-serif; float: left; color: #6caedf; font-size: 10px; border: #6caedf 1px solid; padding: 5px;">Assert that the organisation is PCI compliant, either by completing the Self Assessment Questionnaire or by performing an audit against the PCI DSS.</div>
</div>
<h2>PCI Scope &amp; PCI DSS Scoping Workshop</h2>
<p>In order to determine which parts of your organisation are relevant to the PCI DSS, an initial scoping workshop is recommended. During this stage, our PCI DSS QSA consultants will work with your team to review the following items:</p>
<ul>
<li>Number of sites / offices storing, processing or transmitting payment card data</li>
<li>Payment systems, card data flows and network diagrams</li>
<li>The findings from any security reviews already performed</li>
</ul>
<div class="liststandout">
<p>This workshop will aim to identify:</p>
<ul>
<li>all system components (people, processes and hardware) which form «comp_name»’s cardholder data environment</li>
<li>opportunities to reduce the scope to which the PCI DSS applies</li>
<li>deploy 7Safe’s primary account number discovery tool, 7Seec, in order to assist with the verification of the card holder data environment</li>
</ul>
</div>
<p>During the initial scoping workshop, a verbal summary of your PCI compliance scope will be prepared and presented / discussed on site at the end of the day. A written PCI DSS scope report will then be prepared and shared with you.</p>
<h2>PCI DSS Gap Analysis</h2>
<p><img class="alignnone" src="http://pci-dss.7safe.com/wp-content/themes/7safe/img/banner-thumbprintharddrive.png" alt="" width="375" height="78" /></p>
<p>A Gap Analysis is an assessment process which enables an organisation to compare its current (actual) situation with its desired (target) situation. It enables 7Safe&#8217;s QSA team to measure to what extent the PCI Data Security Standard is currently implemented in your environment, compared to the extent required for compliance.</p>
<p>During this stage, the framework of the PCI DSS Security Audit Procedures v2.0 (which as of the 28<sup>th</sup> October 2010 superseded v1.2) will be used.</p>
<p> 7Safe’s primary account number discovery tool, 7Seec will also be deployed during the Gap Analysis in order to verify that there are no unprotected PAN’s and that your PAN security is strong.</p>
<p>Following this stage, a report will be prepared and its accuracy and reasonableness agreed with you. The report will contain details of areas which are compliant and non-compliant, and will list policies, procedures and standards which are required to comply with Requirement 12 of the Standard. The report may also identify opportunities to reduce the impact of the PCI DSS on your business operations.</p>
<h2>PCI Compliance &amp; Remediation</h2>
<p>Remediation refers to the work required to ensure that your organisation reaches PCI DSS compliance; the actual implementation of protective measures to be undertaken (including <a href="http://penetration-testing.7safe.com/">Penetration Testing</a> and regular <a href="http://7safe.com/security_assessment.html">Vulnerability Assessment</a> (ASV), guided by our PCI compliance team and yout Gap Analysis Report. In support of this activity, 7Safe often is asked to provide ongoing Remediation Support consultancy to for example;</p>
<ul>
<li>construct procedures</li>
<li>provide practical advice to resolve issues</li>
<li>attend progress review meetings</li>
<li>develop remediation plans</li>
<li>ensure effect project management towards the end PCI DSS goal</li>
<li>&#8230; and ultimately achieve PCI compliance</li>
</ul>
<h2><strong>PCI Pre-Audit</strong></h2>
<p>7Safe strongly recommends a PCI DSS pre-audit (or &#8220;readiness&#8221;) phase ensure that your organisation is fully prepared for the full audit, with the intention of identifying un-met requirements which may result in loss of expenditure and ultimately audit failure.  This will also give you the opportunity to experience rigorous audit-style verification prior to an actual audit.</p>
<h2><strong>PCI DSS Audit &amp; Report on Compliance</strong></h2>
<p>In its capacity as a Qualified Security Assessor (QSA) company, 7Safe will carry out an audit on your environment against the PCI DSS.  To validate compliance, all requirements must be met; steps taken in the previous stages will obviously have a major bearing on the audit result.  A Report on Compliance (ROC) will subsequently be produced after rigorous Quality Assurance processes have been adhered to.</p>
<p><img src="http://pci-dss.7safe.com/images/pci_ssc_qsa.jpg" alt="" width="291" height="199" /></p>
]]></content:encoded>
			<wfw:commentRss>http://pci-dss.7safe.com/pci_compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

