PCI DSS, Security Program

Secure Coding 201: Does it Exist?

I constantly hear that recent computer science graduates have not even been introduced to the notion of secure coding. They may have been taught to program in half a dozen different languages and styles, but their assignments have never been run through a static code checker to

Read More

PCI DSS

A Summary of Deadlines in PCI 3.2

Everybody - Immediately Existing implementations that use SSL and/or early TLS must have a formal Risk Mitigation and Migration Plan in place New implementations must not use SSL and/or early TLS

Read More

PCI DSS

Hidden Service Providers in your PCI DSS Assessment

Guidance from the PCI Security Standards Council (PCI SSC) suggests that there are overlooked service providers in many assessments. This begs the question as to what SPs a client has omitted to tell us about. So we present a worksheet for Service

Read More