BreachExchange mailing list archives
Re: Visa/PCI, care to spin-doctor this crap?
From: security curmudgeon <jericho () attrition org>
Date: Fri, 27 Feb 2009 18:52:18 +0000 (UTC)
On Fri, 27 Feb 2009, James Ritchie, CISA, CISSP wrote: : No and they probably will never be able too. Any audit is nothing more : than a snapshot in time. A merchant could apply patches right after the If it wasn't clear from my original mail, this 'snapshot in time' phrase (loophole) sits somewhere between clever spin-doctoring and criminal negligence. Visa and the PCI Council aren't telling the industry the dirty secret that the 'snapshot in time' is totally bunk and not publishing that at least one compromise occured *in the middle of the PCI audit*. The supposed 'snapshot' is a nice picture of vulnerability, not compliance. Just so happens the ASV involved couldn't figure out pen-testing 101 and missed stupid vulnerabilities. : certification, change business process, etc that could have an adverse : effect on the system. The auditor must maintain all the work papers : that they created to support their conclusion. That is why the standard Then organizations should be required to contact Visa and say "we changed things" so they can put an end date on the PCI certification. Currently they list the date a company was certified and leave it at that. _______________________________________________ Dataloss Mailing List (dataloss () datalossdb org) CREDANT Technologies, a leader in data security, offers advanced data encryption solutions. Protect sensitive data on desktops, laptops, smartphones and USB sticks transparently across your enterprise to ensure regulatory compliance. http://www.credant.com/stopdataloss
Current thread:
- Re: Visa/PCI, care to spin-doctor this crap?, (continued)
- Re: Visa/PCI, care to spin-doctor this crap? Michael Hill, CITRMS (Feb 26)
- Re: Visa/PCI, care to spin-doctor this crap? macwheel99 (Feb 26)
- Re: Visa/PCI, care to spin-doctor this crap? B.K. DeLong (Feb 27)
- Re: Visa/PCI, care to spin-doctor this crap? Clint P. Garrison (Feb 27)
- Re: Visa/PCI, care to spin-doctor this crap? Kenton Hoover (Feb 27)
- Re: Visa/PCI, care to spin-doctor this crap? Adam Shostack (Feb 28)
- Re: Visa/PCI, care to spin-doctor this crap? B.K. DeLong (Feb 28)
- Re: Visa/PCI, care to spin-doctor this crap? Michael Hill, CITRMS (Feb 26)
- Re: Visa/PCI, care to spin-doctor this crap? James Ritchie, CISA, CISSP (Feb 27)
- Re: Visa/PCI, care to spin-doctor this crap? Susan Kohl (Feb 27)
- Re: Visa/PCI, care to spin-doctor this crap? halsey (Feb 27)
- Re: Visa/PCI, care to spin-doctor this crap? security curmudgeon (Feb 27)
- Re: Visa/PCI, care to spin-doctor this crap? Smith, Paul (Sr. Admin-InfoSec) (Feb 27)
