BreachExchange mailing list archives

Re: Visa/PCI, care to spin-doctor this crap?


From: security curmudgeon <jericho () attrition org>
Date: Fri, 27 Feb 2009 18:52:18 +0000 (UTC)



On Fri, 27 Feb 2009, James Ritchie, CISA, CISSP wrote:

: No and they probably will never be able too. Any audit is nothing more 
: than a snapshot in time.  A merchant could apply patches right after the 

If it wasn't clear from my original mail, this 'snapshot in time' phrase 
(loophole) sits somewhere between clever spin-doctoring and criminal 
negligence.

Visa and the PCI Council aren't telling the industry the dirty secret that 
the 'snapshot in time' is totally bunk and not publishing that at least 
one compromise occured *in the middle of the PCI audit*. The supposed 
'snapshot' is a nice picture of vulnerability, not compliance. Just so 
happens the ASV involved couldn't figure out pen-testing 101 and missed 
stupid vulnerabilities.

: certification, change business process, etc that could have an adverse 
: effect on the system.  The auditor must maintain all the work papers 
: that they created to support their conclusion.  That is why the standard 

Then organizations should be required to contact Visa and say "we changed 
things" so they can put an end date on the PCI certification. Currently 
they list the date a company was certified and leave it at that.

_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)

CREDANT Technologies, a leader in data security, offers advanced data encryption solutions.
Protect sensitive data on desktops, laptops, smartphones and USB sticks transparently 
across your enterprise to ensure regulatory compliance.
http://www.credant.com/stopdataloss


Current thread: