<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PCI Compliance Requirements &#187; Vulnerability</title>
	<atom:link href="http://www.pci-compliance-requirements.net/tag/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pci-compliance-requirements.net</link>
	<description>PCI Compliance Requirements</description>
	<lastBuildDate>Wed, 26 May 2010 16:39:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Vulnerability Scanning</title>
		<link>http://www.pci-compliance-requirements.net/vulnerability-scanning/</link>
		<comments>http://www.pci-compliance-requirements.net/vulnerability-scanning/#comments</comments>
		<pubDate>Wed, 25 Feb 2009 21:02:34 +0000</pubDate>
		<dc:creator>PCI Compliance Mentor</dc:creator>
				<category><![CDATA[PCI Scanning]]></category>
		<category><![CDATA[Vulnerability Scanning]]></category>
		<category><![CDATA[Approved Scanning Vendor]]></category>
		<category><![CDATA[ASV]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Vulnerability scanner]]></category>

		<guid isPermaLink="false">http://www.pci-compliance-requirements.net/?p=21</guid>
		<description><![CDATA[Unfortunately, we live in a world where identity theft and other electronic crimes are rampant.  As such, the PCI Council has compiled a number of specifications or shall we say requirements that must be put in place by all merchants accepting credit cards online and offline to provide Vulnerability Scanning. Inside a series of [...]]]></description>
			<content:encoded><![CDATA[<p>Unfortunately, we live in a world where identity theft and other electronic crimes are rampant.  As such, the PCI Council has compiled a number of specifications or shall we say requirements that must be put in place by all merchants accepting credit cards online and offline to provide <strong>Vulnerability Scanning</strong>. Inside a series of specifications as the number of &#8220;recommendations&#8221; set forth by the PCI Council designed to ensure that your company adheres to the regulations set forth by the Council.  One such recommendation is vulnerability scanning.</p>
<p>The primary goal of vulnerability scanning is to pinpoint and identify any device inside your network, which may be susceptible or vulnerable to threats.  It&#8217;s important to remember that not all vulnerability scanners are created equally.  And for this reason, you should do your homework prior to utilizing any vulnerability scanning vendor.</p>
<p><span id="more-21"></span></p>
<p>As of late, it has become increasingly important that online e-commerce retailers utilize vulnerability scanning in order to protect themselves from the many electronic threats lurking in the dark reaches of the Internet.  The use of a vulnerability scanner can help protect your network in your system from hackers and other electronic &#8220;vulnerabilities&#8221;.  The use of the vulnerability scanning is considered to be a proactive approach to protecting yourself and your customers during the process of e-commerce.</p>
<p>Running a vulnerability scan can reveal areas in your network that are weak or prone to attack.  This can allow you to make necessary changes to your network in order to protect yourself and your customers.<br />
As with anything else, it is important to note that the use of a vulnerability scanning is not foolproof.  It is important to combine the use of a scanning with other means of protection in order to ensure security.</p>
<p>As mentioned before, it&#8217;s a good idea to do your homework and review some of the available Approved Scanning Vendors on the market today.  You will find that researching available vulnerability scanning vendors to online resources is one of the smartest ways, and the most time efficient ways, to locate a high-quality vulnerability scanner.  You may find it in a fit to note that most vulnerability scanners are relatively simple to use.  A few simple instructions should have you up and running in no time.  If you find the use of <a href="http://www.trust-guard.com/Vulnerability-Scanning-s/69.htm">vulnerability scanning</a> to be too complicated, it is possible to find a professional to perform the service for you.</p>
<p>Remember, the reputation of your online business could be at stake, spending a little time in proactive research of your network could end up saving you lots of effort, time, and even money in the long run. So start your <strong>vulnerability scanning</strong> today.</p>
<p><script type="text/javascript" src="http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/js/lgs-js-init.js"></script><script>var domainAddress   = "http://www.letsgetsocialnow.com/";
					 var bookmarkPage    = "bookmarkthis.php";
					 var url     = "http://www.pci-compliance-requirements.net/vulnerability-scanning/";
					 var title   = "Vulnerability Scanning";
					 var js_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var css_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var img_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var bookmark_button_id = "bookmark_button_21";
					 </script><script type="text/javascript" src="http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/js/lgs-js-end.js"></script></p>]]></content:encoded>
			<wfw:commentRss>http://www.pci-compliance-requirements.net/vulnerability-scanning/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>PCI Compliance Importance</title>
		<link>http://www.pci-compliance-requirements.net/pci-compliance-importance/</link>
		<comments>http://www.pci-compliance-requirements.net/pci-compliance-importance/#comments</comments>
		<pubDate>Thu, 12 Feb 2009 21:22:17 +0000</pubDate>
		<dc:creator>PCI Compliance Mentor</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[PCI Scanning]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Payment Card Industry]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.pci-compliance-requirements.net/?p=11</guid>
		<description><![CDATA[If you already know about PCI Compliance but are yet to take action then you need to really understand why the importance of PCI Compliance and how it can save you money and make you money.]]></description>
			<content:encoded><![CDATA[<p>If you already know about <a href="http://trustseals.wordpress.com/2009/02/10/pci-compliance-explained/">PCI Compliance</a> but are yet to take action then you need to really understand why the importance of <strong>PCI Compliance</strong> and how it can save you money and make you money.</p>
<p>The Payment Card Industry Data Security Standard (PCI DSS) is a collaborative effort to achieve a common set of security standards for use by entities that process, and store payment card data. There has been a lot of talk about how effective PCI Compliance is and will it really protect you and your customers. What you need to remember is that PCI Compliance is not the end all of security. Security is a mindset and nobody can ever say that they are perfectly secure. PCI Compliance is the first step to building up your security by following the current security standards and scanning your servers for vulnerabilities.</p>
<p>Here are some great statements by Michael Dahn of PCIAnswers.com about Compliance vs. Validation and Compliance vs. Security:</p>
<p>“There is a difference between ‘compliance’ and ‘validation’.  Compliance is a state of being, one that must be maintained at all times. Validation is a point-in-time check on that state of compliance.  The example I give is auto insurance.  In order to comply with state laws I must maintain auto insurance at all times.  When I go to register my car I have to show proof of insurance.  I am validating my compliance with the law.  What if I decide to cancel my insurance because it costs too much?  Am I still compliant?  No.  Now, I still validated, but remember validation is a point-in-time while compliance is measured day by day.</p>
<p>Another thing to remember is that compliance, even the continuous state of compliance, does not equal security if not done right.  If a company focuses on check box compliance and doing the minimum they may be able to complete the baseline audit, but does that mean they are properly managing their risk and protecting payment card data?  Let me explain, I’ve asked many people, “can a firewall be used to segment a network?” Everyone agrees YES, but they are wrong.  Only a properly configured firewall can segment a network.  So if I check the checkbox saying that something is out of scope of the audit because it is segmented off, the question remains: was it properly segmented?  Did you really eliminate known attack vectors?”</p>
<p>So ask yourself what your mindset is and where you are with the <em>PCI Compliance</em> and security realms of your business. Becoming compliant and secure takes time and some money, let’s be honest. The amount of money and time you spend will save you in the long run and here is why. </p>
<p>•	First of all if you are hacked and something does happen with your customer’s personal and private information you could potentially be liable for the money and information lost. Also imagine the PR nightmare.<br />
•	Next think of all the sales that you are missing out on by providing trust and confidence to your visitors because you are not showing them that your site is secure and that they can trust you.</p>
<p>So keep all of this in mind when you are reading and pondering <strong>PCI Compliance</strong>. A suggestion would be to work with a company that can help start the process to become PCI Compliant like vulnerability scanning. A company that I would suggest is Trust Guard <a href="http://trustseals.wordpress.com/2009/02/10/pci-compliance-explained/">PCI Compliance</a> Scanning.</p>
<p><script type="text/javascript" src="http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/js/lgs-js-init.js"></script><script>var domainAddress   = "http://www.letsgetsocialnow.com/";
					 var bookmarkPage    = "bookmarkthis.php";
					 var url     = "http://www.pci-compliance-requirements.net/pci-compliance-importance/";
					 var title   = "PCI Compliance Importance";
					 var js_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var css_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var img_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var bookmark_button_id = "bookmark_button_11";
					 </script><script type="text/javascript" src="http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/js/lgs-js-end.js"></script></p>]]></content:encoded>
			<wfw:commentRss>http://www.pci-compliance-requirements.net/pci-compliance-importance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
