<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>paulmudgett.com &#187; PCI</title>
	<atom:link href="http://paulmudgett.com/category/pci/feed/" rel="self" type="application/rss+xml" />
	<link>http://paulmudgett.com</link>
	<description>Information Security &#38; Business Leadership</description>
	<lastBuildDate>Thu, 05 Jan 2012 17:32:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Lessons in Due Diligence</title>
		<link>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/</link>
		<comments>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 19:24:41 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[security mistakes]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=106</guid>
		<description><![CDATA[An article by Kim Zetter on Wired.com caught my attention:  &#8220;Restaurants Sue Vendor for Unsecured Card Processor&#8221;. The gist is that several restaurants purchased Point-of-Sale (POS) systems from a particular vendor.  These POS systems that were sold were apparently not Payment Card Industry &#8211; Data Security Standard (PCI-DSS) compliant and that resulted in a breach [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using a Framework to Navigate Regulatory Compliance</title>
		<link>http://paulmudgett.com/2009/10/21/using-a-framework-to-navigate-regulatory-compliance/</link>
		<comments>http://paulmudgett.com/2009/10/21/using-a-framework-to-navigate-regulatory-compliance/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 22:48:49 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[ISO 27001/27002]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/blog/?p=59</guid>
		<description><![CDATA[The regulatory environment overseeing the protection of sensitive information is incredibly crowded.  Sarbanes-Oxley (SOX), Graham-Leach-Bliley (GLB), the Health Insurance Portability and Accountability Act (HIPAA), HITECH, Red Flags, Payment Card Industry Data Security Standard (PCI-DSS), among a host of state laws and audit guidelines seems to provide the Fort Know of IT risk management if organizations [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/10/21/using-a-framework-to-navigate-regulatory-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Small Business &#8211; a Target</title>
		<link>http://paulmudgett.com/2009/08/26/small-business-a-target/</link>
		<comments>http://paulmudgett.com/2009/08/26/small-business-a-target/#comments</comments>
		<pubDate>Wed, 26 Aug 2009 17:20:28 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Should Have Known Better]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/blog/?p=34</guid>
		<description><![CDATA[Organized cyber-gangs in Eastern Europe are increasingly preying on small and mid-size companies in the United States, setting off a multimillion-dollar online crime wave that has begun to worry the nation&#8217;s largest financial institutions. European Cyber-Gangs Target Small U.S. Firms&#8221;  Washington Post August 25th Launching these attacks from &#8220;safe havens&#8221; against organizations that tend to [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/08/26/small-business-a-target/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Surprising move by MasterCard</title>
		<link>http://paulmudgett.com/2009/07/10/surprising-move-by-mastercard/</link>
		<comments>http://paulmudgett.com/2009/07/10/surprising-move-by-mastercard/#comments</comments>
		<pubDate>Fri, 10 Jul 2009 18:34:07 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[PCI]]></category>
		<category><![CDATA[credit card information]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[security automation]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/blog/?p=18</guid>
		<description><![CDATA[MasterCard made a decision not to allow remote key injection capabilities that allows merchants to install new encryption keys on point-of-sale devices.  Now these merchants are stuck doing this work manually at an off-site facility.  Organizations that are trying to comply with the Payment Card Industry &#8211; Data Security Standard are now hamstrung in their [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/07/10/surprising-move-by-mastercard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

