<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>paulmudgett.com&#187; PCI</title>
	<atom:link href="http://paulmudgett.com/tag/pci/feed/" rel="self" type="application/rss+xml" />
	<link>http://paulmudgett.com</link>
	<description>Information Security &#38; Business Leadership</description>
	<lastBuildDate>Fri, 11 May 2012 16:48:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Checkbox Security Fails Again</title>
		<link>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/</link>
		<comments>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/#comments</comments>
		<pubDate>Wed, 04 Apr 2012 16:41:31 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[federal legislation]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO 27001/27002]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=453</guid>
		<description><![CDATA[Regulatory compliance is often a confusing mess.  Rattling off the alphabet of compliance can often result in dizziness, headaches, and for some, a bad case of nausea.   PCI-DSS, HIPAA, HITECH, GLB, SOX, and heck, might as well throw in some state data breach notification laws as well.  Congress doesn&#8217;t want to stop there as [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lessons in Due Diligence</title>
		<link>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/</link>
		<comments>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 19:24:41 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[security mistakes]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=106</guid>
		<description><![CDATA[An article by Kim Zetter on Wired.com caught my attention:  &#8220;Restaurants Sue Vendor for Unsecured Card Processor&#8221;. The gist is that several restaurants purchased Point-of-Sale (POS) systems from a particular vendor.  These POS systems that were sold were apparently not Payment Card Industry &#8211; Data Security Standard (PCI-DSS) compliant and that resulted in a breach [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/12/02/lessons-in-due-diligence/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nevada&#8217;s New Privacy Law</title>
		<link>http://paulmudgett.com/2009/07/10/nevadas-new-privacy-law/</link>
		<comments>http://paulmudgett.com/2009/07/10/nevadas-new-privacy-law/#comments</comments>
		<pubDate>Fri, 10 Jul 2009 21:42:19 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/blog/?p=21</guid>
		<description><![CDATA[SB227 was passed into law and goes into effect in January 2010.  It contains requirements for PCI compliance as well as encryption of personally identifiable information.  Like any legislation it has both good and bad pieces to it with potential loopholes.  ]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/07/10/nevadas-new-privacy-law/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Surprising move by MasterCard</title>
		<link>http://paulmudgett.com/2009/07/10/surprising-move-by-mastercard/</link>
		<comments>http://paulmudgett.com/2009/07/10/surprising-move-by-mastercard/#comments</comments>
		<pubDate>Fri, 10 Jul 2009 18:34:07 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[PCI]]></category>
		<category><![CDATA[credit card information]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[security automation]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/blog/?p=18</guid>
		<description><![CDATA[MasterCard made a decision not to allow remote key injection capabilities that allows merchants to install new encryption keys on point-of-sale devices.  Now these merchants are stuck doing this work manually at an off-site facility.  Organizations that are trying to comply with the Payment Card Industry &#8211; Data Security Standard are now hamstrung in their [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/07/10/surprising-move-by-mastercard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

