The ENTITY (a scary PCI monster) | blog,pci | Control Gap
If you're subject to PCI DSS you need to understand "The ENTITY". We aren't talking about a...
1 min read
David Gamey
:
Oct 7, 2021 10:07:00 PM
PCI DSS can be hard and not preparing for it just makes things harder. Following this advice is guaranteed to make it both more exciting and painful.
Seriously, if you want your assessment to be smooth and boring you may find these articles useful.
Original Publication: 2021-10-07
Updated PCI FAQ & Learn More links: 2023-06-16
Compliance can seem as dry as toast. Normally, it only gets exciting when things go wrong like when you find problems during an annual assessment, facing a looming deadline, with senior management breathing down your neck expecting a pass. Last minute discovery of problems gets extremely stressful. Failure becomes an option. Remediation is not guaranteed and can often be risky, sub-optimal, and expensive.
PCI DSS has 12 high-level requirements and over 250 sub-requirements each of which is an opportunity for failure. The kinds of challenges we describe are often avoidable and manageable. After all, PCI is an open book exam and there should be no excuse for not being prepared. If you are struggling with business-as-usual compliance, or have challenges, we can help.
David Gamey :
Oct 31, 2019 12:00:00 AM
If you're subject to PCI DSS you need to understand "The ENTITY". We aren't talking about a...
CG Blogger :
Feb 2, 2020 12:00:00 AM
Welcome to This Week’s [in]Security. Recent Wawa breach hit 30M cards. PCI and NIST updates....
David Gamey :
Jul 19, 2021 10:07:00 PM
Documents from the PCI Council, MasterCard, and Visa clearly indicate that Issuers are required to...