« Software risk assessments, redux - the role of static code analysis | Main | Fraud and data leakage »

PCI DSS self-assessment - update

You'll need plenty of these before you finish your PCI DSS self-assessment
226 questions that do nothing to help a small Level 4 merchant (less than 20,000 transactions a year) to build and implement a cost-effective risk mitigation plan. Fill out questionnaire and then?

Long overdue, PCI DSS validation documents for self-assessment have been updated to the current standard PCI DSS 1.1. Version 1.1 of the Self-Assessment Questionnaire has been rewritten to be more in line with the Security Audit Procedures. There are also several companion documents :

The merchant must verify that it adheres to all of the requirements stipulated in the PCI DSS - but heah - who cares about implementation and how much it costs and whether or the requirements are relevant to the merchant and his operating environment.

Any merchant who takes the PCI DSS 1.1 self-assessment checklist seriously should use the free Practical threat analysis for PCI package. It makes the credit card risk assessment simple and cost-effective. This great free software will also save you money on your security implementation by helping you select the most cost-effective countermeasures.

About

This page contains a single entry from the blog posted on February 7, 2008 1:53 PM.

The previous post in this blog was Software risk assessments, redux - the role of static code analysis.

The next post in this blog is Fraud and data leakage.

Many more can be found on the main index page or by looking through the archives.

Creative Commons License
This weblog is licensed under a Creative Commons License.
Powered by
Movable Type 3.32