<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Israeli Software &#187; Mastercard</title>
	<atom:link href="http://www.software.co.il/wordpress/tag/mastercard/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.software.co.il/wordpress</link>
	<description>Data security by a software developer and musician</description>
	<lastBuildDate>Wed, 08 Sep 2010 09:10:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Compliance franchise or real security</title>
		<link>http://www.software.co.il/wordpress/2008/10/credit-card-security-franchise-available-at-a-discount/</link>
		<comments>http://www.software.co.il/wordpress/2008/10/credit-card-security-franchise-available-at-a-discount/#comments</comments>
		<pubDate>Thu, 23 Oct 2008 15:42:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[AMEX]]></category>
		<category><![CDATA[Chris Nickerson]]></category>
		<category><![CDATA[Mastercard]]></category>
		<category><![CDATA[Visa]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=679</guid>
		<description><![CDATA[I&#8217;ve been saying for a long time now that compliance standards like PCI DSS 1.2 have created a marketing franchise for auditors instead of improving security. Empirical evidence of the past 2 years suggests that compliance focuses on meeting auditor requirements instead of assuring actual security of your systems and customer data assets.    Here&#8217;s an [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been saying for a long time now that compliance standards like PCI DSS 1.2 have created a marketing <a title="PCI DSS 1.2 security franchise available" href="http://www.software.co.il/wordpress/2008/08/credit-card-security-franchise-available/" target="_blank">franchise</a> for auditors instead of improving security.</p>
<p>Empirical evidence of the past 2 years suggests that compliance focuses on meeting auditor requirements instead of assuring actual security of your systems and customer data assets.    Here&#8217;s an interesting <a title="Chris Nickerson" href="http://searchsecurity.techtarget.com/news/interview/0,289202,sid14_gci1335619,00.html?track=NL-102&amp;ad=665482&amp;asrc=EM_NLN_4826898&amp;uid=2745540" target="_blank">interview</a> with <em>Chris Nickerson </em>who is billed by SearchSecurity.com  				 				<img src="http://media.techtarget.com/searchSecurity/images/spacer.gif" alt="" width="1" height="15" />as &#8220;<em>your worst nightmare. He&#8217;s the guy you never see coming, the one who can slip into your data center, install malware on any server he chooses and ease back out without so much as a shadow on your security cameras&#8221;.</em></p>
<p>Newspaper hype aside &#8211; Nick had an important insight on PCI compliance:</p>
<blockquote><p><em>You might be compliant, but if your system is compromised, you&#8217;re going home without a paycheck. People err on the side of compliance versus security.</em></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/wordpress/2008/10/credit-card-security-franchise-available-at-a-discount/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
