Pci

SensePost again accredited as a PCI ASV

SensePost is proud to announce that they have retained their status as an Approved Scanning Vendor for PCI DSS purposes. This letter of acknowledgement was gladly received: Truth be told, we did pop the bubbly for this one.

Should InfoSec companies be betting on PCI ?

The United States committee on Homeland Security’s Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology recently held a hearing to determine if “the Payment Card Industry Data Standards Reduce Cybercrime?” Risky Business played snippets of the hearing under the apt title: “Washington spanks PCI DSS” – Like most episodes of RB, its well worth the listen.. One of the “merchants” giving testimony made his point quite succinctly. The credit card companies require us to keep card details, and shift the burden of fraudulent transactions to the merchant. There are much better ways to handle transactions, but the current method is a cheap way for the CC vendors to shift the burden and the risk to the merchants who historically had no alternative.