Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

PCI DSS

Welcome to the PCI DSS topic!

In this topic you may collaborate with your peers by participating in discussions, adding links and documents, and starting or contributing to wikis.

ISACA members can participate by clicking on the “Join this Community” button. You must be signed into the site. Set your alerts to be notified of new discussion activity within this community. Not an ISACA member? Join now!

 
This Topic Has:
796 Members
2 Online
6757 Visits

 Recent Discussions

Looking to store Credit Card Information. Posted by Colleenw.
Will EMV kill PCI-DSS?. Posted by Antonio Ramos.
Failing PCI audit. Posted by Antonio Ramos.

Community Leader

Antonio Ramos
PramodLNS
NEW! Participate in Discussions Via Email. 

You can now respond to discussions by simply replying to the email alert. Just enable this feature in discussions on this topic. Learn more

Discussions: 34 total

Must be a Topic member to contribute
View All »
Our organization has not historically stored credit card information.  However, a division of our organization is wanting to store credit card information.  We want to do a full assessment/workshop to determine what this means for us as an organization.  ...
Colleenw | 5/11/2013 6:25:27 AM | COMMENTS(1)
This week I have read about the creation of EMV Migration Forum for impulse the adoption of EMV in USA (mainly)... With everybody using EMV, fraud should be more difficult, so... will PCI-DSS remain necessary? http://www.smartcardalliance.org/pages/activi...
Antonio Ramos | 3/1/2013 7:01:57 PM | COMMENTS(3)
I must recognize that ex-QSA, I do not know how you feel when you failed a PCI audit... I was reflecting about it, after reading this article (http://www.darkreading.com/security/news/240004877/10-ways-to-fail-a-pci-audit.html)... What is your experience?...
Antonio Ramos | 1/31/2013 10:12:49 AM | COMMENTS(6)
If an internal audit reveals a problem, and if the sample size for the audit is calculated based upon a statistical formula, what are the next steps? Key to my question is timing. In the scenario described, assume that issues are found in an internal audi...
rlmoore | 1/31/2013 10:02:46 AM | COMMENTS(3)
Dear My friends, I have a problem to ask you, I had worked for 10 years IT, among the 10 years, I have 6 years information security experence, I had passed CCIES, CISA, CISSP, PMP and ITIL Foundation V3, Currently My work is Network and PCI and main...
Zujian520 | 11/18/2012 5:16:13 AM | COMMENTS(2)
In the present technological landscape, users expectation is to have every single task executed at the finger tips as one click activity. Tablets, mobiles and Phablets (Phone+ Tablets) are increasingly getting popularity and usage has also grown tremendou...
PramodLNS | 10/25/2012 7:07:06 AM | COMMENTS(0)

Documents & Publications: 3 total

Must be a Topic member to contribute
Books
Posted by ISACA 174 days ago
Mobile payments as a financial transaction medium emerged around a decade ago. Adoption was slow due to the nature of the mobile technology supporting the concept. However, recent significant advances on the technology front have made this area one of burgeoning growth in the financial services sector. Services-based and text-based payment and proximity device communications are appearing worldwide. Widespread use of smartphones and consumer comfort with mobile devices for more than communication are the principal drivers of a resurgent and increased interest in mobile payments. In addition, advances in software and hardware security techniques have made trusted financial transactions possible from these devices. This white paper examines the current state and nature of the mobile payments market, some of the relevant enabling technologies, and looks at the relevant risk, security and assurance issues that security and audit professionals will want to consider when developing and evaluating mobile payment services.
Posted by Antonio Ramos 509 days ago
Posted by ISACA 760 days ago

Events & Online Learning: 1 total

Journal Articles: 11 total

Volume 3, 2013
by Andrew Hay
The PCI Security Standards Council’s Special Interest Group for Cloud released its much-anticipated guidance for securing Software, Platform and Infrastructure as a Service (SaaS, PaaS and IaaS) cloud servers.
Volume 2, 2013
by Tommie W. Singleton, Ph.D., CISA, CGEIT, CITP, CPA
This article attempts to provide the basics of where to find authoritative, reliable standards and frameworks from which an IT audit can be developed and conducted.
Volume 2, 2013
by Ali Alaswad, ITIL, PMPG, PMP
The advent of the Payment Card Industry Data Security Standard (PCI DSS) resulted in many organizations mandating its use.
Volume 5, 2012
by Adesanya Ahmed, CRISC, CGEIT, ACMA, ACPA
Today’s business needs demand that applications and data move across physical, international borders as well as the cloud, and are accessible by third parties.
Volume 2, 2012
by Steve Markey
This article discusses the genesis for CSIR testing, several testing methodologies and/or exercises with which an organization can assess the maturity of its CSIR plan/program.
Volume 1, 2012
by Mathew Nicho, Ph.D., CEH, SAP-SA, RWSP
With more and more transactions based on credit cards, merchants dealing with these are forced to comply with standards such as PCI DSS v2.0 or face huge penalties.

Wikis: 3 total

Blog Posts: 4 total

Must be a Topic member to view blog posts
On March 1st,  I was invited to speak at the CampIT conference on Enterprise Risk/Security Management at Rosemont Convention Center. Before me there were two speakers. The first presenter spent an hour presenting the story from the trenches of technolog...
Posted By : Umesh391 | 1 comments
Como much@s de vosotr@s sabréis, recientemente se ha publicado la versión 2.0 del estándar PCI-DSS, por lo que he pensado que podría ser interesante compartir mi análisis de los cambios (el PCI Council ha publicado un documento titulado "Summary of Change...
Posted By : Antonio Ramos | 0 comments
Continuando con el post anterior vamos a comentar el otro documentado liberado por el PCI Council a principios de octubre relativo a la aplicabilidad de PCI-DSS en los entornos EMV [pdf]. Ante la duda que podía surgir sobre si en los entornos EMV debíamos...
Posted By : Antonio Ramos | 0 comments
El pasado 5 de octubre, el PCI Council publicaba una guía denominada "Initial Roadmap: Point-to-Point Encryption Technology and PCI DSS Compliance" (pdf) dada la importancia creciente de esta tecnología (más conocida como P2PE) y las muchas interpreta...
Posted By : Antonio Ramos | 0 comments