<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PCICompliance &#187; News</title>
	<atom:link href="http://www.pcicompliance.org/category/pci-compliance-news/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pcicompliance.org</link>
	<description>PCI Compliance News and Resources</description>
	<lastBuildDate>Wed, 25 Aug 2010 16:44:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>PCI DSS 2.0 Summary Unveiled – Many Questions Still Unanswered</title>
		<link>http://www.pcicompliance.org/pci-compliance-news/pci-dss-2-0/</link>
		<comments>http://www.pcicompliance.org/pci-compliance-news/pci-dss-2-0/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 16:39:08 +0000</pubDate>
		<dc:creator>sfender</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[pci 2.0 compliance]]></category>
		<category><![CDATA[pci data security standards]]></category>
		<category><![CDATA[pci dss 2.0]]></category>
		<category><![CDATA[pci standards]]></category>

		<guid isPermaLink="false">http://www.pcicompliance.org/pci-compliance-news/pci-dss-2-0/</guid>
		<description><![CDATA[The PCI Security Standards Council unveiled a summary of changes expected to appear in version 2.0 of the Payment Card Industry Data Security Standard (PCI DSS), which will be published October 28, 2010.
According to the PCI Security Standards Council, the updated PCI standard, which will now be refreshed every three years instead of two, was [...]]]></description>
			<content:encoded><![CDATA[<p>The PCI Security Standards Council unveiled a summary of changes expected to appear in version 2.0 of the Payment Card Industry Data Security Standard (PCI DSS), which will be published October 28, 2010.</p>
<p>According to the PCI Security Standards Council, the updated PCI standard, which will now be refreshed every three years instead of two, was based on hundreds of pieces of feedback. PCI DSS 2.0 incorporates a stronger emphasis on scoping sensitive data and a more risk-based approach for assessing vulnerabilities. Some believe, however, that the bigger news is not what IS included in the revised standard, but what IS NOT included. </p>
<p>&#8220;I think the reaction to what&#8217;s missing is the most important part of this announcement because it will push the council to move faster on areas they have not yet,&#8221; Avivah Litan, vice president and distinguished analyst at Gartner, told <a href="http://www.scmagazineus.com/pci-council-unveils-expected-changes-for-dss-guidelines/article/176889/?DCMP=EMC-SCUS_Newswire" target=_blank">SCMagazineUS.com</a>. &#8220;A lot of fundamental questions are still unanswered.&#8221;</p>
<p>A summary of upcoming changes to the PCI DSS is available online at <a href="https://www.pcisecuritystandards.org/pdfs/summary_of_changes_highlights.pdf" target="_blank">https://www.pcisecuritystandards.org/pdfs/summary_of_changes_highlights.pdf</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcicompliance.org/pci-compliance-news/pci-dss-2-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mastercard Raises the Bar for PCI Compliance</title>
		<link>http://www.pcicompliance.org/pci-compliance-news/mastercard-raises-the-bar-for-pci-compliance/</link>
		<comments>http://www.pcicompliance.org/pci-compliance-news/mastercard-raises-the-bar-for-pci-compliance/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 13:52:05 +0000</pubDate>
		<dc:creator>sfender@phonefactor.com</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.pcicompliance.org/?p=134</guid>
		<description><![CDATA[On June 15th, Mastercard announced that Level 2 merchants, those processing between one and three million transactions annually, will now have to undergo an annual onsite assessment for PCI compliance. Previously these merchants were only required to complete the PCI DSS self-assessment questionnaire (SAQ).
The onsite assessment, which must be completed by a PCI QSA (Qualified [...]]]></description>
			<content:encoded><![CDATA[<p>On June 15th, Mastercard announced that Level 2 merchants, those processing between one and three million transactions annually, will now have to undergo an annual onsite assessment for PCI compliance. Previously these merchants were only required to complete the PCI DSS self-assessment questionnaire (SAQ).</p>
<p>The onsite assessment, which must be completed by a PCI QSA (Qualified Security Assessor), will validate compliance with the twelve requirements set forth in the Payment Card Industry Data Security Standards. The <a href="http://www.pcicompliance.org/pci-compliance-faqs/what-are-the-pci-dss-requirements/">PCI DSS requirements</a> are designed to provide increased controls around data and its exposure to compromise.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcicompliance.org/pci-compliance-news/mastercard-raises-the-bar-for-pci-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hearland Payment Systems Recertified for PCI Compliance</title>
		<link>http://www.pcicompliance.org/pci-compliance-news/hearland-payment-systems-recertified-for-pci-compliance/</link>
		<comments>http://www.pcicompliance.org/pci-compliance-news/hearland-payment-systems-recertified-for-pci-compliance/#comments</comments>
		<pubDate>Thu, 21 May 2009 22:37:11 +0000</pubDate>
		<dc:creator>sfender@phonefactor.com</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.pcicompliance.org/?p=33</guid>
		<description><![CDATA[After reporting one of the largest breaches to date, Heartland Payment Systems was removed from Visa list of PCI DSS Validated Service Providers earlier this year. After being revalidated and submitting a Report on Compliance Visa reinstated Heartland as a PCI DSS compliant service provider in early May.
Heartland recently announced that it expects to take [...]]]></description>
			<content:encoded><![CDATA[<p>After reporting one of the largest breaches to date, Heartland Payment Systems was removed from Visa list of PCI DSS Validated Service Providers earlier this year. After being revalidated and submitting a Report on Compliance Visa reinstated Heartland as a PCI DSS compliant service provider in early May.</p>
<p>Heartland recently announced that it expects to take a significant loss in Q3 resulting from more than $12.6 million dollars in fines from Visa and Mastercard, legal fees, and administrative costs. Given that 65% of the cost of a typical data breach is due to lost business from new and existing customers, none of which is included in the $12.6M figure, this may be just the tip of the iceberg for Heartland.</p>
<p>Pained over the cost of compliance? It&#8217;s nothing compared to the cost of a breach. Ask Heartland.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcicompliance.org/pci-compliance-news/hearland-payment-systems-recertified-for-pci-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Update to PCI Compliance Standards Published</title>
		<link>http://www.pcicompliance.org/pci-compliance-news/update-to-pci-compliance-standards-published/</link>
		<comments>http://www.pcicompliance.org/pci-compliance-news/update-to-pci-compliance-standards-published/#comments</comments>
		<pubDate>Thu, 21 May 2009 21:31:02 +0000</pubDate>
		<dc:creator>sfender@phonefactor.com</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[pci compliance 1.2]]></category>
		<category><![CDATA[pci dss]]></category>
		<category><![CDATA[pci dss 1.2]]></category>
		<category><![CDATA[pci standards 1.2]]></category>
		<category><![CDATA[update]]></category>

		<guid isPermaLink="false">http://www.pcicompliance.org/?p=3</guid>
		<description><![CDATA[Revisions to standard include clarifications and other subtle changes to ease
implementation

The PCI Security Standards Council (PCI SSC), a global, open industry standards body providing management of the Payment Card Industry Data Security Standard (PCI DSS), PIN Entry Device (PED) Security Requirements and the Payment Application Data Security Standard (PA-DSS), today announces general availability of version [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Revisions to standard include clarifications and other subtle changes to ease<br />
implementation<br />
</strong><br />
The PCI Security Standards Council (PCI SSC), a global, open industry standards body providing management of the Payment Card Industry Data Security Standard (PCI DSS), PIN Entry Device (PED) Security Requirements and the Payment Application Data Security Standard (PA-DSS), today announces general availability of version 1.2 of the PCI DSS. This latest version is the culmination of two years of feedback and suggestions from its industry stakeholders and is designed to clarify and ease implementation of the foremost standard for cardholder account security. Version 1.2 is effective immediately and version 1.1 of the standard will sunset on Dec. 31, 2008. The updated standard and supporting documentation is available on the Council’s Web site at <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml">https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml</a>.</p>
<p>The Council previously announced the summary of changes between version 1.1 and version 1.2 to ensure awareness of the coming latest changes to the standard. Version 1.2 includes clarifications and explanations of the requirements that improve flexibility to meet today’s security challenges and ensure organization’s can adequately comply with the standard. While version 1.2 does not introduce any new major requirements to the existing 12 in place since the Council’s inception, the updates do change some practices, such as the sun-setting of implementations of Wired Equivalent Privacy (WEP) wireless security by June, 2010.</p>
<p>“This latest revision to the PCI DSS is welcome news for merchants and service providers as they grapple with the latest security threats to their payment transactions systems,” said Diana Kelley, partner and analyst with SecurityCurve, a data security consultancy. “The clarifications and language revisions should go a long way in easing implementation questions and help to reduce compliance costs.”</p>
<p>Since the Council’s inception in Sept. 2006 and the release of version 1.1 of the PCI SSC, its Participating Organizations and Board of Advisors have been providing feedback on the standard, with global industry input into the revisions. This follows the established lifecycle process that will ensure that the PCI DSS standard is revised and updated on a two year cycle. Participating Organizations are given the opportunity to receive early drafts of all pending revisions to the Council’s standards and provide a bulk of the feedback during this process. PCI DSS version 1.2 was the primary discussion topic at the Council’s recently concluded and successful community meeting in Orlando, Fla., in which more than 500 attendees came together to begin the process of strengthening the standards even further.</p>
<p>“It is especially gratifying to know that version 1.2 of the PCI DSS is inclusive of global industry feedback,” said Bob Russo, general manager, PCI Security Standards Council. “This ensures that we continue to offer merchants and service providers a pathway to protect cardholder account data that is sensible and achievable.”</p>
<p>For More Information:<br />
More information on the PCI Security Standards Council and becoming a Participating Organization please visit pcisecuritystandards.org, or contact the PCI Security Standards Council at <a href="mailto:participation@pcisecuritystandards.org">participation@pcisecuritystandards.org</a>.</p>
<p>About the PCI Security Standards Council<br />
The mission of the PCI Security Standards Council is to enhance payment account security by driving education and awareness of the PCI Data Security Standard and other standards that increase payment data security.</p>
<p>The PCI Security Standards Council was formed by the major payment card brands American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc. to provide a transparent forum in which all stakeholders can provide input into the ongoing development, enhancement and dissemination of the PCI Data Security Standard (DSS), PIN Entry Device (PED) Security Requirements and the Payment Application Data Security Standard (PA-DSS). Merchants, banks, processors and other vendors are encouraged to join as Participating Organizations.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcicompliance.org/pci-compliance-news/update-to-pci-compliance-standards-published/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
