The Coalfire Blog
Welcome to the Coalfire Blog, a resource covering the most important issues in IT security and compliance. You'll also find information on Coalfire's insights into the unique IT GRC issues that impact the industries we serve, including Retail, Financial Services, Healthcare, Higher Education, Software, Government and Utilities.
The Coalfire blog is written by the company's leadership team and our highly-credentialed security assessment experts. We look forward to your comments, so please join the conversation.
PCI DSS 3.0 Is Coming Soon
May 13, 2013, Matt Getzelman, PCI Practice Director
The PCI Security Standards Council (SSC) plans on releasing the newest version of the PCI Data Security Standard in October, 2013. Predictably, the PCI SSC has been tight-lipped on divulging details regarding any expected changes. Read More
Posted in: 2.0, 3.0, DSS, PCI, risk | 0 Comments
Determining if your Company is Prepared for FedRAMP
May 13, 2013, Tom McAndrew, EVP, Coalfire Federal
Many companies interested in pursuing FedRAMP are seeking guidelines, checklists and any referenceable source to help them understand and determine their level of preparedness to go through the FedRAMP process. The GSA's FedRAMP.gov site provides documentation on the FedRAMP process in their "Guide to Understanding FedRAMP." In it is a 12-step checklist to help organizations gauge their readiness for FedRAMP. Read More
Posted in: federal, FedRAMP | 0 Comments
Compliance Talk: Debt Collectors and PCI
May 06, 2013, Ken Ballard,
As the largest IT audit and compliance advisor in the U.S., Coalfire is exposed to a wide variety of compliance concerns. In this series of Compliance Talk blogs, Dirk and Ken are back at their favorite coffee shop…the Bean and Berry in Louisville, Colorado. Over a couple cappuccinos, their discussion turned to some of the unique aspects, when it comes to data security, of debt collection companies. Read More
Posted in: Risk | 0 Comments
Agencies to report progress with FedRAMP
April 26, 2013, Tom McAndrew, EVP, Coalfire Federal
The FedRAMP PMO recently conducted webinars on April 23 and 25 regarding Agencies requirement to report their progress on compliance with FedRAMP. The discussion covered the FedRAMP progress to date, the reporting requirements and process for moving services to FedRAMP authorized cloud service providers. You will find the archived webinars on the Past Events page of FedRAMP.gov when they are available. Read More
Posted in: Agency, federal, FedRAMP, policy | 0 Comments
The PCI DSS Cloud Computing Guidelines: An Executive Summary
April 22, 2013, Matt Getzelman, PCI Practice Director
The PCI SSC and its Cloud Special Interest Group has released its Cloud Computing Guidelines after a year of collaboration and input from SIG members. Coalfire was a big contributor to this document, and we think it is required reading for anyone who has front-line responsibility for managing compliance at companies using a Cloud Service Provider (CSP). Read More
Posted in: cloud, Payments, PCI | 0 Comments