The Coalfire Blog

Welcome to the Coalfire Blog, a resource covering the most important issues in IT security and compliance. You'll also find information on Coalfire's insights into the unique IT GRC issues that impact the industries we serve, including RetailFinancial Services, Healthcare, Higher Education, Software, Government and Utilities.

The Coalfire blog is written by the company's leadership team and our highly-credentialed security assessment experts. We look forward to your comments, so please join the conversation.


  • PCI DSS 3.0 Is Coming Soon

    May 13, 2013, Matt Getzelman, PCI Practice Director

    Matt Getzelman

    The PCI Security Standards Council (SSC) plans on releasing the newest version of the PCI Data Security Standard in October, 2013.  Predictably, the PCI SSC has been tight-lipped on divulging details regarding any expected changes. Read More

    Posted in: 2.0, 3.0, DSS, PCI, risk | 0 Comments

  • The PCI DSS Cloud Computing Guidelines: An Executive Summary

    April 22, 2013, Matt Getzelman, PCI Practice Director

    Matt Getzelman

    The PCI SSC and its Cloud Special Interest Group has released its Cloud Computing Guidelines after a year of collaboration and input from SIG members. Coalfire was a big contributor to this document, and we think it is required reading for anyone who has front-line responsibility for managing compliance at companies using a Cloud Service Provider (CSP). Read More

    Posted in: cloud, Payments, PCI | 0 Comments

  • War on Passwords? Check with Your QSA First!

    March 14, 2013, Matt Getzelman, PCI Practice Director

    Matt Getzelman

    Passwords have long been the workhorse of user authentication schemes, and many security experts are speaking out on the need for more effective controls. It seems like hardly a week goes by when we don’t see a password breach in the news. Read More

    Posted in: passwords, PCI, Risk, security | 0 Comments

  • The PCI SAQ P2PE-HW: Patience, POIs and PIMs

    January 15, 2013, Dan Fritsche, Director, Solution Validation Services

    Dan Fritsche

    The new PCI SAQ P2PE-HW (Point to Point Encryption Self-Assessment Questionnaire) was released in July 2012, and many  merchants are excited about the prospect of  a shorter, less arduous compliance validation effort.  After all, it’s significantly shorter than the SAQ-D; instead 12 sections, there are 4, and 284 controls are reduced to 19. Read More

    Posted in: P2PE, payments, PCI, retail | 0 Comments

  • What's Next in Retail IT? The Convergence of Mobile, P2PE and the Cloud

    January 15, 2013, Rick Dakin, CEO, Co-founder and Chief Security Strategist

    Rick Dakin

    Greetings from the Javits Center in New York City, the site of the National Retail Federation’s Big Show.  This year, the theme of NRF is “Next”.

    When it comes to Retail technology – and in particular, security and compliance, the most talked about “next” things are: Read More

    Posted in: NRF, P2PE, PCI, Retail | 0 Comments

  • Displaying results 1-5 (of 10)
     |<  < 1 - 2  >  >|