The Coalfire Blog
Welcome to the Coalfire Blog, a resource covering the most important issues in IT security and compliance. You'll also find information on Coalfire's insights into the unique IT GRC issues that impact the industries we serve, including Retail, Financial Services, Healthcare, Higher Education, Software, Government and Utilities.
The Coalfire blog is written by the company's leadership team and our highly-credentialed security assessment experts. We look forward to your comments, so please join the conversation.
PCI DSS 3.0 Is Coming Soon
May 13, 2013, Matt Getzelman, PCI Practice Director
The PCI Security Standards Council (SSC) plans on releasing the newest version of the PCI Data Security Standard in October, 2013. Predictably, the PCI SSC has been tight-lipped on divulging details regarding any expected changes. Read More
Posted in: 2.0, 3.0, DSS, PCI, risk | 0 Comments
The PCI DSS Cloud Computing Guidelines: An Executive Summary
April 22, 2013, Matt Getzelman, PCI Practice Director
The PCI SSC and its Cloud Special Interest Group has released its Cloud Computing Guidelines after a year of collaboration and input from SIG members. Coalfire was a big contributor to this document, and we think it is required reading for anyone who has front-line responsibility for managing compliance at companies using a Cloud Service Provider (CSP). Read More
Posted in: cloud, Payments, PCI | 0 Comments
War on Passwords? Check with Your QSA First!
March 14, 2013, Matt Getzelman, PCI Practice Director
Passwords have long been the workhorse of user authentication schemes, and many security experts are speaking out on the need for more effective controls. It seems like hardly a week goes by when we don’t see a password breach in the news. Read More
Posted in: passwords, PCI, Risk, security | 0 Comments
The PCI SAQ P2PE-HW: Patience, POIs and PIMs
January 15, 2013, Dan Fritsche, Director, Solution Validation Services
The new PCI SAQ P2PE-HW (Point to Point Encryption Self-Assessment Questionnaire) was released in July 2012, and many merchants are excited about the prospect of a shorter, less arduous compliance validation effort. After all, it’s significantly shorter than the SAQ-D; instead 12 sections, there are 4, and 284 controls are reduced to 19. Read More
Posted in: P2PE, payments, PCI, retail | 0 Comments
What's Next in Retail IT? The Convergence of Mobile, P2PE and the Cloud
January 15, 2013, Rick Dakin, CEO, Co-founder and Chief Security Strategist
Greetings from the Javits Center in New York City, the site of the National Retail Federation’s Big Show. This year, the theme of NRF is “Next”.
When it comes to Retail technology – and in particular, security and compliance, the most talked about “next” things are: Read More
Posted in: NRF, P2PE, PCI, Retail | 0 Comments