<?xml version="1.0" encoding="utf-8"?><rss version="2.0">
<channel>
<title><![CDATA[The Coalfire Blog]]></title>
<link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog?tagid=45&amp;rss=blogs&amp;rss=blogs]]></link>
<description><![CDATA[RSS Feed for The Coalfire Blog]]></description>
<language><![CDATA[en-US]]></language>
<item>
  <guid isPermaLink="false">5f427ba6-9e0f-4726-ac56-628312563efb</guid>
  <title><![CDATA[PCI DSS 3.0 Is Coming Soon]]></title>
  <description><![CDATA[<p>
	The PCI Security Standards Council (SSC) plans on releasing the newest version of the PCI Data Security Standard in October, 2013.&nbsp; Predictably, the PCI SSC has been tight-lipped on divulging details regarding any expected changes.</p>
]]></description>
  <pubDate>Mon, 13 May 2013 19:36:43 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/May-2013/PCI-DSS-3-0-Is-Coming-Soon?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">e64f5177-21cd-4147-ab67-659434c32536</guid>
  <title><![CDATA[Determining if your Company is Prepared for FedRAMP]]></title>
  <description><![CDATA[<p>
	Many companies interested in pursuing FedRAMP are seeking guidelines, checklists and any referenceable source&nbsp; to help them understand and determine their level of preparedness to go through the FedRAMP process. The GSA&#39;s FedRAMP.gov site provides documentation on the FedRAMP process in their &quot;Guide to Understanding FedRAMP.&quot; &nbsp;In it is a 12-step checklist to help organizations gauge their readiness for FedRAMP. &nbsp;</p>
]]></description>
  <pubDate>Mon, 13 May 2013 07:00:00 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/May-2013/Determining-if-your-Company-is-Prepared-for-FedRAM?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">928a120a-f482-4868-9acc-3e8c86146d87</guid>
  <title><![CDATA[Compliance Talk:  Debt Collectors and PCI]]></title>
  <description><![CDATA[<p>
 As the largest IT audit and compliance advisor in the U.S., Coalfire is exposed to a wide variety of compliance concerns.&nbsp; In this series of Compliance Talk blogs, Dirk and Ken are back at their favorite coffee shop&hellip;the Bean and Berry in Louisville, Colorado.&nbsp;&nbsp; Over a couple cappuccinos, their discussion turned to some of the unique aspects, when it comes to data security,&nbsp;of debt collection companies.</p>
]]></description>
  <pubDate>Mon, 06 May 2013 15:27:33 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/May-2013/Compliance-Talk-Debt-Collectors-and-PCI?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">10c175d7-439c-4793-bdae-d184ada67250</guid>
  <title><![CDATA[Agencies to report progress with FedRAMP]]></title>
  <description><![CDATA[<p>
	The FedRAMP PMO recently conducted webinars on April 23 and 25 regarding Agencies requirement to report their progress on compliance with FedRAMP. The discussion covered the FedRAMP progress to date, the reporting requirements and process for moving services to FedRAMP authorized cloud service providers. You will find the archived webinars on the Past Events page of FedRAMP.gov when they are available.</p>
]]></description>
  <pubDate>Fri, 26 Apr 2013 13:00:00 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/April-2013/Agencies-to-report-progress-with-FedRAMP?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">30c438a9-5583-4478-98cc-8890c6deb344</guid>
  <title><![CDATA[The PCI DSS Cloud Computing Guidelines: An Executive Summary]]></title>
  <description><![CDATA[<p>
	The PCI SSC and its Cloud Special Interest Group has released its Cloud Computing Guidelines after a year of collaboration and input from SIG members. Coalfire was a big contributor to this document, and we think it is required reading for anyone who has front-line responsibility for managing compliance at companies using a Cloud Service Provider (CSP).</p>
]]></description>
  <pubDate>Mon, 22 Apr 2013 16:01:35 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/April-2013/The-PCI-DSS-Cloud-Computing-Guidelines-An-Executiv?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">389f04e9-dbde-46f8-b3be-b060caefdc67</guid>
  <title><![CDATA[Getting Your Databases Audit Ready]]></title>
  <description><![CDATA[<p>
	Your database is perhaps one of the most sensitive targets for cybercriminals as they are your company&rsquo;s primary repository for confidential and proprietary data. Besides knowing what vulnerabilities exist for your perimeter network and also for your internal systems, best practices require you to manage and protect your databases from unauthorized access, whether intentional or otherwise.</p>
]]></description>
  <pubDate>Thu, 04 Apr 2013 18:56:26 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/April-2013/Getting-Your-Databases-Audit-Ready?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">5faf1e6e-96af-4eb3-9914-c77531a20dd4</guid>
  <title><![CDATA[Information Governance:  Get Data Classification Right First]]></title>
  <description><![CDATA[<p>
	Data classification is one of the most crucial elements of an effective information governance process&mdash;yet it&rsquo;s also one that many companies fail to implement well. In its simplest terms, data classification is the process of categorizing data based on its level of sensitivity. When done properly, the classification of data helps a company determine the most appropriate level of safeguards and controls that need to be in place.</p>
]]></description>
  <pubDate>Thu, 21 Mar 2013 21:48:09 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/March-2013/Information-Governance-Get-Data-Classification-Rig?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">2f4a12cc-c66e-480a-bcfe-2416410f3730</guid>
  <title><![CDATA[War on Passwords? Check with Your QSA First!]]></title>
  <description><![CDATA[<p>
	Passwords have long been the workhorse of user authentication schemes, and many security experts are speaking out on the need for more effective controls. It seems like hardly a week goes by when we don&rsquo;t see a password breach in the news.</p>
]]></description>
  <pubDate>Thu, 14 Mar 2013 18:58:34 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/March-2013/War-on-Passwords-Check-with-Your-QSA-First!?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">2890702b-a51c-4ed5-b301-665c83f0d6d8</guid>
  <title><![CDATA[Whether you are a large or small business, beware of these 5 common security problems]]></title>
  <description><![CDATA[<p>
	Every January, the trade press if full of new year&rsquo;s resolution-like advice&hellip; things to do in the coming year, even Coalfire made a few predictions for 2013. I work at Coalfire Labs, and since our business is IT security and testing, we want to share some advice on how to avoid your systems and accounts from being breached.&nbsp; While larger companies may feel they can skip some of these steps, and still remain safe, TJX, the parent company of T.J. Maxx and Marshalls learned the hard way the damages a breach can cause.&nbsp; Information from up to tens of millions of credit and debit cards was stolen costing TJX millions of dollars to get the problem under control.&nbsp; With this in mind, here is a list of five issues companies are prone to make, and ways to avoid negative ramifications.</p>
]]></description>
  <pubDate>Mon, 11 Mar 2013 19:44:31 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/March-2013/Whether-you-are-a-large-or-small-business,-beware?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">33207925-64a3-49b0-b2b4-2a12c69d48eb</guid>
  <title><![CDATA[Creative Ideas for Replacing Passwords]]></title>
  <description><![CDATA[<p>
	Passwords have been the de facto manner of providing security for IT systems.&nbsp; They&rsquo;ve got a bad reputation, but it&rsquo;s not the passwords themselves that deserve the reputation &ndash; it&rsquo;s the individuals using them and the weak standards to which these passwords are managed. &nbsp;In fact, a password system implemented in a secure manner &ndash; long and complex passwords that change periodically &ndash; can be (virtually) uncrackable.&nbsp; However, a typical user isn&rsquo;t apt to embrace a system that requires 15 characters or more (including numbers, upper and lower case, and special characters) and needs to change every two to four weeks.&nbsp;&nbsp;</p>
]]></description>
  <pubDate>Fri, 08 Mar 2013 22:47:29 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/March-2013/Creative-Ideas-for-Replacing-Passwords?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">6a126cbc-2ffa-40cc-8cdd-6e9b1551c29d</guid>
  <title><![CDATA[The FFIEC proposes guidance on social media - can you stay two steps ahead?]]></title>
  <description><![CDATA[<p>
	On January 22, 2013, the FFIEC put out a press release called &ldquo;Financial Regulators Propose Guidance on Social Media&rdquo;. &nbsp;We should begin by saying that even without a social media presence, every company should address social media risks in their annual risk assessment. In this day and age where the average person has a smartphone, laptop, and a tablet, everyone is aware of social media. But what exactly is social media?</p>
]]></description>
  <pubDate>Wed, 06 Mar 2013 20:06:43 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/March-2013/The-FFIEC-proposes-guidance-on-social-media-can-yo?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">b01d0b64-9fde-4c14-acc6-c7436b9075ad</guid>
  <title><![CDATA[White House Executive Order on Cyber Security]]></title>
  <description><![CDATA[<p>
	The tense standoff between an unresponsive Congress and a reluctant critical infrastructure industry has been broken.&nbsp; On February 13, 2013, the President issued an Executive Order that provides initial guidance for the country to confront escalating cyber threats.&nbsp; Finally, we have someone with the courage to address the &lsquo;elephant in the room&rsquo;.&nbsp; Our critical infrastructure is under attack and our ability to defend against increasingly sophisticated attacks is simply not adequate.</p>
]]></description>
  <pubDate>Thu, 14 Feb 2013 23:23:05 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/February-2013/White-House-Executive-Order-on-Cyber-Security?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">b50a4d6f-2bfe-4c92-8c45-5d1ea9e6694b</guid>
  <title><![CDATA[All Aboard the HIPAA Omnibus - but is the ‘bus’ missing anything?]]></title>
  <description><![CDATA[<p>
	In the wake of the recently-released HIPAA Omnibus Rule with its upcoming deadline, healthcare organizations are trying to figure out how they&rsquo;re going to achieve compliance. We&rsquo;ve been busy trying to get through the 563-page rule and determine what it means to our clients.</p>
]]></description>
  <pubDate>Wed, 06 Feb 2013 22:35:44 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/February-2013/All-Aboard-the-HIPAA-Omnibus?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">256e3d56-8f0d-40e6-a94c-0275f060579f</guid>
  <title><![CDATA[Long-awaited HIPAA Omnibus Rule is Unveiled]]></title>
  <description><![CDATA[<p>
	As of January 17, 2013, the HIPAA Omnibus Rule has finally been released by the Department of Health and Human Services (HHS), which will modify the HIPAA privacy, security, and enforcement rules.&nbsp; The package of regulations, in regard to this long-overdue HIPAA Omnibus Rule, will officially be posted on the Federal Register on January 25, 2013 and will be put into effect on March 26, 2013.&nbsp; Covered entities and business associates will have until September 23, 2013 to comply with the new regulations.</p>
]]></description>
  <pubDate>Mon, 21 Jan 2013 22:56:04 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/January-2013/Long-awaited-HIPAA-Omnibus-Rule-is-Unveiled?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">adb49d3e-5713-45a7-ae11-c79b376959fe</guid>
  <title><![CDATA[FedRAMP PMO - FedRAMP Process and Developing SSP webinar Q&A]]></title>
  <description><![CDATA[The FedRAMP program continues to gain momentum and GSA and the FedRAMP PMO conduct great, interactive, webinars available to attend live or to watch later. There is much to learn from the GSA on how to navigate the FedRAMP process according to their requirements.]]></description>
  <pubDate>Wed, 16 Jan 2013 21:19:33 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/January-2013/FedRAMP-PMO-FedRAMP-Process-and-Developing-SSP-web?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">7d51c14f-0b59-4f10-8243-9e2a0d32c3ff</guid>
  <title><![CDATA[South Carolina Data Breach Survey Results on Residents' Attitudes]]></title>
  <description><![CDATA[<p>
	Coalfire recently conducted a survey of South Carolina residents who were victims of the recent data breach at the Department of Revenue. The data breach affected residents of the State who had filed their taxes online exposing 3.8 million taxpayer Social Security numbers and nearly 400,000 credit and debit card numbers.</p>
]]></description>
  <pubDate>Tue, 15 Jan 2013 23:44:49 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/January-2013/South-Carolina-Data-Breach-Resident-Attitudes-Surv?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">887cd8ea-798a-420a-9365-a5264713f358</guid>
  <title><![CDATA[The PCI SAQ P2PE-HW: Patience, POIs and PIMs]]></title>
  <description><![CDATA[<p>
	The new PCI SAQ P2PE-HW (Point to Point Encryption Self-Assessment Questionnaire) was released in July 2012, and many&nbsp; merchants are excited about the prospect of&nbsp; a shorter, less arduous compliance validation effort.&nbsp; After all, it&rsquo;s significantly shorter than the SAQ-D; instead 12 sections, there are 4, and 284 controls are reduced to 19.</p>
]]></description>
  <pubDate>Tue, 15 Jan 2013 19:25:48 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/January-2013/The-PCI-SAQ-P2PE-HW-Patience,-POIs-and-PIMs?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">b11cc61a-2f7e-4f2c-847d-2541c85cef72</guid>
  <title><![CDATA[What's Next in Retail IT? The Convergence of Mobile, P2PE and the Cloud]]></title>
  <description><![CDATA[<p>
	Greetings from the Javits Center in New York City, the site of the National Retail Federation&rsquo;s Big Show.&nbsp; This year, the theme of NRF is &ldquo;Next&rdquo;.<br />
	<br />
	When it comes to Retail technology &ndash; and in particular, security and compliance, the most talked about &ldquo;next&rdquo; things are:</p>
]]></description>
  <pubDate>Tue, 15 Jan 2013 18:47:59 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/January-2013/What-s-Next-in-Retail-IT-The-Convergence-of-Mobile?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">aecac2ae-b592-4152-99e1-897d99113e1a</guid>
  <title><![CDATA[Small Breach, Big Settlement]]></title>
  <description><![CDATA[<p>
	Earlier this week the Department of Health and Human Services (HHS) announced the first ever breach settlement where fewer than 500 patient records were compromised.&nbsp; The $50,000 settlement was issued as a result of 441 patient records being stored on an unencrypted laptop that was stolen from the Hospice of North Idaho (HONI).</p>
]]></description>
  <pubDate>Tue, 08 Jan 2013 20:15:38 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/January-2013/First-ever-healthcare-breach-settlement-announced?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">8e256e3c-fa7e-4858-9236-752b50f8c1d5</guid>
  <title><![CDATA[P2PE Hybrid, the next best thing since the Prius]]></title>
  <description><![CDATA[<p>
	P2PE promises many things, the most coveted being scope reduction for the merchant and a shifting of the compliance burden from the merchant to the service provider. A properly implemented P2PE solution can indeed reduce the risk of compromise for a merchant as well as reduce the scope of what must be done to continue to maintain compliance to the PCI DSS.</p>
]]></description>
  <pubDate>Mon, 07 Jan 2013 20:47:54 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/January-2013/P2PE-Hybrid-the-next-best-thing-since-the-prius?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">f2f7dc87-b0cb-45aa-9079-713a93965efd</guid>
  <title><![CDATA[ What “Dexter Malware” tells us about the future of POS security (It might just be P2PE)]]></title>
  <description><![CDATA[<p>
	The recently announced Dexter malware is targeting POS systems and once in, it collects sensitive credit card data and surreptitiously sends it off to attackers. While the details of this particular attack are not yet available, this is not the first time this general approach has been exploited.</p>
]]></description>
  <pubDate>Fri, 21 Dec 2012 05:51:26 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/December-2012/What-Dexter-Malware-tells-us?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">af5c182c-7d4b-446c-91ac-63dfa8b6f32a</guid>
  <title><![CDATA[FedRAMP Question and Answer session from PMO webinar]]></title>
  <description><![CDATA[<p>
	On October 25, the FedRAMP PMO conducted its first webinar, in what will be a series of webinars, on the FedRAMP process. This first webinar covered the four methods that CSPs can get listed in the FedRAMP repository.<br />
	<br />
	This webinar is well worth the time to listen to it. The PMO had a lengthy Q&amp;A session, which we have transcribed for your convenience below. The FedRAMP PMO also provides a transcription, but leverages a speech-to-text service which garbled some of the phrases and meanings. Our human reviewed Q&amp;A of that section of the webinar is below.</p>
]]></description>
  <pubDate>Tue, 13 Nov 2012 17:18:29 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/November-2012/FedRAMP-Question-and-Answer-session-from-PMO-webin?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">b7dcffc1-57e4-426a-953a-a8ec18c1440c</guid>
  <title><![CDATA[IT Security Horror Stories: Tale of the Fake IT Rep]]></title>
  <description><![CDATA[<p>
	Some IT security monsters aren&#39;t as obvious as a Mummy. At Coalfire Labs, we discover&mdash;and help our clients address&mdash;some pretty scary security and compliance problems. There are lots of deceptive monsters looking to exploit the weaknesses of their victims. This is one of those terrifying but true stories...</p>
]]></description>
  <pubDate>Mon, 29 Oct 2012 21:08:32 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/October-2012/IT-Security-Horror-Stories-Tale-of-the-Fake-IT-(1)?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">2706026c-d6be-4686-bb96-7e5204cb0ee8</guid>
  <title><![CDATA[IT Security Horror Stories: Truth is Scarier Than Fiction]]></title>
  <description><![CDATA[<p>
	At Coalfire Labs, we discover&mdash;and help our clients address&mdash;some pretty scary security and compliance problems. Everyone&rsquo;s heard of blood-sucking cyber criminals looking for vulnerable IT systems. Even when organizations have protections in place, these monsters just won&rsquo;t give up. Their appetite is insatiable...</p>
]]></description>
  <pubDate>Mon, 29 Oct 2012 20:56:04 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/October-2012/IT-Security-Horror-Stories-Tale-of-the-Fake-IT-Rep?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">59b38917-27c2-4d4d-9a66-2add32be3eb0</guid>
  <title><![CDATA[IT Security Horror Stories: The Case of the Phantom Technician]]></title>
  <description><![CDATA[<p>
	At Coalfire Labs, we discover&mdash;and help our clients address&mdash;a lot of scary security and compliance problems. Like zombies out looking for a victim, nefarious characters are out to attack your IT infrastructure and compromise your systems. Even when organizations have protections in place, the monsters just won&rsquo;t give up. They keep coming. Consider this frightening tale...</p>
]]></description>
  <pubDate>Mon, 29 Oct 2012 20:45:03 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/October-2012/IT-Horror-Stories-The-Case-of-the-Phantom-Technici?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">97d444b1-a036-44ad-80f7-001c57bce9e8</guid>
  <title><![CDATA[Penetration Testing Frequently Asked Questions]]></title>
  <description><![CDATA[<p>
	You may have noticed this recent article about Google&rsquo;s contest that rewarded a hacker for discovering a vulnerability in Chrome. Once Google verified the vulnerability, they were able to fix the bug and issue the cash prize to the hacker. This is a very public example similar to what Coalfire Labs does every day - working with security leaders to test their security programs.</p>
]]></description>
  <pubDate>Mon, 29 Oct 2012 15:37:12 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/October-2012/Penetration-Testing-Frequently-Asked-Questions?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">9fa11dee-629e-4d0d-be5e-016fce540979</guid>
  <title><![CDATA[Coalfire Client FireHost Achieves HITRUST CSF Certification]]></title>
  <description><![CDATA[<p>
	Yesterday, we were delighted to see our long-time client Firehost announce that they achieved Common Security Framework (CSF) &ldquo;Certified&rdquo; status from the HITRUST Alliance.&nbsp; Headquartered in Richardson, Texas, FireHost has made compliance a top priority, and we&rsquo;ve enjoyed working with them to achieve this important designation.</p>
]]></description>
  <pubDate>Fri, 19 Oct 2012 19:22:29 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/October-2012/Coalfire-Client-FireHost-Achieves-HITRUST-CSF-Cert?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">729df39f-68b0-4ac6-87a6-f647a56038e3</guid>
  <title><![CDATA[Cyber Security Legislation]]></title>
  <description><![CDATA[<p>
	October is Cyber Security Awareness Month: Get Informed and Get Involved on Cyber Legislation. Every October, the National Cyber Security Alliance sponsors National Cyber Security Awareness Month, and a growing number of businesses and institutions are joining the chorus.&nbsp; The White House got in on the act, too, with this Presidential Proclamation.<br />
	<br />
	To celebrate the month, Coalfire will be blogging on topics of interest to our customers and business partners, and we invite you to join the discussion. This first post is an update on cyber legislation.</p>
]]></description>
  <pubDate>Thu, 04 Oct 2012 20:45:31 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/October-2012/Cyber-Security-Legislation?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">402db6fd-bf6d-45e5-a9f2-832444f75fe3</guid>
  <title><![CDATA[My DEFCON social engineering talk and DerbyCon]]></title>
  <description><![CDATA[<p>
	This year has been a year of firsts for me and for Coalfire. I was recently hired to my first Information security job as a penetration tester for Coalfire Labs, the forensic and app/network testing side of Coalfire.&nbsp; Many of the Coalfire Labs team attended DEFCON in Las Vegas in early August.. Not only was it my first visit to DEFCON as an attendee but this was my first time speaking at a conference. Because it seems to be a year of firsts, we at Coalfire Labs thought it would be a good idea to share a first time speaker&rsquo;s experience and an attendee&rsquo;s views on this year&rsquo;s DEFCON.</p>
]]></description>
  <pubDate>Tue, 11 Sep 2012 19:14:31 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/September/My-DEFCON-social-engineering-talk-and-DerbyCon?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">f3c7f8bb-9596-4b92-b2a6-f37c02782e89</guid>
  <title><![CDATA[BYOD Survey Results: Employees are not playing it safe with company data]]></title>
  <description><![CDATA[<p>
	Employers are seeing a drastic increase in the number of employees using personal smartphones and tablets in the office. This &ldquo;Bring Your Own Device&rdquo; (BYOD) trend is causing headaches for the IT department and there is no stopping this trend. Due to the sensitive nature of company information often accessed on those devices, it has become a growing concern for small and large businesses alike.</p>
]]></description>
  <pubDate>Tue, 14 Aug 2012 22:26:31 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/August/BYOD-Survey-Results-Employees-are-not-playing-it-s?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">06580828-3526-47a5-9da3-835d0bb38401</guid>
  <title><![CDATA[Coalfire Certificates: Proof of a Job Well Done]]></title>
  <description><![CDATA[<p>
	Most security professionals don&rsquo;t like to boast about their good work. They would rather stay behind the scenes to keep systems and data protected from harm. However, companies also need to let customers and business partners know that they have a security program and are compliant with applicable security regulations and standards. That is why we created the Coalfire Certificate program. &nbsp; -- so companies can highlight that their IT controls have been independently scanned, assessed or validated in accordance with the highest industry standards.</p>
]]></description>
  <pubDate>Wed, 18 Jul 2012 19:58:35 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/July-2012/Coalfire-Certificates-Proof-of-a-Job-Well-Done?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">708b1e91-e8e2-4b20-bb7a-ba068a3f8959</guid>
  <title><![CDATA[Proudly Supporting Our Country’s Navy Reserves]]></title>
  <description><![CDATA[<p>
	July is a month in which we celebrate our nation&rsquo;s independence and we hope that you&rsquo;ve had the chance to reflect on the many freedoms and blessing we enjoy as citizens of the United States. At Coalfire, we know full well that those freedoms have been paid for, at least in part by the America&rsquo;s service men and women.</p>
]]></description>
  <pubDate>Tue, 10 Jul 2012 16:42:08 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/July-2012/Proudly-Supporting-Our-Navy-Reserves?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">9f411474-3e74-4026-b20d-4ff63d0f3f69</guid>
  <title><![CDATA[VMware releases PCI Solution Guide and it has good news for compliance-oriented buyers]]></title>
  <description><![CDATA[<p>
	This month VMware release an important document, the VMware Solution Guide for Payment Card Industry (PCI). It&rsquo;s significant because it is the first document of its kind to map the PCI requirements &ndash; including those authored by the PCI SSC&rsquo;s&nbsp; Virtualization&nbsp; SIG &ndash; to a commercially-available stack of virtualization solutions.</p>
]]></description>
  <pubDate>Fri, 22 Jun 2012 22:41:09 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/June-2012/VMware-releases-PCI-Solution-Guide?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">9431ad3a-b898-485f-ba41-3c7afd7db9be</guid>
  <title><![CDATA[P2P Encryption Program now available from PCI Council]]></title>
  <description><![CDATA[<p>
	The PCI council has updated the Point-to-Point encryption (P2PE) program requirements (PDF). The update impacts merchants, payment applications, point of sale vendors and service providers. As a participating organization of the PCI P2PE task force, providing input into the standard, I wanted to briefly explain how this affects the various PCI ecosystem participants.<br />
	<br />
	The ultimate goal of the P2PE program is to reduce the PCI DSS scope that merchants experience by shifting the burden away from merchants toward solution providers who are providing validated P2PE solutions. Deploying validated P2PE solutions will simplify PCI DSS validation for merchants while reducing the risk of cardholder data breaches.</p>
]]></description>
  <pubDate>Fri, 25 May 2012 21:18:37 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/May-2012/P2P-Encryption-Program-now-available-from-PCI-Coun?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">935426d3-0643-4ac2-8c10-3f988f3a30e1</guid>
  <title><![CDATA[Moving to the Cloud: Considerations for Implementing Cloud Migration Plans]]></title>
  <description><![CDATA[<p>
	Over 60 executive level attendees came to the Omni Interlocken Resort in Broomfield, Colorado for the National Council of Higer Education Loan Programs (NCHELP) Spring convention and to hear from a panel of cloud experts on how the migration to cloud IT services could impact their business in the future.&nbsp;</p>
]]></description>
  <pubDate>Fri, 25 May 2012 20:13:02 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/May-2012/Moving-to-the-Cloud-Considerations-for-Implementi?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">19841c83-aa5f-45b1-b6f5-7842cb5f9e4d</guid>
  <title><![CDATA[Coalfire Acquires Digital Resources Group in California]]></title>
  <description><![CDATA[<p>
	We have reached a new milestone at Coalfire and have announced the recent acquisition of privately held Digital Resources Group (DRG) in Redwood City, California. We are excited about our latest venture as it consolidates our leadership position within the IT Governance Risk and Compliance (IT GRC) services industry. As we continue to grow, acquisitions such as this will help us gain new staff, clients, skills and additional geographical presence enabling Coalfire to continue to provide top-notch services.</p>
]]></description>
  <pubDate>Thu, 10 May 2012 18:12:33 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/May-2012/Coalfire-Acquires-Digital-Resources-Group-in-Calif?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">d54f01e2-4290-4a84-976b-3cf34142135d</guid>
  <title><![CDATA[FISMA vs FedRAMP: Compliance requirement differences ]]></title>
  <description><![CDATA[<p>
	Organizations that work with, or want to work with, government agencies must manage to government compliance regulations. Almost everyone is familiar with the FISMA compliance standards, but with the announcement of FedRAMP, which provides a structure to manage compliance requirements for &quot;a cloud first initiative&quot; for government agencies and organizations working with them, there&rsquo;s a new set of compliance requirements to adhere to. Or is there?</p>
]]></description>
  <pubDate>Thu, 03 May 2012 17:47:32 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/May-2012/FISMA-vs-FedRAMP-Compliance-requirement-differenc?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">36f5f411-4693-4058-bdc4-d04a4da51f32</guid>
  <title><![CDATA[The hackerproof password? Tips and advice on password management]]></title>
  <description><![CDATA[<p>
	Having some security expert tell you that you should be creating strong passwords that are unique per account and change frequently is like your dentist telling you that you should floss morning, night and after consuming any dentally dangerous foods. The majority of us say, &ldquo;yeah right&rdquo;. The truth is that you really must do better than what the average person is doing today. In our penetration testing and forensics practices we constantly discover, usually very intelligent, people using the same weak password or PIN across every account without ever changing them.</p>
]]></description>
  <pubDate>Wed, 02 May 2012 14:56:22 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/May-2012/The-hackerproof-password-Tips-and-advice-on-passw?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">91da8207-bdff-4a04-9c93-a73f421357d5</guid>
  <title><![CDATA[Surprises Ahead for Some Level 2 Merchants]]></title>
  <description><![CDATA[<p>
	The PCI DSS has been around for years, and most PCI &ldquo;pro&rsquo;s&rdquo; are familiar with the processes needed to validate compliance. However, insiders often forget that small changes to the guidelines can have a big impact on merchants.<br />
	<br />
	One such change is upon us:&nbsp; MasterCard&rsquo;s new validation guidelines for Level 2 merchants that are scheduled to take effect on June 30, 2012.</p>
]]></description>
  <pubDate>Thu, 12 Apr 2012 21:10:09 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/April-2012/Surprises-Ahead-for-Some-Level-2-Merchants?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">16c41687-2a1c-4692-b6d9-73cba30676ca</guid>
  <title><![CDATA[Mobile Banking Malware: Protect Your Finances]]></title>
  <description><![CDATA[<p>
	The prolific rise in smartphones, tablets and other portable devices has greatly expanded the ways in which we interact with personal and professional services. The public can now singlehandedly use their mobile device to pay for things with the ease of flashing their cell phone. Unfortunately, this rapid expansion of convenience and service also expands the threats.</p>
]]></description>
  <pubDate>Mon, 02 Apr 2012 14:02:36 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/April-2012/Mobile-Banking-Malware-Protect-Your-Finances?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">563a94e2-01c7-4926-8dd5-72513279b3a3</guid>
  <title><![CDATA[What We Learned at HIMSS12]]></title>
  <description><![CDATA[<p>
	A few weeks ago, more than 35,000 healthcare IT professionals and 1,100 exhibitors converged on Las Vegas.&nbsp; Some were there to go shopping for &ldquo;HIT&rdquo; or health information technology; others were there to sell it.&nbsp; The IT professionals from across the healthcare spectrum were there to meet with each other and regulators, and stay abreast of the rapid technological changes in the healthcare industry.&nbsp; This was an overwhelming event; a flood of information.&nbsp; It&rsquo;s been a couple of weeks.&nbsp; Here&rsquo;s a few of the HIMSS12 highlights:</p>
]]></description>
  <pubDate>Fri, 16 Mar 2012 19:22:37 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/March-2012/HIMSS-Recap?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">210f8055-e89e-4b65-a512-aeafa0906347</guid>
  <title><![CDATA[RSA 2012: Mobile, Cloud, and Intelligent Control]]></title>
  <description><![CDATA[<p>
	It was good to catch up with our customers and partners at RSA 2012 this week. Much of the buzz this year was around mobile devices and securing the cloud. We were glad to see innovative organizations introducing compliance-validated architectures based on these emerging technologies. One such organization was Hewlett-Packard, a Coalfire client and business partner.&nbsp;</p>
]]></description>
  <pubDate>Fri, 02 Mar 2012 23:30:00 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/March-2012/RSA-2012-Mobile,-Cloud,-and-Intelligent-Control?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">7bc3932d-bab2-48b7-9856-7fde5117090b</guid>
  <title><![CDATA[The Budding Healthcare IT Spring]]></title>
  <description><![CDATA[<p>
	HIMSS12 is in full production in Las Vegas this week. Over 40,000 healthcare IT professionals and service providers have descended upon a conference that will set the direction for a new wave to technology innovations for the healthcare industry. Almost every booth has a sign that extolls the benefits of cloud-based services delivered through mobile devices. The promise to shake the industry to its core is a common theme.</p>
]]></description>
  <pubDate>Thu, 23 Feb 2012 21:24:32 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/February-2012/The-Budding-Healthcare-IT-Spring?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">d846b07d-38d4-494e-87d8-983a7475d837</guid>
  <title><![CDATA[Is your HIPAA Security and HITECH audit program in order?]]></title>
  <description><![CDATA[<p>
	Healthcare organizations have been working towards HIPAA and HITECH compliance for a few years now. &ldquo;Surprise&rdquo; HIPAA compliance audits conducted by the OCR have begun and at Coalfire we&rsquo;ve come across some gaps that have led organizations to fall short of their compliance initiatives.</p>
]]></description>
  <pubDate>Mon, 20 Feb 2012 20:25:20 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/February-2012/Is-your-HIPAA-Security-and-HITECH-audit-program-in?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">1314b1e1-a919-4179-9f18-b74793c14ea0</guid>
  <title><![CDATA[Password Management: How many do you need to remember?]]></title>
  <description><![CDATA[<p>
	In today&rsquo;s online world, the proliferation of usernames and passwords has resulted in a cottage industry springing up to meet the need to keep track of them in a secure manner. Software and hardware providers have developed a number of unique approaches to deal with this problem, but they all achieve the end goal of being a single credential that grants access to all your passwords.</p>
]]></description>
  <pubDate>Sat, 18 Feb 2012 00:05:34 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/February-2012/Password-Management-How-many-do-you-need-to-remem?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">88e409f7-ff3c-45a3-9f11-a70702b46501</guid>
  <title><![CDATA[Data Privacy Day 2012 – BYOD]]></title>
  <description><![CDATA[<p>
	January marks Data Privacy Month and on January 28th we celebrated Data Privacy Day. In the past year, we have seen an increase in the consumerization of IT and &ldquo;Bring Your Own Device&rdquo; (BYOD) in the enterprise. In honor of Data Privacy Day 2012, we have partnered with The Center for Identity at The University of Texas to host a seminar on Wednesday, February 1.</p>
]]></description>
  <pubDate>Mon, 30 Jan 2012 23:51:48 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/January-2012/Data-Privacy-Day-2012-BYOD?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">b56f5198-a988-4e2a-8846-c66ac4bdb688</guid>
  <title><![CDATA[Formalized IT Security Policy Now Required for Government Prime and Sub-contractors]]></title>
  <description><![CDATA[<p>
	This month the GSA announced an IT security mandate for government prime- and sub-contractors that requires them to have a formalized IT security plan that includes periodic audits.&nbsp; Many government sub-contractors, large and small, will benefit from a third-party compliance program review so they can meet the intent of the rule but more importantly, they can promote an IT risk audit as a benefit to their customer base in their business development efforts.&nbsp; There are a large number of sub-contractors, including IT service providers, that will need to comply with this new mandate.</p>
]]></description>
  <pubDate>Sat, 21 Jan 2012 00:13:29 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/January-2012/Formalized-IT-Security-Policy-Now-Required-for-Gov?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">e67f5ef9-6c4e-4823-8e67-4020f5cf44ef</guid>
  <title><![CDATA[Navis HITECH Complete Services Offer Protection for Medical Data]]></title>
  <description><![CDATA[<p>
	We are proud to introduce Navis HITECH Complete, our first Navis service for the healthcare industry. For years, Navis has been providing IT governance, risk and compliance (IT GRC) solutions to merchants that need to comply with the PCI DSS and banks and credit unions that measure compliance with the GLBA regulations.</p>
]]></description>
  <pubDate>Thu, 19 Jan 2012 23:37:04 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/January-2012/Navis-HITECH-Complete-Services-Offer-Protection-fo?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">c276da06-83e6-4315-a49a-968f1de6f793</guid>
  <title><![CDATA[Coalfire in the News]]></title>
  <description><![CDATA[<p>
 It&rsquo;s been quite a season in the world of IT security as we move into 2012. As experts in our field, we are often asked to comment on current trends and recent stories. Take some time to check out what we have had to say recently:</p>
]]></description>
  <pubDate>Tue, 17 Jan 2012 20:30:58 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/January-2012/Coalfire-in-the-News?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">70481050-47d8-48d4-b21e-351118b6078a</guid>
  <title><![CDATA[Electronic Health Records and Meaningful Use: Protecting Electronic Health Information]]></title>
  <description><![CDATA[<p>
	Since 2009, healthcare providers and other companies providing services to the healthcare industry have been mobilizing to take advantage of government incentives to implement Electronic Health Records (or EHRs).&nbsp; These incentives were established by federal law as a part of the HITECH Act of 2009, and are now administered by the Centers of Medicare and Medicaid Services (CMS).</p>
]]></description>
  <pubDate>Mon, 09 Jan 2012 23:33:42 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/January-2012/electronic-health-records-and-meaningful-use?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">8c5eadb7-86ef-449e-8d45-482f177cd596</guid>
  <title><![CDATA[Cyber Security Fraud in the Banking Industry: Lessons Learned in OCC Examiner Training]]></title>
  <description><![CDATA[<p>
	In late October 2011, Coalfire participated in a day of IT audit training with about 35 bank examiners.&nbsp; As you would expect, we covered a lot of previously hot topics. The conversation changed as we started talking about the amount of fraud being realized by community banks and credit unions.</p>
]]></description>
  <pubDate>Tue, 03 Jan 2012 20:59:00 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/January-2012/Cyber-Security-Fraud-in-the-Banking-Industry-Less?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">dd9cd4f3-a980-414e-915d-51ea544a25fe</guid>
  <title><![CDATA[What is Your Risk Assessment Worth?]]></title>
  <description><![CDATA[<p>
	A risk assessment provides your organization with a tool to determine how, where and how much to invest in controls and security over technology.&nbsp; It also serves to document the risk acceptance policy of your organization as the acceptable level of risk dictates the level of controls to be implemented.&nbsp; It is also a requisite part of legal and regulatory compliance for Sarbanes-Oxley, HIPAA and PCI, among others.&nbsp;</p>
]]></description>
  <pubDate>Thu, 08 Dec 2011 22:42:53 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/December-2011/What-is-your-risk-assessment-worth?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">da1899e0-be7d-4baf-b6f7-5396ff44ce43</guid>
  <title><![CDATA[GivingFirst Launches online Charity Processing Service]]></title>
  <description><![CDATA[<p>
	In the spirit of the Holiday Season, Coalfire has made a significant contribution to GivingFirst.org in the form of free Penetration Testing services.&nbsp; GivingFirst is a Denver-based community foundation whose mission is &ldquo;to improve quality of life by increasing community generosity and involvement.&rdquo;&nbsp;</p>
<quickprintreadystate style="display: none;"></quickprintreadystate><quickprintreadystate style="display: none;"></quickprintreadystate><quickprintreadystate style="display: none;"></quickprintreadystate>]]></description>
  <pubDate>Tue, 06 Dec 2011 18:20:02 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/December-2011/GivingFirst-Launches-online-Charity-Processing-Ser?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">d3ef88ec-d13c-438d-8c02-6b6671878fba</guid>
  <title><![CDATA[Exercise your Incident Response Plan]]></title>
  <description><![CDATA[<p>
	So you&rsquo;ve finally completed your Incident Response Plan.&nbsp; You&rsquo;ve named your team, defined roles, documented standard operating procedures, and establishing escalation processes.&nbsp; Heck, you&rsquo;ve even got training material.&nbsp; So now what?&nbsp;</p>
]]></description>
  <pubDate>Mon, 07 Nov 2011 18:45:33 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/Nov-2011/Exercise-your-Incident-Response-Plan?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">170cde84-d126-4428-864f-50bfc6eff171</guid>
  <title><![CDATA[Cyber Security Awareness - Are you Doing All You Can to Stay Safe?]]></title>
  <description><![CDATA[<p>
	Every company has vulnerabilities and must learn to protect themselves from fast-moving cyber threats.&nbsp; Below are a few tips to keep in mind as you examine your network security:</p>
<quickprintreadystate style="display: none;"></quickprintreadystate><quickprintreadystate style="display: none;"></quickprintreadystate>]]></description>
  <pubDate>Thu, 27 Oct 2011 02:45:50 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/October-2011/October-is-Cyber-Security-Awareness-Month?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">6074b0e6-a0a8-44bb-b79e-4868d39c0c8d</guid>
  <title><![CDATA[Can we kick the attachment habit?]]></title>
  <description><![CDATA[<p>
	As consumers of messaging services, particularly email, we have become addicted to attachments. This habit has become an easy avenue for mounting cyber-attacks against an organization. In the 2010 Verizon Data Breach Investigations Report, conducted in cooperation with the United States Secret Service, 38 percent of breaches utilized some form of malware and 28 percent employed social tactics.</p>
]]></description>
  <pubDate>Tue, 11 Oct 2011 21:56:49 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/October-2011/Can-we-kick-the-attachment-habit?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">d6e7b4a3-7a2a-4b53-8f1a-f10d81472032</guid>
  <title><![CDATA[Get Real-time Evidence Management with Navis Lighthouse]]></title>
  <description><![CDATA[<p>Data breaches have been dominating the headlines for months, and we are  pleased to see so many of our customers sign up for our Navis services.&nbsp;  These customers are serious about IT Governance, Risk and Compliance  and are seeking to protect their organizations with accurate and  thorough self assessments against the PCI DSS, HIPAA, GLBA/FFIEC and  FISMA standards.</p>]]></description>
  <pubDate>Wed, 21 Sep 2011 22:38:18 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/September-2011/Get-Real-time-Evidence-Management-with-Navis-Light?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">c2245bfa-b048-4815-9758-f576fa3f477e</guid>
  <title><![CDATA[Recent Surveys Reveal Trends and Spending Habits for Retailers in PCI Compliance]]></title>
  <description><![CDATA[<p>Recently, Gartner Research released two separate research reports on retailer PCI DSS compliance progress, trends and strategies. These reports are based on a survey of 77 merchants of varying sizes and covers a wide range of topics, including compliance status, spending and the incidence of assessed fines and penalties.</p>]]></description>
  <pubDate>Tue, 06 Sep 2011 23:11:48 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/September-2011/First-Post?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">4850f959-b78a-4017-b26b-3640e8aedc91</guid>
  <title><![CDATA[Phishing Season: Spam on the rise]]></title>
  <description><![CDATA[<p>Within the past two weeks there have been several reports on the increase in email spam,  which can be directly correlated to an increase in phishing schemes and  malware attacks.&nbsp; These attacks are frequently being delivered under  the guise of legitimate business: they come in the form of shipment  confirmations, credit card statements, and IRS alerts.&nbsp; They all request  swift action to click a link or to read an attachment to address some  pressing issue.</p>]]></description>
  <pubDate>Thu, 01 Sep 2011 23:11:37 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/September-2011/Phishing-Season--Spam-on-the-rise?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">a1edb49c-d746-4c99-9a12-1131b59bee73</guid>
  <title><![CDATA[Coalfire Appoints Larry Jones to Board of Directors]]></title>
  <description><![CDATA[<p>We are proud to announce the election of Larry Jones to our board of directors. Larry is the former CEO of StarTek, Activant, Message Media and NeoData, and is a seasoned veteran in technology services.&nbsp; He also serves on the board of Comverge, Inc., a publicly traded provider of smart grid, demand management and energy efficiency solutions.</p>
<br />]]></description>
  <pubDate>Mon, 29 Aug 2011 23:25:00 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/August-2011/Coalfire-Appoints-Larry-Jones-to-Board-of-Director?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">3aca903e-0c7e-4611-b08f-424d8dfbae6d</guid>
  <title><![CDATA[New Guidelines Address PCI DSS Tokenization]]></title>
  <description><![CDATA[<p>
	&ldquo;Tokenization&rdquo; is one of the best techniques to reduce the risk of credit card data loss. Basically, it is the process of substituting sensitive data with other values not considered sensitive. By doing this, tokenization technology essentially removes anything of value from the data stream, and, after all, what is not there cannot get stolen. This technique can be used with sensitive data of all kinds including financial transactions and medical records.</p>
]]></description>
  <pubDate>Fri, 19 Aug 2011 23:37:48 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/August-2011/New-Guidelines-Address-PCI-DSS-Tokenization?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">def99e5a-1692-4243-a051-74a139364973</guid>
  <title><![CDATA[Cyber Defense Summit 2011]]></title>
  <description><![CDATA[<p>On September 14, we will be partnering with InfraGard&rsquo;s New York City Alliance to host a one-day Cyber Defense Summit. This year we have seen a drastic increase in data breaches. As these hacks have become daily occurrences, enterprises must learn how to protect their data while simultaneously guarding their corporate reputation.</p>]]></description>
  <pubDate>Tue, 16 Aug 2011 23:44:18 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/August-2011/Cyber-Defense-Summit-2011?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">903ecf51-c781-4a3f-95f9-fdb04dd57ac3</guid>
  <title><![CDATA[Viruses and Vendors Can Put Healthcare Data At Risk]]></title>
  <description><![CDATA[<p>
	A recent article in Healthcare Security Info highlights that computer viruses can cause security breaches, that can then in turn compromise health care data and potentially violate the HIPAA and HITECH Act regulations. Beth Israel Deaconess Medical Center in Boston had to notify more than 2,000 people that a computer virus sent data, including medical record numbers, names, etc. to an undisclosed location.</p>
]]></description>
  <pubDate>Tue, 09 Aug 2011 23:48:55 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/August-2011/Viruses-and-Vendors-Can-Put-Healthcare-Data-At-Ris?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">6fd16722-5095-41b7-8bfe-13530dd40d3d</guid>
  <title><![CDATA[Where should CISO report?]]></title>
  <description><![CDATA[<p>
	A key question faced by many organizations in defining the role and responsibilities of the security organization, is where to align the most senior information security executive, (typically referred to as the Chief Information Security Officer or CISO).&nbsp; To answer this question it is important to clearly define the responsibilities of this position and place them in appropriate context.</p>
]]></description>
  <pubDate>Wed, 06 Jul 2011 23:53:21 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/July-2011/Where-should-CISO-report?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">31be2422-8e25-42b5-86e0-96ee760352e3</guid>
  <title><![CDATA[Coalfire Systems Assessment: Merchant Link’s TransactionShield and TransactionVault Reduce Merchant’s PCI Scope]]></title>
  <description><![CDATA[<p>
	Merchants spend a lot of time and money developing IT controls programs to protect consumer credit card data. Through our work with thousands of retailers, we&rsquo;ve learned that one of the best ways to contain costs and reduce risk is to keep cardholder data out of as many systems and business processes as possible. In our line of business, that&rsquo;s called &lsquo;reducing PCI scope&rsquo;, since systems and processes that don&rsquo;t store, process or transmit cardholder data are excluded from the controls required by the PCI DSS.</p>
]]></description>
  <pubDate>Thu, 23 Jun 2011 23:58:54 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/June/Coalfire-Systems-Assessment-Merchant-Links-Trans?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">dba06d15-e5f4-4f92-a1ce-3e7911ca26de</guid>
  <title><![CDATA[This Week: Coalfire Systems in the News]]></title>
  <description><![CDATA[<p>
	It&rsquo;s been quite a week in the world of IT security, and as experts in our field, we are often asked to comment on current trends and recent stories. Take some time to check out what we had to say recently:</p>
]]></description>
  <pubDate>Thu, 16 Jun 2011 00:02:58 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/June/This-Week--Coalfire-Systems-in-the-News?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">9bce4d22-d77c-4756-9ba8-9cea11baf91b</guid>
  <title><![CDATA[Coalfire Expands Dallas Office and Names Kurt Hagerman Managing Director]]></title>
  <description><![CDATA[<p>
	I am pleased to announce that our Dallas office is growing by leaps and bounds. Leading the charge is Kurt Hagerman, the newly appointed managing director. Kurt will serve more than 60 clients in the Southwest region and oversee Coalfire&rsquo;s strategic vision while building new client relationships for the company. Also joining the Dallas office are Rick Link as an IT audit director, Adam Bush as a senior auditor and Justin Baker as a regional sales manager.</p>
]]></description>
  <pubDate>Wed, 15 Jun 2011 00:25:19 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/June/Coalfire-Expands-Dallas-Office?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">127a7772-12d0-457e-a1bd-ed9effdf033d</guid>
  <title><![CDATA[HIPAA Compliance and Call Centers]]></title>
  <description><![CDATA[<p align="center" style="text-align: left;">
	In a previous post titled Is It Safe to Speak? Protection for Telephone-Based Payment Card Data, I commented on the PCI SSC new requirements for call center operations and recording systems.</p>
<p align="center" style="text-align: left;">
	Call center security has been a hot topic for a long time. How safe is the information that is given over the phone?&nbsp; Especially in the healthcare industry, patient privacy is paramount.</p>
]]></description>
  <pubDate>Thu, 09 Jun 2011 07:08:34 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/June/HIPAA-Compliance-and-Call-Centers?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">2d3246cb-d5ef-4f2c-a62b-67a2d9f74445</guid>
  <title><![CDATA[They Changed What? HIPAA & HITECH]]></title>
  <description><![CDATA[<p>
	In 1996, the Healthcare Insurance Portability and Accountability Act (HIPAA) opened the door to increased exchanges of healthcare information in an effort to improve care and reduce costs. The Act included new provisions for <a href="http://coalfire-staging.coalfire.com/Industries/Healthcare">protected health information</a> (PHI). Since there are only a few limited reviews and enforcement efforts, the effectiveness of the implementations have remained open.</p>
]]></description>
  <pubDate>Tue, 24 May 2011 07:16:32 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/May-2011/They-Changed-What-HIPAA-HITECH?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">0c81925b-7e41-4c10-9c67-95b9cf2d96c3</guid>
  <title><![CDATA[Meet John Rostern: Managing Director of the New York Office]]></title>
  <description><![CDATA[We are pleased to announce that John Rostern has joined Coalfire Systems as managing director of the <a href="http://coalfire-staging.coalfire.com/Contact">New York office</a>.]]></description>
  <pubDate>Wed, 11 May 2011 07:38:15 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/May-2011/Meet-John-Rostern-Managing-Director?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">b9f0178f-a1c9-4e68-99a7-ee3729dba49c</guid>
  <title><![CDATA[Botnets: 2011 Rocky Mountain Information Security Conference]]></title>
  <description><![CDATA[<p>
	Botnets have become one of the most dangerous cyber threats affecting businesses today. Botnets criminals focus on the same things as most criminals: money and information. That is why these criminals are targeting payroll, human resources departments, C-level executives and senior strategists.</p>
]]></description>
  <pubDate>Mon, 09 May 2011 07:43:45 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/May-2011/Botnets--2011-Rocky-Mountain-Information-Security-?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">0c78753f-5db1-474a-a089-7b55a4b6d209</guid>
  <title><![CDATA[Trust the ‘Cloud’ (just make sure you have it examined first)]]></title>
  <description><![CDATA[<p>
	In the wake of Amazon&rsquo;s Web Service disruption over the past few days we think it is important to look at the case a little closer.</p>
]]></description>
  <pubDate>Tue, 26 Apr 2011 07:53:32 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/April-2011/Trust-the-Cloud?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">69e648a7-f67c-4148-9607-a926cd733da8</guid>
  <title><![CDATA[Navis PCI Complete Arrives]]></title>
  <description><![CDATA[<p>
	Small companies often feel that to be compliant, they must spend a large sum of money on just testing and reporting compliance validation. Not true&ndash;that is why we have developed <a href="https://navis.coalfiresystems.com/Login.aspx">Navis</a> PCI Complete. These new service bundles are specifically aimed at smaller and medium-sized businesses and are similar to other high-end services offered by Coalfire.</p>
]]></description>
  <pubDate>Thu, 21 Apr 2011 17:59:07 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/April-2011/Navis-PCI-Complete-Arrives?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">1a5ad5de-2c61-4488-bb35-40026994006e</guid>
  <title><![CDATA[Mobile Application Security – The New Frontier]]></title>
  <description><![CDATA[<p>
	The power and popularity of consumer mobile computing is changing faster then you can say iFart (the #1 downloaded app worldwide). Commercial entities are rapidly adopting <a href="http://coalfire-staging.coalfire.com/Services/Application-Security">mobile-based applications</a> for retail sales floors, restaurants and dining rooms, distributed mobile banking, and more.</p>
]]></description>
  <pubDate>Mon, 18 Apr 2011 18:03:28 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/April-2011/Mobile-Application-Security-The-New-Frontier?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">66ca9f1c-7ff5-4a69-8a1e-6f14352ef272</guid>
  <title><![CDATA[Is it Safe to Speak? Protection for Telephone-Based Payment Card Data]]></title>
  <description><![CDATA[<p>
	Recently, the <a href="https://www.pcisecuritystandards.org/" target="_blank">PCI Security Standards Council</a> released educational resource requirements for <a href="https://www.pcisecuritystandards.org/pdfs/pr_110318_call_recording.pdf" target="_blank">securing cardholder data in audio recordings</a>. The PCI SSC has been focusing on call center operations and recording systems of merchants. The need to provide a secure system to protect cardholder data is at an all-time high for these call centers.</p>
]]></description>
  <pubDate>Tue, 12 Apr 2011 18:06:16 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/April-2011/Is-it-Safe-to-Speak-Protection-for-Telephone-Base?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">6623aec4-9b57-46ce-91f2-58f4a4634c2a</guid>
  <title><![CDATA[Coalfire Systems Speaking at Shared Assessments Summit 2011]]></title>
  <description><![CDATA[<p>
	Do you know how to ensure reliability and resiliency in cloud and SaaS environments? Join leaders from within the IT outsourcing risk management industry at the <a href="http://www.cvent.com/events/shared-assessments-summit-march-2011/event-summary-4674fa4021ac46a4b37f5781ea3c8baf.aspx">Shared Assessments Summit 2011</a> in Boston on March 29 and 30.</p>
Coalfire is participating in this summit because the value of managing risk for companies today cannot be underestimated.]]></description>
  <pubDate>Fri, 25 Mar 2011 18:10:40 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/March-2011/Coalfire-Systems-Speaking-at-Shared-Assessments-Su?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">229411c3-e246-4a72-97ef-d4bde581395c</guid>
  <title><![CDATA[Compliance and the Cloud]]></title>
  <description><![CDATA[<p>
	&ldquo;The Cloud&rdquo; is a hot topic right now. Yet most people can&rsquo;t even define what &ldquo;the cloud&rdquo; really is. As I talk to more companies, who are considering the move, they all have two main concerns: security and compliance. Of course, security and compliance are key when it comes to cloud computing, but the questions you really need to be asking is not, &ldquo;Will I be secure and compliant if I move to the cloud?&rdquo; but rather, &ldquo;What do I need to do to be secure and compliant when I move to the cloud?&rdquo;</p>
]]></description>
  <pubDate>Mon, 14 Mar 2011 18:13:52 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/March-2011/Compliance-and-the-Cloud?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">f18bd823-465d-41ab-836a-0a1eda23b1ad</guid>
  <title><![CDATA[IT Compliance Matures into Risk Management]]></title>
  <description><![CDATA[<p>
	Over the past ten years rapid change and an evolving threat landscape has better prepared Coalfire to defend our clients against known risks. Not surprisingly, much of the progress is due to compliance-related investments. As we look towards the next ten years, we see a proactive risk management framework being set in place.</p>
]]></description>
  <pubDate>Mon, 07 Mar 2011 19:16:35 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/March-2011/IT-Compliance-Matures-into-Risk-Management?feed=blogs]]></link>     	
</item><item>
  <guid isPermaLink="false">b8eebb2e-02a2-45c4-88f0-b65a049dc5fd</guid>
  <title><![CDATA[Full Steam Ahead! Coalfire Systems Secures $5 Million in Funding from Baird Venture Partners]]></title>
  <description><![CDATA[<p>
	People often ask me what defines a successful company. At Coalfire Systems, it&rsquo;s having a clear roadmap of services that clients need and want, which in turn drives growth and expansion. I am pleased to announce that Coalfire Systems has received an investment of $5 million dollars from Baird Venture Partners.</p>
]]></description>
  <pubDate>Thu, 17 Feb 2011 19:21:03 GMT</pubDate>
  <link><![CDATA[http://www.coalfire.com/The-Coalfire-Blog/Feb-2011/Full-Steam-Ahead!-Coalfire-Systems-Secures-$5-Mill?feed=blogs]]></link>     	
</item></channel>
</rss>
