• The HOW, WHY, and HUH? Blog on Disputes

    Travis Finn, Consultant, CoalfireOne Scanning Services

    As you may know, performing vulnerability scans is a requirement for PCI DSS compliance. One of those specific requirements, described in section 11.2.2, states that quarterly external scanning must be done by a qualified Approved Scanning Vendor. Coalfire just so happens to be an ASV, so if you need these scans we would happily oblige!

    Read more
  • The California Consumer Privacy Act: Will It Apply to Your Organization?

    Lisa Gumbs, Senior Consultant, Commercial Services, GDPR, Coalfire

    In August 2018, California issued a revised version of a new consumer privacy law—the California Consumer Privacy Act (CCPA). This statute goes into effect on January 1, 2020 and provides broad privacy protections to California consumers. This statute will have wide-ranging effects outside of California because it will apply to organizations that conduct business in California.

    Read more
  • PA-DSS to Software Security Framework: What You Need to Know

    Bhavna Sondhi, Senior Consultant, Commercial Services, Coalfire

    The Payment Application Data Security Standard (PA-DSS) developed by the Payment Card Industry Security Standards Council (PCI SSC) applies to software vendors and others who develop payment applications that store, process, or transmit cardholder data and/or sensitive authentication data. The list of various payment applications that are currently validated for software vendors is located on the PCI SSC Website.

    Read more
  • Scan Interference

    James Cox, Support Analyst, CoalfireOne Scanning Services, Coalfire

    Scan interference is best defined as when traffic from our scanners gets blocked, filtered, dropped, or modified in response to some sort of active protection system not recognizing our traffic. Once our scanners are flagged as an intruder, the client’s environment is no longer accessible, which causes the scan to fail. In order to ensure that reliable scans can be conducted, our scanners must be allowed to perform scanning without this interruption.

    Read more
  • CoalfireOne Special Notes

    Erica Woods, Associate, Commercial Services, Vulnerability Assessments and Scanning, Coalfire

    PCI-DSS can be challenging  to navigate – particularly when it comes to the ASV scanning requirements.  While fulfilling the scanning requirement is easy, obtaining a passing  attestation report may involve more than simply remediating failed findings.  One requirement that we receive many questions about is Special Notes.

    Read more
  • RISE in the Community

    Chalice Beam, Senior Manager, Health & Life Sciences, Coalfire

    Hope House of Colorado is metro-Denver’s only resource for providing free self-sufficiency programs to teen moms, including residential, General Educational Development (GED), and college and career programs. Additional supportive services include parenting and healthy relationship classes, life skills workshops, and certified counseling, all designed to prepare young mothers for long-term independence. On December 3, 2018, Coalfire RISE members teamed with Hope House of Colorado to announce a scholarship program to add to Hope House’s programs and advance our mission of giving back to our communities while supporting the development of cybersecurity talent.

    Read more

Recent Posts

Post Topics



Accounting Agency AICPA Assessment assessments ASV audit AWS AWS Certified Cloud Practitioner AWS Certs AWS Summit Azure bitcoin Black Hat Black Hat 2017 blockchain Blueborne Breach BSides BSidesLV Burp BYOD California Consumer Privacy Act careers CCPA Chertoff CISO cloud CMMC CoalfireOne Compliance Covid-19 CPRA credit cards C-Store Culture Cyber cyber attacks Cyber Engineering cyber incident Cyber Risk cyber threats cyberchrime cyberinsurance cybersecurity danger Dangers Data DDoS DevOps DevSecOps DFARS DFARS 7012 diacap diarmf Digital Forensics DoD DRG DSS e-banking Education encryption engineering ePHI Equifax Europe EU-US Privacy Shield federal FedRAMP financial services FISMA Foglight forensics Gartner Report GDPR Google Cloud NEXT '18 government GRC hack hacker hacking Halloween Health Healthcare heartbleed Higher Education HIMSS HIPAA HITECH HITRUST HITRUST CSF Horror Incident Response interview IoT ISO IT JAB JSON keylogging Kubernetes Vulnerability labs LAN law firms leadership legal legislation merchant mobile NESA News NH-ISAC NIST NIST 800-171 NIST SP 800-171 NotPetya NRF NYCCR O365 OCR of P2PE PA DSS PA-DSS password passwords Payments PCI PCI DSS penetration Penetration Testing pentesting Petya/NotPetya PHI Phishing Phising policy POODLE PowerShell Presidential Executive Order Privacy program Ransomware Retail Risk RSA RSA 2019 Safe Harbor Scanning Scans scary security security. SOC SOC 2 social social engineering Spectre Splunk Spooky Spraying Attack SSAE State Stories Story test Testing theft Virtualization Visa vulnerability Vulnerability management web Wifi women XSS