-
P2P Encryption Program now available from PCI Council
Mike Weber, Vice President, Coalfire Labs
The PCI council has updated the Point-to-Point encryption (P2PE) program requirements (PDF). The update impacts merchants, payment applications, point of sale vendors and service providers. As a participating organization of the PCI P2PE task force, providing input into the standard, I wanted to briefly explain how this affects the various PCI ecosystem participants.
The ultimate goal of the P2PE program is to reduce the PCI DSS scope that merchants experience by shifting the burden away from merchants toward solution providers who are providing validated P2PE solutions. Deploying validated P2PE solutions will simplify PCI DSS validation for merchants while reducing the risk of cardholder data breaches.
Read more
-
Moving to the Cloud: Considerations for Implementing Cloud Migration Plans
Kennet Westby, President and COO
Over 60 executive level attendees came to the Omni Interlocken Resort in Broomfield, Colorado for the National Council of Higer Education Loan Programs (NCHELP) Spring convention and to hear from a panel of cloud experts on how the migration to cloud IT services could impact their business in the future.
Read more
-
Coalfire Acquires Digital Resources Group in California
Rick Dakin, CEO, Co-founder and Chief Security Strategist
We have reached a new milestone at Coalfire and have announced the recent acquisition of privately held Digital Resources Group (DRG) in Redwood City, California. We are excited about our latest venture as it consolidates our leadership position within the IT Governance Risk and Compliance (IT GRC) services industry. As we continue to grow, acquisitions such as this will help us gain new staff, clients, skills and additional geographical presence enabling Coalfire to continue to provide top-notch services.
Read more
-
FISMA vs FedRAMP: Compliance requirement differences
Tom McAndrew, Chief Executive Officer, Coalfire
Organizations that work with, or want to work with, government agencies must manage to government compliance regulations. Almost everyone is familiar with the FISMA compliance standards, but with the announcement of FedRAMP, which provides a structure to manage compliance requirements for "a cloud first initiative" for government agencies and organizations working with them, there’s a new set of compliance requirements to adhere to. Or is there?
Read more
-
The hackerproof password? Tips and advice on password management
Kennet Westby, President and COO
Having some security expert tell you that you should be creating strong passwords that are unique per account and change frequently is like your dentist telling you that you should floss morning, night and after consuming any dentally dangerous foods. The majority of us say, “yeah right”. The truth is that you really must do better than what the average person is doing today. In our penetration testing and forensics practices we constantly discover, usually very intelligent, people using the same weak password or PIN across every account without ever changing them.
Read more