<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>CPSC 466 Reading Assignment 15 by Marc Velasco</title>
      <link>https://padlet.com/themarcvelasco/od041cv7kkcakt8h</link>
      <description>Thoughts and summary of main points from Reading Assignment 15 - PCI DSS Standard v 4.0</description>
      <language>en-us</language>
      <pubDate>2022-05-04 01:19:01 UTC</pubDate>
      <lastBuildDate>2022-05-04 02:11:59 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>Risk Management</title>
         <author></author>
         <link>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169230893</link>
         <description><![CDATA[<div>Reminded me of the SQA reading on risk management. RM listed three steps: Identify, Analyze, assign priority to risks.&nbsp;<br><br>Current reading listed 🤬, Repair, and Report.&nbsp;</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-04 01:47:30 UTC</pubDate>
         <guid>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169230893</guid>
      </item>
      <item>
         <title>Topics of PCI DSS</title>
         <author></author>
         <link>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169235303</link>
         <description><![CDATA[<div>1. Build and Maintain a Secure Network and System<br><br>2. Protect Cardholder Data<br><br>3. Maintain a Vulnerability Management Program<br><br>4. Implement Strong Access Control Measures<br><br>5. Regularly Monitor and Test Networks.&nbsp;<br><br>6. Maintain an Information Security Policy</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-04 01:51:23 UTC</pubDate>
         <guid>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169235303</guid>
      </item>
      <item>
         <title>How to Properly Report</title>
         <author></author>
         <link>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169243888</link>
         <description><![CDATA[<ol><li>Contact Information and Report Date</li><li>Executive Summary</li><li>Description of Scope of Work and Approach Taken</li><li>Details about Reviewed Environment</li><li>Quarterly Scan Results</li><li>Findings and Observations</li></ol><div><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-04 01:58:35 UTC</pubDate>
         <guid>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169243888</guid>
      </item>
      <item>
         <title>Not using vendor supplied passkeys</title>
         <author></author>
         <link>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169246542</link>
         <description><![CDATA[<div>Something that seems quite common sense, but perhaps is a bigger issue that threatens OpSec in the paycard industry.</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-04 02:00:56 UTC</pubDate>
         <guid>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169246542</guid>
      </item>
      <item>
         <title>PCI DSS</title>
         <author></author>
         <link>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169251880</link>
         <description><![CDATA[<div>Specific goals and requirements must be met as part of the PCI DSS, which include maintaining secure networks, protecting cardholder data, managing vulnerabilities, implementing access controls, testing networks and maintaining a security policy.</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-04 02:05:56 UTC</pubDate>
         <guid>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169251880</guid>
      </item>
      <item>
         <title>Three Ongoing Steps to adhering to PCI DSS standards</title>
         <author></author>
         <link>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169254908</link>
         <description><![CDATA[<div>Assess - Identify all locations of cardholder data, taking an inventory of your IT assets and business processes for payment card processing and analyzing them for vulnerabilities that could expose cardholder data.<br>Repair - Fixing any identified vulnerabilities and removing unnecessary cardholder data storage and implementing secure business practices<br>Report - documenting assessment and remediation details and submitting compliance reports to the acquiring bank and card brands that you do business with.</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-04 02:09:00 UTC</pubDate>
         <guid>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169254908</guid>
      </item>
      <item>
         <title>PCI DSS Requirements </title>
         <author></author>
         <link>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169256651</link>
         <description><![CDATA[<div>1. Install and maintain a firewall configuration to protect cardholder data.<br>2. Do not use vendor-supplied defaults for system passwords and other security parameters.&nbsp;<br>3. Protect stored cardholder data.<br>4. Encrypt transmission of cardholder data across open, public networks.<br>5. Protect all systems against malware and regularly update anti-virus software or programs.<br>6. Develop and maintain secure systems and applications.<br>7. Restrict access to cardholder data by business need to know.<br>8. Identify and authenticate access to system components.<br>9. Restrict physical access to cardholder data.<br>10. Track and monitor all access to network resources and cardholder data.<br>11. Regularly test security systems and processes.<br>12. Maintain a policy that addresses information security for all personnel.</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-04 02:10:45 UTC</pubDate>
         <guid>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169256651</guid>
      </item>
      <item>
         <title>Overview of PCI Requirements </title>
         <author></author>
         <link>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169257883</link>
         <description><![CDATA[<div>&nbsp;Requirements set by the PCI security standards council (PCI SSC) to protect cardholder data. The standards apply to all transactions (process or transmit data) with requirements for software developers and manufacturers of applications and devices used in those transactions. The council is responsible for managing the security standards.&nbsp;</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-04 02:11:59 UTC</pubDate>
         <guid>https://padlet.com/themarcvelasco/od041cv7kkcakt8h/wish/2169257883</guid>
      </item>
   </channel>
</rss>
