Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 125 guests and 6 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Featuresarrow Book Reviewsarrow [Article]-Book Review: PCI Compliance
EH-Net
February 10, 2012, 07:52:52 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: [Article]-Book Review: PCI Compliance  (Read 10879 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 3845


Editor-In-Chief


View Profile WWW
« on: January 04, 2010, 04:22:40 PM »

Old friend and former MS MVP, Joel Dubin (The IT Security Guy), has tons of experience dealing with PCI working with Trustwave. So I thought he was the perfect person to review this book. Thankfully he said yes. Much appreciated.

Permanent link: [Article]-Book Review: PCI Compliance

Quote

Review by Joel Dubin, CISSP

The Payment Card Industry Data Security Standard (PCI DSS) has taken it on the chin recently.  With several high profile breaches of credit card numbers, some critics of the industry standard have said it either isn’t strong enough, or should be abolished altogether.  But as Dr. Anton Chuvakin and Branden Williams correctly point out in the second edition of their book, PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance, PCI is here to stay.

This is no ordinary field manual to the PCI standard.  It isn’t a book, for example, that a PCI auditor, called a Qualified Security Assessor (QSA), would have open on their lap as a reference while working with a client.  Instead it carefully weaves together PCI, which is considered compliance, with IT security.  In fact, it also discusses PCI in the universe of other regulatory compliance standards, like SOX and HIPAA, which also give IT managers plenty of headaches.
         
The book correctly notes that compliance isn’t the same as security, a common misconception of PCI critics, but that it is part of a sound IT security program covering both bases, compliance and security, and not narrowly focused on PCI, but other standards, as well.  That’s good news for IT managers suffering from compliance fatigue and looking for a single path to handle not just security but all the other regulations they face.  PCI might not be a cure-all, but the IT security it requires can go a long way toward that single path.
         

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Andrew Waite
Hero Member
*****
Offline Offline

Posts: 857



View Profile WWW
« Reply #1 on: January 05, 2010, 09:46:01 AM »

Nice review Joel, I was in two minds whether to pick this one up as I was concerned it might just be a re-hash of the PCI requirements with some 'explanation' that didn't go beyond what you would already know.

Sounds like it goes beyond what I was concerned about, I'll add it to my already increasing To Read list.

P.S. On a side note one of Joel's examples jogged my memory; I was waiting for the missus outside a shop bored recently and fired up my phone's wireless scanner to be nosey. Didn't want to poke around too much but found an SSID of 'epos' running WEP, could be interesting...
Logged

don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 3845


Editor-In-Chief


View Profile WWW
« Reply #2 on: February 24, 2010, 10:46:23 AM »

Submitted to digg:

http://digg.com/tech_news/Book_Review_PCI_Compliance

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.273 seconds with 24 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge Training: Build Security Skills to Protect and Defend

offsec_130x200-2_jan-feb2012.png
Offensive Security
AWE Live in the Caribbean!
March 5 - 9, 2012

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: Refer_EHN
Including SANS Phoenix 2012, SANS 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.