by Gerdien van den Bosch | Oct 1, 2019 | Compliance, PCI DSS
We still have clients ask us this question from time to time. Unfortunately, simply encrypting Cardholder data (CHD) doesn’t necessarily de-scope it. Under most circumstances, if encrypted CHD is stored, processed or transmitted it will still be in the scope of PCI...
by Gerdien van den Bosch | Aug 26, 2019 | Compliance, PCI DSS
Complying to PCI DSS requires you to have both documented processes and policies in place. Remember: PCI DSS is about People, Processes and Technology. The processes are usually described in policy and process documentation. You have to supply these documents as...
by Gerdien van den Bosch | Jul 23, 2019 | Compliance, PCI DSS
This blog is part of a blog series on the 12 requirements of PCI DSS. We discuss the common challenges and explain what kind of evidence is needed to comply with the requirement. Here we discuss: Requirement 12: Maintain a policy that addresses information...
by Gerdien van den Bosch | Jul 9, 2019 | Compliance, PCI DSS
This blog is part of a blog series on the 12 requirements of PCI DSS. We discuss the common challenges and explain what kind of evidence is needed to comply with the requirement. Here we discuss: Requirement 11: Regularly test security systems and processes The system...
by Gerdien van den Bosch | Jul 1, 2019 | Compliance, PCI DSS
Achieving PCI Compliance can be challenging. However, maintaining compliance with the latest version of the PCI Data Security Standards can be even more difficult. As part of the PCI Compliance process, there are many different things that an organization must do...
by Gerdien van den Bosch | Jun 24, 2019 | Compliance, PCI DSS
The Self-Assessment Questionnaires (SAQs) are validation tools designed to help merchants and service providers report on the results of their compliance with PCI DSS. It must be completed as evidence of their completion of the PCI DSS self-assessment. These SAQs need...