<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: PCI is about transfering the risk, not mitigating it</title>
	<atom:link href="http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/</link>
	<description>The views of one man on security, privacy and anything else that catches his attention.  The views expressed on this blog do not reflect the views of my employer or anyone other than myself.</description>
	<lastBuildDate>Thu, 02 Feb 2012 21:45:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Network Security Blog &#187; PCI is just the beginning of security</title>
		<link>http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/comment-page-1/#comment-1327</link>
		<dc:creator>Network Security Blog &#187; PCI is just the beginning of security</dc:creator>
		<pubDate>Wed, 27 Feb 2008 15:54:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/#comment-1327</guid>
		<description>[...] PCI DSS is about risk mitigation (or risk transference, depending on your point of view).&nbsp; It list a minimum set of standards that merchants and [...]</description>
		<content:encoded><![CDATA[<p>[...] PCI DSS is about risk mitigation (or risk transference, depending on your point of view).&amp;nbsp; It list a minimum set of standards that merchants and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PCI DSS Compliance Demystified &#187; Blog Archive &#187; What is PCI all about?</title>
		<link>http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/comment-page-1/#comment-1111</link>
		<dc:creator>PCI DSS Compliance Demystified &#187; Blog Archive &#187; What is PCI all about?</dc:creator>
		<pubDate>Tue, 29 Jan 2008 16:52:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/#comment-1111</guid>
		<description>[...] a friend of mine, writes that PCI is about transferring risk and not mitigating it.  This implies that the acquiring bank somehow has the ability or responsibility to prevent a [...]</description>
		<content:encoded><![CDATA[<p>[...] a friend of mine, writes that PCI is about transferring risk and not mitigating it.  This implies that the acquiring bank somehow has the ability or responsibility to prevent a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/comment-page-1/#comment-1022</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Mon, 14 Jan 2008 19:44:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/#comment-1022</guid>
		<description>Great points.  And it&#039;s worth noting that there&#039;s nothing wrong with an ISMS or even use of PCI as a template for an ISMS per se, the issue comes in the inflexibility and perception that the letter of the law will fulfill some promise of security.

I mean to write something on the future of auditing at some point when all this mad rush is over for me.</description>
		<content:encoded><![CDATA[<p>Great points.  And it&#8217;s worth noting that there&#8217;s nothing wrong with an ISMS or even use of PCI as a template for an ISMS per se, the issue comes in the inflexibility and perception that the letter of the law will fulfill some promise of security.</p>
<p>I mean to write something on the future of auditing at some point when all this mad rush is over for me.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

