<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: PCI is about transfering the risk, not mitigating it</title>
	<atom:link href="http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/</link>
	<description>The views of one man on security, privacy and anything else that catches his attention</description>
	<pubDate>Fri, 08 Aug 2008 20:56:17 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>By: Network Security Blog &#187; PCI is just the beginning of security</title>
		<link>http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/#comment-1327</link>
		<dc:creator>Network Security Blog &#187; PCI is just the beginning of security</dc:creator>
		<pubDate>Wed, 27 Feb 2008 15:54:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/#comment-1327</guid>
		<description>[...] PCI DSS is about risk mitigation (or risk transference, depending on your point of view).&#38;nbsp; It list a minimum set of standards that merchants and [...]</description>
		<content:encoded><![CDATA[<p>[...] PCI DSS is about risk mitigation (or risk transference, depending on your point of view).&amp;nbsp; It list a minimum set of standards that merchants and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PCI DSS Compliance Demystified &#187; Blog Archive &#187; What is PCI all about?</title>
		<link>http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/#comment-1111</link>
		<dc:creator>PCI DSS Compliance Demystified &#187; Blog Archive &#187; What is PCI all about?</dc:creator>
		<pubDate>Tue, 29 Jan 2008 16:52:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/#comment-1111</guid>
		<description>[...] a friend of mine, writes that PCI is about transferring risk and not mitigating it.  This implies that the acquiring bank somehow has the ability or responsibility to prevent a [...]</description>
		<content:encoded><![CDATA[<p>[...] a friend of mine, writes that PCI is about transferring risk and not mitigating it.  This implies that the acquiring bank somehow has the ability or responsibility to prevent a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/#comment-1022</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Mon, 14 Jan 2008 19:44:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/01/14/pci-is-about-transfering-the-risk-not-mitigating-it/#comment-1022</guid>
		<description>Great points.  And it's worth noting that there's nothing wrong with an ISMS or even use of PCI as a template for an ISMS per se, the issue comes in the inflexibility and perception that the letter of the law will fulfill some promise of security.

I mean to write something on the future of auditing at some point when all this mad rush is over for me.</description>
		<content:encoded><![CDATA[<p>Great points.  And it&#8217;s worth noting that there&#8217;s nothing wrong with an ISMS or even use of PCI as a template for an ISMS per se, the issue comes in the inflexibility and perception that the letter of the law will fulfill some promise of security.</p>
<p>I mean to write something on the future of auditing at some point when all this mad rush is over for me.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.332 seconds -->
