<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: PCI Compliance in the Cloud: Get it in writing!</title>
	<atom:link href="http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/</link>
	<description>The views of one man on security, privacy and anything else that catches his attention</description>
	<lastBuildDate>Sat, 20 Mar 2010 10:00:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Mark</title>
		<link>http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/comment-page-1/#comment-5026</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Thu, 20 Aug 2009 00:51:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/#comment-5026</guid>
		<description>Thanks for the information.  Big news in Australia for cloud computing is Telstra have just announced a $500m investment into cloud services.  Great news for the local industry.</description>
		<content:encoded><![CDATA[<p>Thanks for the information.  Big news in Australia for cloud computing is Telstra have just announced a $500m investment into cloud services.  Great news for the local industry.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin</title>
		<link>http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/comment-page-1/#comment-4968</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Thu, 13 Aug 2009 14:09:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/#comment-4968</guid>
		<description>Good to know Jason.  And I&#039;m glad to know that Amazon is acknowledging that they are not enabling merchants to become PCI compliant.

Martin</description>
		<content:encoded><![CDATA[<p>Good to know Jason.  And I&#8217;m glad to know that Amazon is acknowledging that they are not enabling merchants to become PCI compliant.</p>
<p>Martin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason Rushton</title>
		<link>http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/comment-page-1/#comment-4967</link>
		<dc:creator>Jason Rushton</dc:creator>
		<pubDate>Thu, 13 Aug 2009 14:02:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/#comment-4967</guid>
		<description>I realize I&#039;m resurrecting an ancient post, but it was very enlightening when I was researching Amazon and PCI

I just wanted to add that I did get an answer from Amazon stating that it is NOT possible to be PCI Level 1 certified using AWS services:

http://developer.amazonwebservices.com/connect/thread.jspa?threadID=34960&amp;tstart=0</description>
		<content:encoded><![CDATA[<p>I realize I&#8217;m resurrecting an ancient post, but it was very enlightening when I was researching Amazon and PCI</p>
<p>I just wanted to add that I did get an answer from Amazon stating that it is NOT possible to be PCI Level 1 certified using AWS services:</p>
<p><a href="http://developer.amazonwebservices.com/connect/thread.jspa?threadID=34960&amp;tstart=0" rel="nofollow">http://developer.amazonwebservices.com/connect/thread.jspa?threadID=34960&amp;tstart=0</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jackie</title>
		<link>http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/comment-page-1/#comment-4634</link>
		<dc:creator>Jackie</dc:creator>
		<pubDate>Mon, 04 May 2009 16:57:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/#comment-4634</guid>
		<description>&lt;a href=&quot;http://www.merchantserviceprovider.org&quot; title=&quot;merchant service provider&quot; rel=&quot;nofollow&quot;&gt;Merchant Service Provider&lt;/a&gt; is a great new alternative to Paypal and Google Checkout.</description>
		<content:encoded><![CDATA[<p><a href="http://www.merchantserviceprovider.org" title="merchant service provider" rel="nofollow">Merchant Service Provider</a> is a great new alternative to Paypal and Google Checkout.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jess</title>
		<link>http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/comment-page-1/#comment-4407</link>
		<dc:creator>Jess</dc:creator>
		<pubDate>Fri, 27 Mar 2009 17:16:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/#comment-4407</guid>
		<description>A few have stated something to the effect of &quot;don&#039;t hand the cardholder data&quot;.... or, that &quot;amazon would not be holding the data, the VM would&quot;. This is simply not true. For instance, an SQL database on a VM in the could, would still be sitting on hardware somewhere, and for all intents and purposes that VM is an application on said hardware. Which would require the underlying hardware/OS to be PCI compliant. What happens when the cloud is compromised, and an entire VM image is offloaded to the attackers machine? The attacker has ALL the data.</description>
		<content:encoded><![CDATA[<p>A few have stated something to the effect of &#8220;don&#8217;t hand the cardholder data&#8221;&#8230;. or, that &#8220;amazon would not be holding the data, the VM would&#8221;. This is simply not true. For instance, an SQL database on a VM in the could, would still be sitting on hardware somewhere, and for all intents and purposes that VM is an application on said hardware. Which would require the underlying hardware/OS to be PCI compliant. What happens when the cloud is compromised, and an entire VM image is offloaded to the attackers machine? The attacker has ALL the data.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cloud compliance: Will PCI be applied to cloud computing by the FTC? - IT Compliance Advisor</title>
		<link>http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/comment-page-1/#comment-4397</link>
		<dc:creator>Cloud compliance: Will PCI be applied to cloud computing by the FTC? - IT Compliance Advisor</dc:creator>
		<pubDate>Mon, 23 Mar 2009 19:23:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/#comment-4397</guid>
		<description>[...] PCI Compliance in the Cloud: Get it in writing!       &#160;&#160;&#160;  Comment &#160;&#160;&#160;  RSS Feed &#160;&#160;&#160;  Email a friend [...]</description>
		<content:encoded><![CDATA[<p>[...] PCI Compliance in the Cloud: Get it in writing!       &nbsp;&nbsp;&nbsp;  Comment &nbsp;&nbsp;&nbsp;  RSS Feed &nbsp;&nbsp;&nbsp;  Email a friend [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PCI Data Security Standard en virtualisatie &#171; EarlyBert</title>
		<link>http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/comment-page-1/#comment-3740</link>
		<dc:creator>PCI Data Security Standard en virtualisatie &#171; EarlyBert</dc:creator>
		<pubDate>Sun, 09 Nov 2008 18:42:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/#comment-3740</guid>
		<description>[...] om hulp bij zijn transactieverwerking via Amazon&#8217;s EC2 platform. Dit werd onder andere opgepikt door Martin McKeay en eindigde eigenlijk in een [...]</description>
		<content:encoded><![CDATA[<p>[...] om hulp bij zijn transactieverwerking via Amazon&#8217;s EC2 platform. Dit werd onder andere opgepikt door Martin McKeay en eindigde eigenlijk in een [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cranston Snoard</title>
		<link>http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/comment-page-1/#comment-3699</link>
		<dc:creator>Cranston Snoard</dc:creator>
		<pubDate>Tue, 04 Nov 2008 18:28:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/#comment-3699</guid>
		<description>It&#039;s not just PCI that will get caught or need to adapt to cloud computing environments... SOX, privacy, and other compliance issues require similar attention in a cloud computing environment.

Proper due diligence and risk analysis need to be part of the business case for a firm to adopt cloud computing.  It may be that regulators et al will not allow use of cloud computing if one performs certain types of processing or handles certain classifications of data.  Similar requirements for isolation exist elsewhere - such as handling of classified military data.

On the other hand, everyone seems to overlook one of the easiest means of PCI compliance - simply don&#039;t handle the card data unless you have to.  There are lots of ways to do this - just get your head out of the clouds...</description>
		<content:encoded><![CDATA[<p>It&#8217;s not just PCI that will get caught or need to adapt to cloud computing environments&#8230; SOX, privacy, and other compliance issues require similar attention in a cloud computing environment.</p>
<p>Proper due diligence and risk analysis need to be part of the business case for a firm to adopt cloud computing.  It may be that regulators et al will not allow use of cloud computing if one performs certain types of processing or handles certain classifications of data.  Similar requirements for isolation exist elsewhere &#8211; such as handling of classified military data.</p>
<p>On the other hand, everyone seems to overlook one of the easiest means of PCI compliance &#8211; simply don&#8217;t handle the card data unless you have to.  There are lots of ways to do this &#8211; just get your head out of the clouds&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ICMPECHO &#183; PCI DSS: What&#8217;s in the cloud?</title>
		<link>http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/comment-page-1/#comment-3698</link>
		<dc:creator>ICMPECHO &#183; PCI DSS: What&#8217;s in the cloud?</dc:creator>
		<pubDate>Tue, 04 Nov 2008 12:05:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/#comment-3698</guid>
		<description>[...] an interesting article by Martin McKeay through &#8220;Security Bloggers Network&#8221; which discusses PCI compliance and the implications [...]</description>
		<content:encoded><![CDATA[<p>[...] an interesting article by Martin McKeay through &#8220;Security Bloggers Network&#8221; which discusses PCI compliance and the implications [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Interesting Information Security Bits for 11/03/2008 &#171; Infosec Ramblings</title>
		<link>http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/comment-page-1/#comment-3697</link>
		<dc:creator>Interesting Information Security Bits for 11/03/2008 &#171; Infosec Ramblings</dc:creator>
		<pubDate>Mon, 03 Nov 2008 23:58:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/#comment-3697</guid>
		<description>[...] Network Security Blog &gt;&gt; PCI Compliance in the Cloud: Get it in writing! Martin has written a article that you should read if you have any responsibility for PCI. [...]</description>
		<content:encoded><![CDATA[<p>[...] Network Security Blog &gt;&gt; PCI Compliance in the Cloud: Get it in writing! Martin has written a article that you should read if you have any responsibility for PCI. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
