<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Verizon Data Breach Investigation:  The numbers say PCI IS important</title>
	<atom:link href="http://www.mckeay.net/2009/04/15/verizon-data-breach-investigation-the-numbers-say-pci-is-important/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mckeay.net/2009/04/15/verizon-data-breach-investigation-the-numbers-say-pci-is-important/</link>
	<description>The views of one man on security, privacy and anything else that catches his attention</description>
	<lastBuildDate>Thu, 29 Jul 2010 22:22:29 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
	<item>
		<title>By: RateNerd</title>
		<link>http://www.mckeay.net/2009/04/15/verizon-data-breach-investigation-the-numbers-say-pci-is-important/comment-page-1/#comment-4583</link>
		<dc:creator>RateNerd</dc:creator>
		<pubDate>Mon, 27 Apr 2009 13:29:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2009/04/15/verizon-data-breach-investigation-the-numbers-say-pci-is-important/#comment-4583</guid>
		<description>The rate of CC theft is really alarming - to the point that you can get CC numbers for as little as $0.06 according to Symantic&#039;s report on the black market.  I did an ROI calculation and even at that price it is still tempting for fraud - http://ratenerd.com/black-market-prices-for-stolen-credit-card-identity-theft-1080</description>
		<content:encoded><![CDATA[<p>The rate of CC theft is really alarming &#8211; to the point that you can get CC numbers for as little as $0.06 according to Symantic&#8217;s report on the black market.  I did an ROI calculation and even at that price it is still tempting for fraud &#8211; <a href="http://ratenerd.com/black-market-prices-for-stolen-credit-card-identity-theft-1080" rel="nofollow">http://ratenerd.com/black-market-prices-for-stolen-credit-card-identity-theft-1080</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: idblackbox</title>
		<link>http://www.mckeay.net/2009/04/15/verizon-data-breach-investigation-the-numbers-say-pci-is-important/comment-page-1/#comment-4525</link>
		<dc:creator>idblackbox</dc:creator>
		<pubDate>Wed, 22 Apr 2009 03:41:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2009/04/15/verizon-data-breach-investigation-the-numbers-say-pci-is-important/#comment-4525</guid>
		<description>You should have been on the phone with my client when I told her that the company she was using to process credit cards was not on the list of Validated Payment Applications! She went into this long spiel of how she doesn&#039;t want to switch because she likes the payment application company and blah blah blah.

One of the biggest challenges I see for most of these companies that are not on board yet is to get them to change their thought process. Standards, policies and procedures are all fine and good, but when not many company employees buy into it as a whole, it will be struggle for the entire process.

If everyone could envision the idea of, &quot;I scratch your back, you scratch mine&quot;, maybe they would realize, I should treat sensitive data in my company as I would want another company&#039;s employees to treat mine :)</description>
		<content:encoded><![CDATA[<p>You should have been on the phone with my client when I told her that the company she was using to process credit cards was not on the list of Validated Payment Applications! She went into this long spiel of how she doesn&#8217;t want to switch because she likes the payment application company and blah blah blah.</p>
<p>One of the biggest challenges I see for most of these companies that are not on board yet is to get them to change their thought process. Standards, policies and procedures are all fine and good, but when not many company employees buy into it as a whole, it will be struggle for the entire process.</p>
<p>If everyone could envision the idea of, &#8220;I scratch your back, you scratch mine&#8221;, maybe they would realize, I should treat sensitive data in my company as I would want another company&#8217;s employees to treat mine <img src='http://mckeay.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Network Security Blog &#187; Friday morning reading, 04/17/09</title>
		<link>http://www.mckeay.net/2009/04/15/verizon-data-breach-investigation-the-numbers-say-pci-is-important/comment-page-1/#comment-4501</link>
		<dc:creator>Network Security Blog &#187; Friday morning reading, 04/17/09</dc:creator>
		<pubDate>Fri, 17 Apr 2009 12:52:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2009/04/15/verizon-data-breach-investigation-the-numbers-say-pci-is-important/#comment-4501</guid>
		<description>[...] knew about the 2009 Data Breach Investigation by Verizon, but did you know they&#8217;re having a roadshow in support of the [...]</description>
		<content:encoded><![CDATA[<p>[...] knew about the 2009 Data Breach Investigation by Verizon, but did you know they&#8217;re having a roadshow in support of the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Interesting Information Security Bits for 04/15/2009 &#124; Infosec Ramblings</title>
		<link>http://www.mckeay.net/2009/04/15/verizon-data-breach-investigation-the-numbers-say-pci-is-important/comment-page-1/#comment-4491</link>
		<dc:creator>Interesting Information Security Bits for 04/15/2009 &#124; Infosec Ramblings</dc:creator>
		<pubDate>Wed, 15 Apr 2009 21:22:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2009/04/15/verizon-data-breach-investigation-the-numbers-say-pci-is-important/#comment-4491</guid>
		<description>[...] first pass at the PCI specific portions of the Verizon report. Network Security Blog &gt;&gt; Verizon Data Breach Investigation: The numbers say PCI IS important Tags: ( reports [...]</description>
		<content:encoded><![CDATA[<p>[...] first pass at the PCI specific portions of the Verizon report. Network Security Blog &gt;&gt; Verizon Data Breach Investigation: The numbers say PCI IS important Tags: ( reports [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.mckeay.net/2009/04/15/verizon-data-breach-investigation-the-numbers-say-pci-is-important/comment-page-1/#comment-4489</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Wed, 15 Apr 2009 15:25:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2009/04/15/verizon-data-breach-investigation-the-numbers-say-pci-is-important/#comment-4489</guid>
		<description>It&#039;s worth noting that the data set represents a mix of merchants from all levels.</description>
		<content:encoded><![CDATA[<p>It&#8217;s worth noting that the data set represents a mix of merchants from all levels.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LonerVamp</title>
		<link>http://www.mckeay.net/2009/04/15/verizon-data-breach-investigation-the-numbers-say-pci-is-important/comment-page-1/#comment-4488</link>
		<dc:creator>LonerVamp</dc:creator>
		<pubDate>Wed, 15 Apr 2009 15:05:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2009/04/15/verizon-data-breach-investigation-the-numbers-say-pci-is-important/#comment-4488</guid>
		<description>Disclaimer: Have yet to read the report.

But my opinion on PCI being relevant is that PCI is infinitely defensible and will always be relevant and never be a problem.

It&#039;s like a best practices approach. If someone is breached, PCI can infinitely say it&#039;s not their fault, but rather the entity at the time was non-compliant, or a QSA did a bad review, or whatnot.

I&#039;m not passionately against PCI by any means (I think it&#039;s valuable!), but I tend to be realistic with how deftly they&#039;re able to position themselves to never be at fault but always be relevant...no matter what happens.</description>
		<content:encoded><![CDATA[<p>Disclaimer: Have yet to read the report.</p>
<p>But my opinion on PCI being relevant is that PCI is infinitely defensible and will always be relevant and never be a problem.</p>
<p>It&#8217;s like a best practices approach. If someone is breached, PCI can infinitely say it&#8217;s not their fault, but rather the entity at the time was non-compliant, or a QSA did a bad review, or whatnot.</p>
<p>I&#8217;m not passionately against PCI by any means (I think it&#8217;s valuable!), but I tend to be realistic with how deftly they&#8217;re able to position themselves to never be at fault but always be relevant&#8230;no matter what happens.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
