<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Level 2 merchants are going to have to get serious about PCI</title>
	<atom:link href="http://www.mckeay.net/2009/06/17/level-2-merchants-are-going-to-have-to-get-serious-about-pci/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mckeay.net/2009/06/17/level-2-merchants-are-going-to-have-to-get-serious-about-pci/</link>
	<description>The views of one man on security, privacy and anything else that catches his attention.  The views expressed on this blog do not reflect the views of my employer or anyone other than myself.</description>
	<lastBuildDate>Thu, 02 Feb 2012 21:45:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Martin</title>
		<link>http://www.mckeay.net/2009/06/17/level-2-merchants-are-going-to-have-to-get-serious-about-pci/comment-page-1/#comment-4835</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Wed, 24 Jun 2009 21:24:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2009/06/17/level-2-merchants-are-going-to-have-to-get-serious-about-pci/#comment-4835</guid>
		<description>David,

I wish that this had been discussed with the industry as a whole before MC had gone through with it, but I see it as a good thing regardless.  I&#039;d heard rumors earlier this year that this was something that was being contemplated, but so far everyone I&#039;ve talked to said the move caught them by surprise.  

Martin</description>
		<content:encoded><![CDATA[<p>David,</p>
<p>I wish that this had been discussed with the industry as a whole before MC had gone through with it, but I see it as a good thing regardless.  I&#8217;d heard rumors earlier this year that this was something that was being contemplated, but so far everyone I&#8217;ve talked to said the move caught them by surprise.  </p>
<p>Martin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Whitelegg</title>
		<link>http://www.mckeay.net/2009/06/17/level-2-merchants-are-going-to-have-to-get-serious-about-pci/comment-page-1/#comment-4833</link>
		<dc:creator>Dave Whitelegg</dc:creator>
		<pubDate>Wed, 24 Jun 2009 11:32:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2009/06/17/level-2-merchants-are-going-to-have-to-get-serious-about-pci/#comment-4833</guid>
		<description>I was speaking with some of the senior folk at Visa Europe about this recently, it is fair to say they were rather surprised by this move by MasterCard, and said Visa had no plans to follow suit in requiring level 2 merchants to under go an inaugural onsite assessment by a QSA.

The cards schemes can set their own criteria in regards to PCI DSS assessment requirements; however I personally don’t think it is good for the PCI standard to have disjointed assessment requirements.

I appreciate the competition laws, but for me PCI&#039;s main strength is it is an industry agreed and accepted standard, so I am hoping this doesn’t lead to further fractures and disjointed messaging.</description>
		<content:encoded><![CDATA[<p>I was speaking with some of the senior folk at Visa Europe about this recently, it is fair to say they were rather surprised by this move by MasterCard, and said Visa had no plans to follow suit in requiring level 2 merchants to under go an inaugural onsite assessment by a QSA.</p>
<p>The cards schemes can set their own criteria in regards to PCI DSS assessment requirements; however I personally don’t think it is good for the PCI standard to have disjointed assessment requirements.</p>
<p>I appreciate the competition laws, but for me PCI&#8217;s main strength is it is an industry agreed and accepted standard, so I am hoping this doesn’t lead to further fractures and disjointed messaging.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Network Security Blog &#187; Saturday morning reading for 06/20/09</title>
		<link>http://www.mckeay.net/2009/06/17/level-2-merchants-are-going-to-have-to-get-serious-about-pci/comment-page-1/#comment-4822</link>
		<dc:creator>Network Security Blog &#187; Saturday morning reading for 06/20/09</dc:creator>
		<pubDate>Sat, 20 Jun 2009 14:32:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2009/06/17/level-2-merchants-are-going-to-have-to-get-serious-about-pci/#comment-4822</guid>
		<description>[...] off, I have a cluster of stories on PCI.&#160; MasterCard stunned a lot of us this week by changing the requirements for Level 2 merchant, making it mandatory for them to have an annual [...]</description>
		<content:encoded><![CDATA[<p>[...] off, I have a cluster of stories on PCI.&nbsp; MasterCard stunned a lot of us this week by changing the requirements for Level 2 merchant, making it mandatory for them to have an annual [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Interesting Information Security Bits for 06/18/2009 &#124; Infosec Ramblings</title>
		<link>http://www.mckeay.net/2009/06/17/level-2-merchants-are-going-to-have-to-get-serious-about-pci/comment-page-1/#comment-4819</link>
		<dc:creator>Interesting Information Security Bits for 06/18/2009 &#124; Infosec Ramblings</dc:creator>
		<pubDate>Thu, 18 Jun 2009 20:42:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2009/06/17/level-2-merchants-are-going-to-have-to-get-serious-about-pci/#comment-4819</guid>
		<description>[...] Martin says, Level 2 merchants are now faced with a little bit higher bar to get over. Network Security Blog &gt;&gt; Level 2 merchants are going to have to get serious about PCI Tags: ( pci [...]</description>
		<content:encoded><![CDATA[<p>[...] Martin says, Level 2 merchants are now faced with a little bit higher bar to get over. Network Security Blog &gt;&gt; Level 2 merchants are going to have to get serious about PCI Tags: ( pci [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chaordic Mind &#187; MasterCard change for L2 merchants increases the market for QSAs by 2-4x</title>
		<link>http://www.mckeay.net/2009/06/17/level-2-merchants-are-going-to-have-to-get-serious-about-pci/comment-page-1/#comment-4810</link>
		<dc:creator>Chaordic Mind &#187; MasterCard change for L2 merchants increases the market for QSAs by 2-4x</dc:creator>
		<pubDate>Thu, 18 Jun 2009 06:12:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2009/06/17/level-2-merchants-are-going-to-have-to-get-serious-about-pci/#comment-4810</guid>
		<description>[...] actually more concerned about the currently overworked assessors having their workload added to.  Martin McKeay notes the following: &#8220;I’m hoping that the quality of the assessors doesn’t fall because of the huge influx of [...]</description>
		<content:encoded><![CDATA[<p>[...] actually more concerned about the currently overworked assessors having their workload added to.  Martin McKeay notes the following: &#8220;I’m hoping that the quality of the assessors doesn’t fall because of the huge influx of [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

