loader from loading.io

IIA Knoxville—Risky Business

Cybersecurity Sense

Release Date: 03/19/2018

PCI Monthly Update: Latest PCI News, Requirement 11 Overview, and QSA Insights show art PCI Monthly Update: Latest PCI News, Requirement 11 Overview, and QSA Insights

Cybersecurity Sense

Join us for the latest episode of our PCI Monthly Update podcast, where we explore the latest developments in the world of payment card industry security. We begin with a news segment covering the launch of PCI v4.0 and the ins and outs of the new INFI (Items Noted For Improvement) Worksheet. Next up, we'll cover Requirement 11 - Test security of systems and networks regularly. This requirement can either be the easiest or hardest for organizations depending on their setup. Our QSA experts provide their insights on best practices and what has changed in v4.0. This episode is a must-listen for...

info_outline
PCI Monthly Update: Version 4.0 Countdown, Requirement 10, and QSA Insights show art PCI Monthly Update: Version 4.0 Countdown, Requirement 10, and QSA Insights

Cybersecurity Sense

In this edition of the PCI Monthly Update, we’re counting down to the launch of PCI 4.0! We start this month's podcast with a reminder that v4.0 goes into full effect on March 31. Our focus then shifts to Requirement 10 covering logging and monitoring all access to system components and card holder data and what is changing with v4.0. This podcast is your monthly briefing on PCI standards - an indispensable listen for anyone tasked with safeguarding payment card data.

info_outline
PCI Monthly Update: Gearing Up for Version 4.0, Mastering Requirement 9, and QSA Insights show art PCI Monthly Update: Gearing Up for Version 4.0, Mastering Requirement 9, and QSA Insights

Cybersecurity Sense

In this January edition of the PCI Monthly Update, we’re on the brink of exciting changes with version 4.0 just around the corner! We start with a spotlight on the ongoing Request for Comments (RFC) period for PCI DSS v4.0, inviting insights from industry experts. Plus, we discuss the Global Content Library, showcasing insights from the 2023 Community Meetings. Our focus then shifts to Requirement 9, where we break down the critical protocols for restricting physical access to cardholder data. We'll cover everything from documenting security policies to managing visitor access, ensuring...

info_outline
PCI Monthly Update: December News, Deep Dive into Requirement 8, and QSA Q&A show art PCI Monthly Update: December News, Deep Dive into Requirement 8, and QSA Q&A

Cybersecurity Sense

Join us for the latest episode of our PCI Monthly Update podcast, where we explore the latest developments in the world of payment card industry security. We begin with a news segment highlighting the PCI SSC's TRA Guidance. Next, we delve into Requirement 8 of the PCI DSS, dedicated to identifying users and authenticating access to system components. We'll explore the intricate details of this requirement, covering sub-requirements 8.1 to 8.6. These discussions will include processes for user identification, strict management of user and administrator accounts, strong authentication methods,...

info_outline
PCI Monthly Update: October - New SAQ Review, Focused Look at Requirement 7, and Expert QSA Insights show art PCI Monthly Update: October - New SAQ Review, Focused Look at Requirement 7, and Expert QSA Insights

Cybersecurity Sense

Dive into the latest in the PCI landscape with our October update. We kick off with a news segment spotlighting the new SAQ SPOC (Software PIN Entry on COTS) which includes portions of PCI DSS Requirements 3, 8, 9, and 12. Transitioning to Requirement 7, we discuss restricting access to system components and cardholder data based on business necessity, delving into sub-requirements 7.1 to 7.3, and discussing the principles of 'need to know' and 'least privileges.' Our QSA Q&A segment addresses the applicability of Requirement 7 to customer/cardholder accounts, clarifying the scope and...

info_outline
PCI Monthly Update: September Highlights & Requirement 6 Deep Dive show art PCI Monthly Update: September Highlights & Requirement 6 Deep Dive

Cybersecurity Sense

Catch the latest news in our September "PCI Monthly Update" from Tuesday, September 26, 2023. We kick things off with key insights from the recent PCI Community Meeting. Next, we dive into Requirement 6, discussing the essence of secure software development, from processes to security vulnerabilities, web application protection, and change management. Our QSA Q&A segment addresses a vital question: What documentation should you expect from PCI DSS compliant service providers? Join us for a succinct roundup of September's essential PCI updates and insights. Perfect for both newcomers...

info_outline
PCI Monthly Update: August Highlights & Requirement 5 Breakdown show art PCI Monthly Update: August Highlights & Requirement 5 Breakdown

Cybersecurity Sense

Tune in to the August edition of our PCI Monthly Update. We kick off with a sneak peek into the upcoming PCI North America Community Meeting in Portland and introduce the newly launched PCI Community Job Board—a dedicated platform for security talent and job postings in the payment industry. Next, we delve into Requirement 5, shedding light on anti-malware solutions. We explore the criteria for system components which do not require anti-malware, delve into the specifics of anti-malware implementation, and highlight the periodic evaluations required for maintaining optimal security. Wrapping...

info_outline
PCI Monthly Update: July Insights & Innovations show art PCI Monthly Update: July Insights & Innovations

Cybersecurity Sense

Dive into the latest PCI news in our July PCI Update. This episode covers key PCI developments, an in-depth exploration of Requirement 4, and a helpful QSA Q&A. We kick off this episode by previewing the upcoming PCI Community Meeting in Portland and discuss our hosts' presentation on "Generative AI: Your New Secret Weapon or an Insider Threat?" We also talk about the INFI worksheet and the importance of Continuous Compliance. In the Requirement 4 segment, we focus on strong cryptography, robust security protocols, and the need to secure PAN during transmission over public networks. We...

info_outline
Worried about Ransomware? show art Worried about Ransomware?

Cybersecurity Sense

Do you know the average payout organizations are hit with for every attack? William Parks and Bill Dean discuss a service dedicated to helping your organization (big or small) withstand a ransomware attack. Bill and his team are ready to help you and your organization obtain peace of mind when it comes to these advanced threats.  Questions for Bill? Find him here:

info_outline
Advance Guard Could Save You show art Advance Guard Could Save You

Cybersecurity Sense

LBMC Shareholder Bill Dean and William Parks spend today’s episode discussing Advance Guard, a new service offering from LBMC's Security Technical Team. Learn how Advance Guard may help protect your organization's most valuable assets, save time on compliance audits, and give peace of mind about your current security stance.  Want to see Bill’s “Prescription”? Check out the link below: Questions for Bill? Find him here:

info_outline
 
More Episodes

No matter the industry—government, healthcare, financial, or even smaller, mom-and-pop businesses—each deal with some type of sensitive customer information, and each has decisions to make when it comes to managing risk. Most security and audit frameworks (HIPAA, ISO, PCI, NIST, SOC 2, etc.) have requirements for risk assessment, making them one of the first things auditors or regulators ask for. Many companies are still using spreadsheets when it comes to performing risk assessments, which can be ineffective and insecure. Such a lack of functionality can keep a company from moving beyond assessment and into true risk management.

In this podcast from the Institute of Internal Audit meeting in Knoxville, LBMC Information Security’s Bill Dean and Mark Fulford discuss the importance of risk management, including the effectiveness of risk assessments and how BALLAST can help organizations automate the risk assessment process.

Listen, and discover these key takeaways:

  • Understanding what’s important to your organization when it comes to managing risks
  • Reasons to consider more targeted risk assessments
  • Why you shouldn’t just do gap assessments
  • How to automate the risk assessment process
  • Why not to stop at the assessment phase