<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PCI Toolkit &#187; Press</title>
	<atom:link href="http://www.pcitoolkit.com/category/press/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pcitoolkit.com</link>
	<description>Powered by CSRSI®</description>
	<lastBuildDate>Wed, 30 Jun 2010 16:28:10 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>CSRSI Announces Enhancements to the PCI ToolKit® Web Application</title>
		<link>http://www.pcitoolkit.com/2010/04/30/csrsi-announces-enhancements-to-the-pci-toolkit%c2%ae-web-application/</link>
		<comments>http://www.pcitoolkit.com/2010/04/30/csrsi-announces-enhancements-to-the-pci-toolkit%c2%ae-web-application/#comments</comments>
		<pubDate>Fri, 30 Apr 2010 17:17:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Press]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=174</guid>
		<description><![CDATA[CSRSI unveiled a more user-friendly interface for the PCI ToolKit® survey-based system for merchants to complete their required annual Self-Assessment Questionnaire and become PCI compliant as mandated by the PCI Standards Council.  ]]></description>
			<content:encoded><![CDATA[<p>IMMEDIATE RELEASE</p>
<p>Jensen Beach, FL-April 15, 2010- CSRSI, a leading electronics payments consulting firm, proudly announced several new enhancements to their PCI ToolKit® web application at a Client Appreciation Dinner for 60 clients attending the Electronic Transaction Association’s Annual Meeting and Expo in Las Vegas April 14th. The dinner, held at Smith &amp; Wollensky’s restaurant, highlighted a new look and feel and a more user-friendly interface for its survey-based system for merchants to complete their required annual Self-Assessment Questionnaire as mandated by the PCI Standards Council.</p>
<p><a title="PCIToolKit" href="http://www.pcitoolkit.com" target="_blank">The PCI ToolKit®</a> is a broadly used web-based, comprehensive system for merchants processing credit cards to become compliant with the Payment Card Industry’s Data Security Standard (PCI-DSS). Introduced in 2005, the ToolKit also provides an interface to CSRSI’s clients composed of member banks, payment processors and ISOs to administer oversight of merchants’ progress.</p>
<p>Ross Federgreen, one of CSRSI’s founders, in appreciation of the moment, summed up the milestone event: “We continue to listen to our clients’ feedback and incorporate their requests for advancements in our development stages. We’re thrilled to see how many of our long term client/friends were present to show their confidence in and support of the PCI ToolKit®, representing many well-known member banks, processors and ISOs.</p>
<p>About CSRSI</p>
<p>CSRSI provides electronic payment consultation and management. Our areas of focus include PCI, PII (personally identifiable information), risk, liability, compliance, systems selection and vendor selection. Our expertise includes merchant services, ACH, SWIFT, IBAN and all other electronic formats. For more information, visit www.csrsi.com.</p>
<p>For further information, contact: <a href="mailto:jcarroza@csrsi.com">jcarroza@csrsi.com</a>.</p>
<p>Twitter: @pcitoolkit</p>
<p>Twitter: @csrsi</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2010/04/30/csrsi-announces-enhancements-to-the-pci-toolkit%c2%ae-web-application/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Aberdeen report shows firms using PCI-DSS can halve costs</title>
		<link>http://www.pcitoolkit.com/2009/12/31/aberdeen-report-shows-firms-using-pci-dss-can-halve-costs/</link>
		<comments>http://www.pcitoolkit.com/2009/12/31/aberdeen-report-shows-firms-using-pci-dss-can-halve-costs/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 13:01:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Press]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=162</guid>
		<description><![CDATA[Aberdeen report shows firms using PCI-DSS can halve costs]]></description>
			<content:encoded><![CDATA[<p>The Aberdeen group&#8217;s third annual study into Payment Card Industry Data Security Standard (PCI-DSS) issues claims to show that a growing number of companies are saving up to 55% on maintaining their compliance by adopting best practices.</p>
<p>The <a href="http://research.aberdeen.com/index.php/-information-technology/54-business- intelligence/1011-5892">report</a>  &#8211; which is offered free until the end of January &#8211; also says that companies adopting PCI-DSS compliance can save up to 45% on their costs by adopting a best practice strategy.</p>
<p>The study, which is billed as providing year-over-year insights into the progress that affected organizations have made in achieving and sustaining compliance with PCI-DSS <https://www.pcisecuritystandards.org/> , found that adopting a best-in-class approach can halve a company&#8217;s compliance costs.</p>
<p>On top of this, the report notes that best-in-class companies can divert the PCI-DSS compliance savings into other areas, such as sustainable programs and continuous improvement.</p>
<p>According to the research firm, best-in-class companies were found to have reduced their deficiencies related to PCI-DSS compliance by 7.5% on a year-over-year basis, when compared to `laggards.&#8217;</p>
<p>The conclusions of the security analysis show how companies can reduce the scope of their PCI-DSS compliance, as well as `map and adapt&#8217; to better security practices.</p>
<p>One of the most interesting conclusions of the report is the need for managers to assign clear ownership of the PCI-DSS issues and so achieve better PCI-DSS efficiencies.</p>
<p>Source: Infosecurity Magazine</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2009/12/31/aberdeen-report-shows-firms-using-pci-dss-can-halve-costs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The 10 Myths of Payment Credit Card Industry (PCI) Compliance</title>
		<link>http://www.pcitoolkit.com/2009/10/29/the-ten-myths-of-payment-card-industry-pci-compliance/</link>
		<comments>http://www.pcitoolkit.com/2009/10/29/the-ten-myths-of-payment-card-industry-pci-compliance/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 15:28:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Press]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=93</guid>
		<description><![CDATA[Merchants are becoming acutely aware of the mandated requirements of the Payment Card Industry Data Security Standard (PCI DSS). Unfortunately associated with this are many misconceptions or myths. It is important that members of the merchant service community have a detailed understanding of PCI and can assist merchants with the complexities of compliance]]></description>
			<content:encoded><![CDATA[<p>Merchants are becoming acutely aware of the mandated requirements of the Payment Card Industry Data Security Standard (PCI DSS). Unfortunately associated with this are many misconceptions or myths. It is important that members of the merchant service community have a detailed understanding of PCI and can assist merchants with the complexities of compliance.</p>
<p><strong><br />
</strong><br />
<strong>MYTH 1: I DO NOT HAVE TO BE COMPLIANT</strong></p>
<p>This is untrue. Every merchant who in any manner accepts, handles, stores or transmits credit card information must be compliant. This extends to all merchants regardless of the type of credit card environment they are in. There are no exceptions for merchants who are in the card present environment.</p>
<p><strong><br />
</strong></p>
<p><strong>MYTH 2: IF I HAVE PENETRATION SCANS I AM COMPLIANT</strong></p>
<p>This is untrue. Penetration scans or vulnerability scans represent a small fraction of the requirements. Having penetration scans done is important but it is not all that is required. The merchant must complete the 75 questions that make up the annual self-assessment questionnaire (SAQ).</p>
<p><strong><br />
</strong></p>
<p><strong>MYTH 3: FOR THE SAQ I CAN JUST ANSWER YES TO PASS.</strong></p>
<p>This is untrue. You should only answer yes if you both understand the question and have the documented evidence that the answer should be yes. Fabricating yes answers is both inappropriate and opens the merchant to severe penalties including loss of credit card privileges.</p>
<p><strong><br />
</strong></p>
<p><strong>MYTH 4: NO ONE WILL EVER LOOK AT MY ANSWERS TO THE SELF-ASSESSMENT QUESTIONAIRE</strong></p>
<p>This is untrue. As part of the requirements for PCI compliance each merchant must file the SAQ with his or her acquirer. If a merchant is compromised, risk rated, randomly audited or for other reasons the response to the SAQ will be examined.</p>
<p><strong><br />
</strong></p>
<p><strong>MYTH 5: ALL I NEED TO DO IS TO GET MY PENETRATION SCAN COMPLETED.</strong></p>
<p>This is untrue.  It is vitally important to examine the results of the penetration scans and note findings. Each abnormal finding must be addressed regardless of which of the four levels from informational to severe is listed. Severe findings must be remediate within 30 days.</p>
<p><strong><br />
</strong></p>
<p><strong>MYTH 6: IF MY SOFTWARE OR TERMINAL IS COMPLIANT THAN I AM COMPLIANT.</strong></p>
<p>This is untrue. Every merchant to answer the questions of the SAQ correctly and honestly must have written policies, procedures and auditable logs. There are significant physical security requirements that are required as well which must be met. Compliant software and terminals arecritical but not the entire answer.</p>
<p><strong><br />
</strong></p>
<p><strong>MYTH 7: IT CAN’T HAPPEN TO ME.</strong></p>
<p>This is untrue security breaches happen everywhere and can happen to anyone at anytime.</p>
<p><strong><br />
</strong></p>
<p><strong>MYTH 8: ALL SECURITY BREACHES OCCUR FROM EXTERNAL SOURCES.</strong></p>
<p>This is untrue over 90% of security breaches occur because of employees are others with internal access to the merchant.</p>
<p><strong><br />
</strong></p>
<p><strong>MYTH 9: MY PROCESSOR IS RESPONSIBLE FOR THE FINES SO WHY SHOULD I CARE.</strong></p>
<p>This is untrue. The merchant is ultimately responsible for all financial fines and penalties. This can be up to $25,000 per month per event.</p>
<p><strong><br />
</strong></p>
<p><strong>MYTH 10: I CAN DO THE SAQ MYSELF</strong></p>
<p>This is true but no one should. The 75 questions on the SAQ are complicated and complex to answer them requires a detailed understanding of the meaning and intent of each of the questions.</p>
<p><strong><br />
</strong></p>
<p>With the above said it is incumbent for the MLS and or ISO to have a detailed understanding of PCI. The fact needs to be strongly emphasized to each merchant that they must comply with the PCI. Failure to do this can lead to civil penalties, criminal prosecution and loss of credit card accepting privileges.</p>
<p><strong><br />
</strong></p>
<p>The payment brands have spent considerable sums attempting to educate the merchant population. A number of resources are available to assist you in helping the merchant achieve compliance. The Green Sheet has published a number of articles addressing these issues. In addition each of the payment brands have information on their web sites defining the requirements and the various categories of merchants.</p>
<p><strong><br />
</strong></p>
<p>We strongly recommend that each merchant obtain qualified assistance in achieving PCI DSS compliance. Knowledge of PCI and what it really takes to be compliant will help you the ISO or MLS maintain, retain and obtain merchants.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2009/10/29/the-ten-myths-of-payment-card-industry-pci-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
