search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Blue outlined 3D text saying 'PCI 4.0' with stacked line effect on a light gray background.
PCI 4.0 Summary of Changes
PCI Trends

PCI 4.0 summary of changes including new requirements that have been added to the standard.

Stylized numbers 1 to 5 in blue shades above diagonal light blue lines on a white background.
What To Include In An Incident Response Plan
Forensics

Creating an incident response plan can seem overwhelming. To simplify the process, develop your incident response plan in smaller, more manageable procedures.

Illustration of secure online shopping with a lock, shopping cart, credit card, and checkmark icons.
How to Test Your Incident Response Plan
Forensics

How to test your incident response plan and conduct tabletop exercises.

Small blue shop with large window and door under striped awning and sign reading SHOP.
Scoping for PCI Compliance: What You Need To Know
PCI Audit

Scoping is determining what systems are covered or need to be assessed or included as part of your PCI compliance.

Text 'Auditor Tips PCI DSS' on a dark geometric patterned background with a blue underline.
Auditor Tips: Requirement 10: Audit Logs and Log Monitoring
PCI Audit

It’s critical that you configure the log monitoring solution correctly so that the appropriate directories, files, security controls, and events are being monitored.

Text reading Auditor Tips PCI DSS on a dark geometric patterned background.
Auditor Tips: Requirement 11: Testing Security
Penetration Testing

If your organization is required to be PCI compliant, don’t procrastinate beginning the penetration test process.

Text reading Auditor Tips PCI DSS on a dark geometric background with a blue underline.
Auditor Tips: Requirement 12: PCI Compliance Basics
Risk Assessment

A risk assessment can be the most important part of your overall security and compliance program, since it helps you identify systems, third parties, business processes, and people that are in scope for PCI compliance.

Text 'Auditor Tips PCI DSS' in white on a dark geometric patterned background.
Auditor Tips: Requirement 9: Improve Your Physical Security
PCI Audit

Once you know what systems you need to protect, put controls in place that can log and restrict access to them.

Text reading Auditor Tips PCI DSS in bold white font on a dark geometric background.
Auditor Tips: Requirement 8: Use Unique ID Credentials
PCI Audit

Requirement 8 is all about using unique ID credentials.

Auditor Tips PCI DSS
Auditor Tips: Requirement 5: Implement And Update Your Anti-Malware
Pulse

PCI DSS requires anti-malware software to be installed on all systems that are commonly affected by malware (e.g., Windows).

Text 'Auditor Tips PCI DSS' on dark background with geometric pattern and blue underline.
Auditor Tips: Requirement 7: Restrict Access
PCI Audit

Cardholder data and card systems should only be accessible to those that need that information to do their jobs. Once you’ve implemented access privileges, make sure to document it.

Text reading Auditor Tips PCI DSS on dark textured background with a blue underline.
Auditor Tips: Requirement 6: System Updating And Software Development
PCI Audit

System administrators have the responsibility to ensure that all system components (e.g., servers, firewalls, routers, workstations) and software are updated with critical security patches within 30 days of public release.

Text reading Auditor Tips PCI DSS on a dark geometric background with a small blue bar.
Auditor Tips: Requirement 4: Sending Data Over Open And Public Networks
PCI

Know exactly where CHD is coming from and being sent to, inside and outside of your organization.

Text reading Auditor Tips PCI DSS on a dark geometric background with blue underline.
Auditor Tips: Requirement 3: Protect Cardholder Data
PCI

It is important to know what data you actually store, process, and/or transmit.

Text reading Auditor Tips PCI DSS on a dark geometric patterned background with a blue underline.
Auditor Tips: PCI DSS Responsibilities and Challenges
PCI

As you implement your cybersecurity program, make sure you understand why a security control is required so you can structure tools and processes around the protection each control offers.

Text reading Auditor Tips PCI DSS on a dark geometric patterned background with a blue underline.
Auditor Tips: Requirement 2: System Configuration
PCI

You are required to use industry-accepted configuration and hardening standards when setting up systems that are part of your PCI scope.

Stone castle gate with two towers symbolizing firewalls in PCI Requirement 1 security concept.
Requirement 1: Establish Secure Firewall Rules
PCI

Make sure to choose firewalls that support the necessary configuration options to protect critical systems and provide segmentation between the CDE and other internal and external networks specific to your organization.

Text reading Auditor Tips PCI DSS on a dark geometric patterned background with a blue underline.
Auditor Tips: PCI DSS Scope
PCI Audit

To discover your PCI scope and what must be included for yourPCI compliance, you need to identify anything that processes, stores, or transmits cardholder data, and then evaluate what people and systems are communicating with your systems.

3D blue outlined text reading PC 4.0 with layered line effects on light gray background.
Performing an SAQ-B Version 4.0 Self-Assessment
PCI Trends

The SAQ B is designed for merchant environments where all cardholder data is processed using standalone Point-of-Interaction (POI) terminals connected via an analog phone line.

Blue outlined 3D text reading 'PCI 4.0' on a light gray background with scattered white shapes.
Performing an SAQ B-IP version 4.0 Self-Assessment
PCI Trends

The Self-Assessment Questionnaire (SAQ) B-IP is intended for payment channels where cardholder data is processed using IP-connected PTS-approved point-of-interaction terminals.

Medical worker working at a computer with blue stripes behind.
5 Steps to Secure Your Healthcare Organization
HIPAA

Securing your healthcare organization should be a priority. Healthcare organizations are especially vulnerable to attacks because they cannot afford to be shut down.

Medical professional with stethoscope standing at a computer workstation focused on the screen.
Everything You Need to Know About How to Manage PHI
HIPAA

Fully understanding all the PHI you have, where it is stored, what processes touch it, and how it is used in your organization is critical to enabling a business to properly manage PHI.

Medical professional in scrubs and glasses using a computer on a mobile workstation.
HIPAA Compliance Best Practices
HIPAA

With over 20 years in the industry, we have found that these HIPAA compliance best practices are most helpful in securing your organization.

Laptop screen filled with binary code and a magnifying glass highlighting part of the code.
2023 Forensic Predictions
Forensics

In 2023, we've got three predictions of cyber attacks that we think will be the most prevalent this year.