The wording ... having received as a customer, it feels like they try and slip the number "1.9 million" past us like a side issue.
This is maybe the most comprehensive breach I've seen.
"hackmd is now SOC 2 compliant"
what's next, "gist proudly becomes ISO-14001"?
"towards a PCI-DSS notepad"?
"hackmd is now SOC 2 compliant"
what's next, "gist proudly becomes ISO-14001"?
"towards a PCI-DSS notepad"?
In Australia, PCI DSS is contractual, not law. But the Privacy Act (APP 11) still requires reasonable security, and a card-data leak can be a notifiable breach.
In Australia, PCI DSS is contractual, not law. But the Privacy Act (APP 11) still requires reasonable security, and a card-data leak can be a notifiable breach.
Stripe is used for a lot of actual payment systems.
Websites used to play fast and loose with CC info, that is why we now have PCI-DSS.
Stripe is used for a lot of actual payment systems.
Websites used to play fast and loose with CC info, that is why we now have PCI-DSS.
PCI DSS is designed to protect payment account data, but security teams should not look at the standard only as a checklist of individual requirements.
sisa.ai/resource/cyb...
PCI DSS is designed to protect payment account data, but security teams should not look at the standard only as a checklist of individual requirements.
sisa.ai/resource/cyb...
Toho zobáka na fotce si nevšímejte, kde tomu je konec 🙂
Toho zobáka na fotce si nevšímejte, kde tomu je konec 🙂
This violates so many DOD/HIPAA/PCI DSS IT security and credibility practices that are in place today. This makes Crowdstrike's issue look like a splinter next to a nuke crater. This needs to be documented for evidence and analyzed, if we ever get a chance.
This violates so many DOD/HIPAA/PCI DSS IT security and credibility practices that are in place today. This makes Crowdstrike's issue look like a splinter next to a nuke crater. This needs to be documented for evidence and analyzed, if we ever get a chance.
#compliance #cloud-security #security #monitoring
#compliance #cloud-security #security #monitoring
...but yeah, "experience with PCI-DSS a plus"
...but yeah, "experience with PCI-DSS a plus"
Ja, startet witzig, wird aber auch n bisgen #Brandroden. Ist ja klar, nech?
Ja, startet witzig, wird aber auch n bisgen #Brandroden. Ist ja klar, nech?
(20+ years in e-commerce as a software engineer)
(20+ years in e-commerce as a software engineer)
⭐ 1,387 (+50)
🗒 Python
CISO Assistant is a one-stop-shop for GRC, covering Risk, AppSec and Audit Management and supporting +70 frameworks worldwide with auto-mapping: NIST CSF, ISO 27001, SOC2, CIS, PCI DSS, NIS2, CMMC, PSPF, GDPR, HIPAA, Essential...
⭐ 1,387 (+50)
🗒 Python
CISO Assistant is a one-stop-shop for GRC, covering Risk, AppSec and Audit Management and supporting +70 frameworks worldwide with auto-mapping: NIST CSF, ISO 27001, SOC2, CIS, PCI DSS, NIS2, CMMC, PSPF, GDPR, HIPAA, Essential...