<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>PCI DSS Book Series on PCI Resources</title>
		<link>/book/</link>
		<description>Recent content in PCI DSS Book Series on PCI Resources</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<atom:link href="/book/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Summary of changes in the 4.0 edition of the book</title>
				<link>/book/40-changes/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>/book/40-changes/</guid>
				<description>&lt;p&gt;&lt;em&gt;Back to &lt;a href=&#34;/book&#34;&gt;books home&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;summary-of-changes-in-the-40-edition-of-the-book&#34;&gt;Summary of changes in the 4.0 edition of the book&lt;/h3&gt;&#xA;&lt;p&gt;The original 3 volumes were written between fall 2014 and summer 2015 for PCI DSS 3.1; the fourth in 2017 for 3.2. They were only slightly modified based on changes from PCI DSS 3.1 to 3.2 and 3.2.1.&lt;/p&gt;&#xA;&lt;p&gt;This version includes many more changes including:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Terminology (see 1.8.7.1)&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Requirement changes both language and numbering&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;All numbers are from 4.0, but the equivalent 3.2.1 number is present if available, e.g:&#xA;&lt;ul&gt;&#xA;&lt;li&gt;12.5.1, v3#2.4&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Images&lt;/p&gt;</description>
			</item>
			<item>
				<title>Summary of changes in the 4.0.1 edition of the book</title>
				<link>/book/401-changes/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>/book/401-changes/</guid>
				<description>&lt;p&gt;&lt;em&gt;Back to &lt;a href=&#34;/book&#34;&gt;books home&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;summary-of-changes-in-the-401-edition-of-the-book&#34;&gt;Summary of changes in the 4.0.1 edition of the book&lt;/h3&gt;&#xA;&lt;p&gt;The original 3 volumes were written between fall 2014 and summer 2015 for PCI DSS 3.1; the fourth in 2017 for 3.2. They were only slightly modified based on changes from PCI DSS 3.1 to 3.2 and 3.2.1.&#xA;The fifth release for 4.0 in 2022 was as major a change as version 4.0 was to 3.2.1, the &lt;a href=&#34;/book/40-changes/&#34;&gt;summary of changes in the 4.0 edition&lt;/a&gt; is still available.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Table of Content - Volume 1 (PCI DSS 4.0.1 edition)</title>
				<link>/book/volume-1-toc/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>/book/volume-1-toc/</guid>
				<description>&lt;p&gt;&lt;em&gt;Back to &lt;a href=&#34;/book&#34;&gt;books home&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;volume-1---a-business-case-for-the-pci-dss-pci-dss-401-edition&#34;&gt;Volume 1 - A Business Case for the PCI DSS (PCI DSS 4.0.1 edition)&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.1 Volume Introduction&lt;/li&gt;&#xA;&lt;li&gt;1.2 Why PCI DSS?&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.2.1 The value of card information&lt;/li&gt;&#xA;&lt;li&gt;1.2.2 The costs of PCI DSS&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;1.3 How We Got Here - An Oversimplified History of the Payment Card Industry (PCI)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.3.1 From metals to paper&lt;/li&gt;&#xA;&lt;li&gt;1.3.2 Development of the financial industry in the USA&lt;/li&gt;&#xA;&lt;li&gt;1.3.3 The credit card era&lt;/li&gt;&#xA;&lt;li&gt;1.3.4 Credit card and the internet - or the automated fraud era&lt;/li&gt;&#xA;&lt;li&gt;1.3.5 Government Reaction to Accounting Scandals and Industry Reaction&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;1.4 Who should care about the PCI DSS?&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.4.1 The payment card model&lt;/li&gt;&#xA;&lt;li&gt;1.4.2 Anatomy of payment card transactions&lt;/li&gt;&#xA;&lt;li&gt;1.4.3 Clearing and Settlement&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;1.5 So what exactly is PCI DSS?&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.5.1 PCI DSS and the PCI SSC&lt;/li&gt;&#xA;&lt;li&gt;1.5.2 Defining the PCI DSS?&lt;/li&gt;&#xA;&lt;li&gt;1.5.3 PCI DSS at a high-level&lt;/li&gt;&#xA;&lt;li&gt;1.5.4 High-level overview of other PCI standards&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.5.4.1 Issuer Standards&lt;/li&gt;&#xA;&lt;li&gt;1.5.4.2 Software Security Standards&lt;/li&gt;&#xA;&lt;li&gt;1.5.4.3 Device Security Standards&lt;/li&gt;&#xA;&lt;li&gt;1.5.4.4 Payment Device and COTS (Commercial off the Shelf) Devices (aka mobile phones)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;1.6 How should PCI DSS compliance be addressed?&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.6.1 From physical security to basic network security: Fort Knox or the &amp;lsquo;castle&amp;rsquo; metaphor&lt;/li&gt;&#xA;&lt;li&gt;1.6.2 Network complexity and virtualization lead to cloud computing&lt;/li&gt;&#xA;&lt;li&gt;1.6.3 New approaches&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;1.7 Demonstrating PCI DSS compliance&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.7.1 RoC vs SAQ (and AoC)&lt;/li&gt;&#xA;&lt;li&gt;1.7.2 Merchant Compliance&lt;/li&gt;&#xA;&lt;li&gt;1.7.3 Service Provider Compliance&lt;/li&gt;&#xA;&lt;li&gt;1.7.4 Other compliance - issuers, acquirers&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;1.8 Where do we go from here? The evolution of the PCI DSS standard&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.8.1 Early PCI DSS versions: versions 1.0, 1.1, 1.2 and 1.2.1&lt;/li&gt;&#xA;&lt;li&gt;1.8.2 PCI DSS 2.0&lt;/li&gt;&#xA;&lt;li&gt;1.8.3 PCI DSS 3.0 and 3.1&lt;/li&gt;&#xA;&lt;li&gt;1.8.4 PCI DSS Designated Entities Supplemental Validation (DESV)&lt;/li&gt;&#xA;&lt;li&gt;1.8.5 PCI DSS 3.2&lt;/li&gt;&#xA;&lt;li&gt;1.8.6 PCI DSS 3.2.1&lt;/li&gt;&#xA;&lt;li&gt;1.8.7 PCI DSS 4.0 and 4.0.1&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.8.7.1 PCI DSS 4.0 - New terminology (Glossary)&lt;/li&gt;&#xA;&lt;li&gt;1.8.7.2 PCI DSS 4.0 Structural changes&lt;/li&gt;&#xA;&lt;li&gt;1.8.7.3 PCI DSS 4.0 Major Requirement Changes&lt;/li&gt;&#xA;&lt;li&gt;1.8.7.4 PCI DSS 4.0.1&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;1.9 The rise of genAI (summer 2026 status)&lt;/li&gt;&#xA;&lt;li&gt;1.10 Parting thoughts for PCI DSS 4.0.1 version (Summer 2026)&lt;/li&gt;&#xA;&lt;li&gt;End Notes - Volume 1&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>Table of Content - Volume 2 (PCI DSS 4.0.1 edition)</title>
				<link>/book/volume-2-toc/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>/book/volume-2-toc/</guid>
				<description>&lt;p&gt;&lt;em&gt;Back to &lt;a href=&#34;/book&#34;&gt;books home&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;volume-2---pci-dss-scoping-pci-dss-401-edition&#34;&gt;Volume 2 - PCI DSS Scoping (PCI DSS 4.0.1 edition)&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2.1 Volume Terminology and Acronyms&lt;/li&gt;&#xA;&lt;li&gt;2.2 PCI Resources basic diagrams&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2.2.1 PCI Resources Base Network Diagram&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;2.3 Scoping&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2.3.1 It all starts with data&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;2.4 PCI DSS Scoping explained&lt;/li&gt;&#xA;&lt;li&gt;2.5 PCI Resources Simplified PCI DSS Scoping Model and Approach&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2.5.1 Categories Summary&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;2.6 Simplified Approach and Scoping categories&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2.6.1 Simplified Approach Part 1 - CDE (steps 1-3)&lt;/li&gt;&#xA;&lt;li&gt;2.6.2 Simplified Approach Part 2 - Connected systems (steps 4-6)&lt;/li&gt;&#xA;&lt;li&gt;2.6.3 Out-of-scope systems&lt;/li&gt;&#xA;&lt;li&gt;2.6.4 Scope Documentation&lt;/li&gt;&#xA;&lt;li&gt;2.6.5 Comparison to other models&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;2.7 Scope Reduction Methods&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2.7.1 Outsourcing&lt;/li&gt;&#xA;&lt;li&gt;2.7.2 Data Reduction (via PAN Transformations)&lt;/li&gt;&#xA;&lt;li&gt;2.7.3 Segmentation / Isolation&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;2.8 Advanced Scoping&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2.8.1 eCommerce&lt;/li&gt;&#xA;&lt;li&gt;2.8.2 Card Present payments using Mobile payment devices as terminals&lt;/li&gt;&#xA;&lt;li&gt;2.8.3 Virtualization and Cloud&lt;/li&gt;&#xA;&lt;li&gt;2.8.4 Complex Virtualization Cases&lt;/li&gt;&#xA;&lt;li&gt;2.8.5 Scope of Emails and Instant Messaging Solutions&lt;/li&gt;&#xA;&lt;li&gt;2.8.6 Scope using genAI/LLM (summer 2026 status)&lt;/li&gt;&#xA;&lt;li&gt;2.8.7 Non-covered technologies&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;2.9 Sources and References&lt;/li&gt;&#xA;&lt;li&gt;End Notes - Volume 2&lt;/li&gt;&#xA;&lt;li&gt;Appendix 2A - PCI DSS Scope Documentation Guidance for PCI DSS 4.0 .1&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>Table of Content - Volume 3 (PCI DSS 4.0.1 edition)</title>
				<link>/book/volume-3-toc/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>/book/volume-3-toc/</guid>
				<description>&lt;p&gt;&lt;em&gt;Back to &lt;a href=&#34;/book&#34;&gt;books home&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;volume-3---building-a-pci-dss-information-security-program-pci-dss-401-edition&#34;&gt;Volume 3 - Building a PCI DSS Information Security Program (PCI DSS 4.0.1 edition)&lt;/h3&gt;&#xA;&lt;p&gt;Volume 3 - Building a PCI DSS Information Security Program&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.1 Volume Introduction&lt;/li&gt;&#xA;&lt;li&gt;3.2 The High-Level PCI DSS requirements&lt;/li&gt;&#xA;&lt;li&gt;3.3 Building a PCI DSS Information Security Program&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.3.1 Where you come from matters&lt;/li&gt;&#xA;&lt;li&gt;3.3.2 Information Security Programs are meant to address Risks&lt;/li&gt;&#xA;&lt;li&gt;3.3.3 Information Security Frameworks&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;3.4 Considerations for an Information Security Program&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.4.1 Recapping the PCI DSS data elements&lt;/li&gt;&#xA;&lt;li&gt;3.4.2 Data Classification&lt;/li&gt;&#xA;&lt;li&gt;3.4.3 Examples of data classification&lt;/li&gt;&#xA;&lt;li&gt;3.4.4 Governance&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;3.5 The PCI DSS Information Security Program Structure (the head of the program)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.5.1 (Information Security) Policies (Sections 12.1, 12.2, X.1)&lt;/li&gt;&#xA;&lt;li&gt;3.5.2 Responsibilities for the program (Section 12.1)&lt;/li&gt;&#xA;&lt;li&gt;3.5.3 Targeted Risk Assessments (TRA, Section 12.3)&lt;/li&gt;&#xA;&lt;li&gt;3.5.4 PCI DSS Program and Monitoring (Service Provider, Section 12.4)&lt;/li&gt;&#xA;&lt;li&gt;3.5.5 Scope : Documenting usage of card information (Section 12.5)&lt;/li&gt;&#xA;&lt;li&gt;3.5.6 Security awareness (Section 12.6)&lt;/li&gt;&#xA;&lt;li&gt;3.5.7 Human Resource Security (Section 12.7)&lt;/li&gt;&#xA;&lt;li&gt;3.5.8 Managing Third-party service providers (TPSP) (Section 12.8)&lt;/li&gt;&#xA;&lt;li&gt;3.5.10 Incident Response Management (Section 12.10)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;3.6 The body of the program&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.6.1 Objective 1: Build and Maintain a Secure Network and Systems&lt;/li&gt;&#xA;&lt;li&gt;3.6.2 Objective 2: Protect Account Data&lt;/li&gt;&#xA;&lt;li&gt;3.6.3 Objective 3: Maintain a Vulnerability Management Program&lt;/li&gt;&#xA;&lt;li&gt;3.6.4 Objective 4: Implement Strong Access Control Measures&lt;/li&gt;&#xA;&lt;li&gt;3.6.5 Objective 5: Regularly Monitor and Test Networks&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;3.7 Additional Requirements&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.7.1 Requirement Appendix A1:Multi-tenant service provider (previously called shared service provider) requirements&lt;/li&gt;&#xA;&lt;li&gt;3.7.2 Requirement Appendix A2: Secure transmission of CHD from payment devices (cryptography for data in motion)&lt;/li&gt;&#xA;&lt;li&gt;3.7.3 Requirement Appendix A3: Designated Entities Supplemental Validation (DESV)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;3.8 Controls to consider when using, and to protect from, genAI/LLM&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.8.1 Controls when using genAI&lt;/li&gt;&#xA;&lt;li&gt;3.8.2 Use of genAI to supplement controls&lt;/li&gt;&#xA;&lt;li&gt;3.8.3 Impact of genAI and similar tools on the threat landscape&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;3.9 Addressing compliance gaps - prioritization&lt;/li&gt;&#xA;&lt;li&gt;3.10 When you cannot meet the &amp;ldquo;defined approach&amp;rdquo; as is&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.10.1 Compensating Controls - the old way&lt;/li&gt;&#xA;&lt;li&gt;3.10.2 Customized Approach - the new way&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;3.11 Total Cost of Ownership (TCO) and Return-on-Investment (ROI)&lt;/li&gt;&#xA;&lt;li&gt;End Notes - Volume 3&lt;/li&gt;&#xA;&lt;li&gt;Appendix 3A - Network Primer&lt;/li&gt;&#xA;&lt;li&gt;Appendix 3B - A primer on encryption&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>Table of Content - Volume 4 (PCI DSS 4.0.1 edition)</title>
				<link>/book/volume-4-toc/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>/book/volume-4-toc/</guid>
				<description>&lt;p&gt;&lt;em&gt;Back to &lt;a href=&#34;/book&#34;&gt;books home&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;volume-4---hypothetical-case-studies---from-janes-flower-attic-to-janes-flower-emporium-pci-dss-401-edition&#34;&gt;Volume 4 - Hypothetical Case Studies - From Jane&amp;rsquo;s Flower Attic to Jane&amp;rsquo;s Flower Emporium (PCI DSS 4.0.1 edition)&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Volume 4 - Hypothetical Case Studies&lt;/li&gt;&#xA;&lt;li&gt;4.1 Volume Introduction&#xA;&lt;ul&gt;&#xA;&lt;li&gt;4.1.1 Assumptions&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;4.2 Jane&amp;rsquo;s journey - Step 1 - A small side business&#xA;&lt;ul&gt;&#xA;&lt;li&gt;4.2.1 Jane&amp;rsquo;s Flower Attic (JFA) business&lt;/li&gt;&#xA;&lt;li&gt;4.2.2 Applying SAQ-B-IP using a cellular network connection to the payment device&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;4.3 - Step 2 - Jane&amp;rsquo;s Flower Boutique (JFB)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;4.3.1 JFB Network Security Control (NSC, e.g. firewall) standard&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;4.4 Step 3 - Jane&amp;rsquo;s Flower Chain (JFC)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;4.4.1 Network level controls&lt;/li&gt;&#xA;&lt;li&gt;4.4.2 Identification and Authentication controls&lt;/li&gt;&#xA;&lt;li&gt;4.4.3 Physical security controls&lt;/li&gt;&#xA;&lt;li&gt;4.4.4 System level controls&lt;/li&gt;&#xA;&lt;li&gt;4.4.5 Application level controls&lt;/li&gt;&#xA;&lt;li&gt;4.4.6 Logging and Monitoring&lt;/li&gt;&#xA;&lt;li&gt;4.4.7 Testing&lt;/li&gt;&#xA;&lt;li&gt;4.4.8 Governance, Policies, Procedures&lt;/li&gt;&#xA;&lt;li&gt;4.4.9 Incident Response&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;4.5 - Step 4 - Jane&amp;rsquo;s Flower Depot (JFD)&lt;/li&gt;&#xA;&lt;li&gt;4.6 - Step 4 - Jane&amp;rsquo;s Flower Emporium (JFE)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;4.6.1 JFE Organizational Structure&lt;/li&gt;&#xA;&lt;li&gt;4.6.2 Best-practice in information security governance - Information security separate from IT&lt;/li&gt;&#xA;&lt;li&gt;4.6.3 Payment transactions&lt;/li&gt;&#xA;&lt;li&gt;4.6.4 Card present payments in stores and at delivery&lt;/li&gt;&#xA;&lt;li&gt;4.6.5 Customer Service and MOTO transactions&lt;/li&gt;&#xA;&lt;li&gt;4.6.6 eCommerce&lt;/li&gt;&#xA;&lt;li&gt;4.6.7 The Information Security Program (based on ISO 27002)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;End Notes - Volume 4&lt;/li&gt;&#xA;&lt;li&gt;Appendix 4A - JFA Information Security Policy (simplified example)&lt;/li&gt;&#xA;&lt;li&gt;Appendix 4B - JFB NSC (firewall) standard&lt;/li&gt;&#xA;&lt;li&gt;Appendix 4C - JFC Incident Response Plan&lt;/li&gt;&#xA;&lt;li&gt;Appendix 4D - JFD Payment Device Tampering Review Process&lt;/li&gt;&#xA;&lt;li&gt;Appendix 4E - JFE Information Security Policy&lt;/li&gt;&#xA;&lt;li&gt;Appendix 4F - JFE Risk Assessment&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
	</channel>
</rss>
