<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>PCI Resources</title>
		<link>/</link>
		<description>Recent content on PCI Resources</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<lastBuildDate>Mon, 05 Sep 2022 00:00:00 +0000</lastBuildDate>
		
			<atom:link href="/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>2022 PCICM Calendar Files</title>
				<link>/posts/2022-pcicm-calendar-files/</link>
				<pubDate>Mon, 05 Sep 2022 00:00:00 +0000</pubDate>
				<guid>/posts/2022-pcicm-calendar-files/</guid>
				<description>&lt;p&gt;I&amp;rsquo;ll be attending both the 2022 PCI Community Meetings (often abbreviated PCICM) in Toronto and Milan.&lt;/p&gt;&#xA;&lt;p&gt;While the schedule is provided on each individual site and within the useful companion app, I wanted something to put in my calendar.&lt;/p&gt;&#xA;&lt;p&gt;So I wrote a script (adapted actually, I had created it for last year&amp;rsquo;s online meeting) and created 2 separate iCalendar (.ics) files which can be imported into regular calendar programs such as Outlook and Google Calendar.&lt;/p&gt;</description>
			</item>
			<item>
				<title>GoSec 2019 Presentation</title>
				<link>/posts/gosec-2019-presentation/</link>
				<pubDate>Thu, 05 Sep 2019 00:00:00 +0000</pubDate>
				<guid>/posts/gosec-2019-presentation/</guid>
				<description>&lt;p&gt;On Thursday August 29th, 2019, I gave a presentation at the&#xA;&lt;a href=&#34;https://www.gosec.net/&#34;&gt;GoSec 2019 conference&lt;/a&gt; in Montreal, Canada.&lt;/p&gt;&#xA;&lt;p&gt;As promised to the attendees, here is a&#xA;&lt;a href=&#34;/s/GoSec2019-Desharnais-FutureProofingYourPCIDSSprogram-final.pdf&#34;&gt;PDF of the slides of the presentation&lt;/a&gt; entitled &amp;ldquo;Future proofing your PCI DSS program&amp;rdquo;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Updated Scoping Model (version 1.2.1) and French/Spanish Versions</title>
				<link>/posts/updated-scoping-model-version-121-and-frenchspanish-versions/</link>
				<pubDate>Tue, 31 Jul 2018 00:00:00 +0000</pubDate>
				<guid>/posts/updated-scoping-model-version-121-and-frenchspanish-versions/</guid>
				<description>&lt;p&gt;I&amp;rsquo;m happy to announce the release of the update for the&#xA;&lt;a href=&#34;/pci-dss-scoping-model-and-approach&#34;&gt;PCI Resources Scoping Model and Approach to version 1.2.1&lt;/a&gt;. The model is still available under a creative commons license (CC-BY-SA).&lt;/p&gt;&#xA;&lt;p&gt;The changes are minor and mainly reflect reference changes for PCI DSS 3.2.1 which came out late May 2018 (and mainly reflected the fact that announced date related changes are now mandatory).&lt;/p&gt;&#xA;&lt;p&gt;With this version, I&amp;rsquo;m adding the French and Spanish versions of the model from the upcoming translations of the book which should be available late summer or early fall 2018. Again, the model is available in PDF versions in both US letter and A4 (for my European friends).&lt;/p&gt;</description>
			</item>
			<item>
				<title>Updated Scoping Model (version 1.2)</title>
				<link>/posts/updated-scoping-model-version-12/</link>
				<pubDate>Tue, 10 Apr 2018 00:00:00 +0000</pubDate>
				<guid>/posts/updated-scoping-model-version-12/</guid>
				<description>&lt;p&gt;I&amp;rsquo;m happy to announce the release of the update for the&#xA;&lt;a href=&#34;/pci-dss-scoping-model-and-approach&#34;&gt;PCI Resources Scoping Model and Approach to version 1.2&lt;/a&gt;. The model is still available under a creative commons license (CC-BY-SA).&lt;/p&gt;&#xA;&lt;p&gt;The update is extracted from the most recent version of volume 2 of the book series (paperback called &amp;quot;&#xA;&lt;a href=&#34;/book/&#34;&gt;PCI DSS made easy&lt;/a&gt;&amp;quot;, or individual digital volumes) released in December 2017. The major changes were addressing the PCI SSC (PCI council) supplement called &amp;ldquo;Guidance for PCI DSS Scoping and Network Segmentation&amp;rdquo;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Announcing the 2017 revision of the PCI Resources books on PCI DSS (including PCI DSS made easy)</title>
				<link>/posts/pci-resources-books-pcidss-2017-revision-announcement/</link>
				<pubDate>Wed, 17 Jan 2018 00:00:00 +0000</pubDate>
				<guid>/posts/pci-resources-books-pcidss-2017-revision-announcement/</guid>
				<description>&lt;p&gt;Late December 2017, the updated versions of the of the PCI Resources book series on PCI DSS were released (links at the end of this post). I received the first paperback copies in early January 2018, and other than tweaks to the cover page for a design issue (weird things can happen when you go from 312 to 458 pages), the book is unchanged from its December 2017 release. The physical book has a new ISBN number, while digital editions kept the same one.&lt;/p&gt;</description>
			</item>
			<item>
				<title>BSides Calgary 2017 Presentation</title>
				<link>/posts/bsides-calgary-2017-netflow/</link>
				<pubDate>Sun, 22 Oct 2017 00:00:00 +0000</pubDate>
				<guid>/posts/bsides-calgary-2017-netflow/</guid>
				<description>&lt;p&gt;I just had the pleasure of presenting at BSides Calgary on the topic of &amp;quot;&#xA;Using NetFlow &amp;amp; Open Source tools for Network Behavioral Analysis&amp;quot;. Thanks to the event organizers and volunteers for a great event!&lt;/p&gt;&#xA;&lt;p&gt;While I await a link to the recorded presentation on Youtube, I want to publish as promised the&#xA;&lt;a href=&#34;/s/BSides-Calgary-Netflow-20171022.pdf&#34;&gt;PDF of the slides&lt;/a&gt;, a&#xA;&lt;a href=&#34;/s/20161019-code.zip&#34;&gt;ZIP of the source code&lt;/a&gt;, and a&#xA;&lt;a href=&#34;/s/BSides-Calgary-Netflow-Installation.pdf&#34;&gt;PDF of the demo installation instructions&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Announcing the release of Volume 4</title>
				<link>/posts/announcingvolume4/</link>
				<pubDate>Fri, 14 Jul 2017 00:00:00 +0000</pubDate>
				<guid>/posts/announcingvolume4/</guid>
				<description>&lt;p&gt;I&amp;rsquo;m happy to announce the release of PCI Resources volume 4 in my series on PCI DSS, entitled &amp;ldquo;Hypothetical Case Studies&amp;rdquo;, available now in the&#xA;&lt;a href=&#34;https://www.amazon.com/dp/B073WRTJNL&#34;&gt;Amazon kindle store&lt;/a&gt; (and hopefully in the next few hours in the iBooks store).&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;/s/cover-vol4-32.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;!--&#xA;![](https://images.squarespace-cdn.com/content/v1/55934274e4b0d71f69d61a3c/1500039070125-B7ZFXIPL42ELL20SARCY/image-asset.png)&#xA;--&gt;&#xA;&lt;p&gt;You may notice the design change&amp;hellip; This will roll out slowly to all volumes and physical book (which will include volume 4 in its next release). So expect updates to the full series this fall (with major revisions to all volumes), and even including French and Spanish translations of all of the volumes in all formats (kindle, ibooks and paper).&lt;/p&gt;</description>
			</item>
			<item>
				<title>December 2016 PCI council scoping guidance vs PCI Resources model</title>
				<link>/posts/december-2016-pci-council-scoping-guidance-vs-pci-resources-model/</link>
				<pubDate>Mon, 16 Jan 2017 00:00:00 +0000</pubDate>
				<guid>/posts/december-2016-pci-council-scoping-guidance-vs-pci-resources-model/</guid>
				<description>&lt;p&gt;The PCI council (PCI SSC) finally released its promised&#xA;&lt;a href=&#34;https://www.pcisecuritystandards.org/documents/Guidance-PCI-DSS-Scoping-and-Segmentation_v1.pdf&#34;&gt;guidance on scoping and network segmentation&lt;/a&gt; on December 9, 2016 (and I think they did a good job). As with all other information supplements they produce, this guidance is strong recommendation but leaves space for interpretation. Your assessor still (QSA,  ISA, or other such as yours truly) has ultimate say in these matters;  he or she is also receiving more guidance from the PCI council. The PCI Guru has covered this with&#xA;&lt;a href=&#34;https://pciguru.wordpress.com/2016/12/10/the-council-releases-draft-scope-and-network-segmentation-information-supplement/&#34;&gt;initial opinions&lt;/a&gt; and through answers in a&#xA;&lt;a href=&#34;https://pciguru.wordpress.com/2016/12/15/the-council-speaks-on-a-number-of-topics/&#34;&gt;webinar&lt;/a&gt; from the council (both posts are recommended reading).&lt;/p&gt;</description>
			</item>
			<item>
				<title>Changes between PCI DSS 3.1 and 3.2</title>
				<link>/posts/changes-between-pci-dss-31-and-32/</link>
				<pubDate>Mon, 14 Nov 2016 00:00:00 +0000</pubDate>
				<guid>/posts/changes-between-pci-dss-31-and-32/</guid>
				<description>&lt;p&gt;This post was initially published on LinkedIn on October 13, 2016 at&#xA;&lt;a href=&#34;https://www.linkedin.com/pulse/changes-between-pci-dss-31-32-yves-desharnais-mba-cissp-pcip?trk=prof-post&#34;&gt;https://www.linkedin.com/pulse/changes-between-pci-dss-31-32-yves-desharnais-mba-cissp-pcip?trk=prof-post&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;This text is adapted from section 1.8.5 of my book series on PCI DSS. (&#xA;&lt;a href=&#34;/book/&#34;&gt;http://www.pciresources.com/book/&lt;/a&gt;) and supplemented with information from the 2016 North American PCI Community meetings (PCICM) which I just attended a couple of weeks ago.&#xA;As a reminder PCI DSS 3.2 will become the active standard as of November 1, 2016, although new requirements will only become mandatory on February 1, 2018. PCI DSS 3.1 can only be used for assessments ending by October 31, 2016.&lt;/p&gt;</description>
			</item>
			<item>
				<title>A better PCI DSS scoping model? Or the problems with the OPST.</title>
				<link>/posts/a-better-pci-dss-scoping-model-or-the-problems-with-the-opst/</link>
				<pubDate>Mon, 07 Mar 2016 00:00:00 +0000</pubDate>
				<guid>/posts/a-better-pci-dss-scoping-model-or-the-problems-with-the-opst/</guid>
				<description>&lt;p&gt;I have seen and heard about many ways of classifying systems for PCI DSS or expressing how to go about scoping. The most formal method I have found described out there is in the Open PCI Scoping Toolkit (OPST, &lt;a href=&#34;http://itrevolution.com/pci-scoping-toolkit/&#34;&gt;http://itrevolution.com/pci-scoping-toolkit/&lt;/a&gt;) (which is not endorsed or approved by the PCI SSC). It was released in 2012, though I only learned of it in 2014. While I agree with the general approach to classifying systems, I have disagreements on the categories defined in the OPST. The lack of a model that I felt addressed PCI DSS appropriately is one of the reasons I dedicated a complete&#xA;&lt;a href=&#34;/book/volume-2-toc&#34;&gt;volume&lt;/a&gt; to scoping. I’ve decided to open the model under a Creative Commons licence (&#xA;&lt;a href=&#34;https://creativecommons.org/licenses/by-sa/3.0/&#34;&gt;CC BY-SA&lt;/a&gt;) for free to everyone in the hopes that we can all improve scoping and thus better manage our risks. The model is not endorsed or approved by the PCI SSC, though they are aware of it (and the PCI SSC, or PCI Council, has promised scoping guidance for 2016). The model can be found here: &lt;a href=&#34;http://www.pciresources.com/pci-dss-scoping-model-and-approach/&#34;&gt;http://www.pciresources.com/pci-dss-scoping-model-and-approach/&lt;/a&gt; (a PDF version is also available).&lt;/p&gt;</description>
			</item>
			<item>
				<title>PCI Resources volumes are available on the Apple iBook store as well as the Amazon Kindle store</title>
				<link>/posts/pci-resources-volumes-are-available-on-the-apple-ibook-store-as-well-as-the-amazon-kindle-store/</link>
				<pubDate>Mon, 07 Mar 2016 00:00:00 +0000</pubDate>
				<guid>/posts/pci-resources-volumes-are-available-on-the-apple-ibook-store-as-well-as-the-amazon-kindle-store/</guid>
				<description>&lt;p&gt;This post is just a summary of changes that have occured but that I&amp;rsquo;ve not yet blogged about.&lt;/p&gt;&#xA;&lt;p&gt;Volumes 1 and 2 were released on the&#xA;&lt;a href=&#34;https://www.amazon.com/Yves-B.-Desharnais/e/B012KZCNTI&#34;&gt;Amazon Kindle store&lt;/a&gt; in July 2015.&#xA;The&#xA;&lt;a href=&#34;/pci-dss-scoping-model-and-approach&#34;&gt;PCI Resources Scoping Model and Approach&lt;/a&gt;, derived from volume 2 and published under a Creative Common license at the same time.&#xA;Volume 3 was released on the Amazon Kindle store in September 2015.&lt;/p&gt;&#xA;&lt;p&gt;All 3 volumes were updated in January 2016 to reflect the&#xA;&lt;a href=&#34;https://listings.pcisecuritystandards.org/pdfs/15_12_18_SSL_Webinar_Press_Release_FINAL.pdf&#34;&gt;SSL/TLS changes published by the PCI SSC in December 2015&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Welcome to PCI Resources</title>
				<link>/posts/welcome-to-pci-resources/</link>
				<pubDate>Tue, 28 Jul 2015 00:00:00 +0000</pubDate>
				<guid>/posts/welcome-to-pci-resources/</guid>
				<description>&lt;p&gt;After many long hours over the last year, I am happy to announce the release of my first two volumes on PCI DSS compliance, the information security standard that covers credit card protection.&#xA;&lt;a href=&#34;https://www.amazon.com/Yves-B.-Desharnais/e/B012KZCNTI&#34;&gt;Volumes 1 and 2 are available on the Kindle store now&lt;/a&gt;, and I hope to have volume 3 out in September 2015.&lt;/p&gt;&#xA;&lt;p&gt;Volume 1, A business case for the PCI DSS, explains why the PCI DSS standard matters, how it works, how we got here, and where it may be heading. Volume 2, PCI DSS Scoping, explains what (and why) people, processes and technologies must be subjected to PCI DSS controls. Volume 3 will cover how to build an information security program that takes PCI DSS into consideration.&lt;/p&gt;</description>
			</item>
			<item>
				<title>PCI DSS Overview</title>
				<link>/pci-dss-overview/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>/pci-dss-overview/</guid>
				<description>&lt;ul&gt;&#xA;&lt;li&gt;This section is adapted from the &lt;a href=&#34;/book&#34;&gt;books&lt;/a&gt;*&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The goal of information security should never be to block anything outright, but only to enable users to perform their legitimate business tasks in a secure fashion.&lt;/p&gt;&#xA;&lt;p&gt;The goal of PCI DSS is to protect cardholder data from theft or unauthorized disclosure. This is our gold standard, the lens through which we will look at the PCI DSS requirements. And while the goal is to protect data, it is accomplished through measures on people, processes and technologies.&lt;/p&gt;</description>
			</item>
			<item>
				<title>PCI DSS Scoping Model and Approach</title>
				<link>/scoping-model/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>/scoping-model/</guid>
				<description>&lt;p&gt;The PCI Resources Scoping Model and Approach is available for free under a &lt;a href=&#34;https://creativecommons.org/licenses/by-sa/3.0/&#34;&gt;Creative Commons CC BY-SA&lt;/a&gt; license.&#xA;This model is derived from &lt;a href=&#34;/book/volume-2-toc/&#34;&gt;Volume 2&lt;/a&gt; of the book series and is at version 2.0 in English updated for PCI DSS 4.0.1.&#xA;The guidance on PCI DSS scope documentation was added to this version and is also available below.&lt;/p&gt;&#xA;&lt;p&gt;Other languages are still at the older version 1.2.1 (2018) and will be updated in fall 2026.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Summary of changes in the 4.0 edition of the book</title>
				<link>/book/40-changes/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>/book/40-changes/</guid>
				<description>&lt;p&gt;&lt;em&gt;Back to &lt;a href=&#34;/book&#34;&gt;books home&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;summary-of-changes-in-the-40-edition-of-the-book&#34;&gt;Summary of changes in the 4.0 edition of the book&lt;/h3&gt;&#xA;&lt;p&gt;The original 3 volumes were written between fall 2014 and summer 2015 for PCI DSS 3.1; the fourth in 2017 for 3.2. They were only slightly modified based on changes from PCI DSS 3.1 to 3.2 and 3.2.1.&lt;/p&gt;&#xA;&lt;p&gt;This version includes many more changes including:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Terminology (see 1.8.7.1)&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Requirement changes both language and numbering&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;All numbers are from 4.0, but the equivalent 3.2.1 number is present if available, e.g:&#xA;&lt;ul&gt;&#xA;&lt;li&gt;12.5.1, v3#2.4&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Images&lt;/p&gt;</description>
			</item>
			<item>
				<title>Summary of changes in the 4.0.1 edition of the book</title>
				<link>/book/401-changes/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>/book/401-changes/</guid>
				<description>&lt;p&gt;&lt;em&gt;Back to &lt;a href=&#34;/book&#34;&gt;books home&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;summary-of-changes-in-the-401-edition-of-the-book&#34;&gt;Summary of changes in the 4.0.1 edition of the book&lt;/h3&gt;&#xA;&lt;p&gt;The original 3 volumes were written between fall 2014 and summer 2015 for PCI DSS 3.1; the fourth in 2017 for 3.2. They were only slightly modified based on changes from PCI DSS 3.1 to 3.2 and 3.2.1.&#xA;The fifth release for 4.0 in 2022 was as major a change as version 4.0 was to 3.2.1, the &lt;a href=&#34;/book/40-changes/&#34;&gt;summary of changes in the 4.0 edition&lt;/a&gt; is still available.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Table of Content - Volume 1 (PCI DSS 4.0.1 edition)</title>
				<link>/book/volume-1-toc/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>/book/volume-1-toc/</guid>
				<description>&lt;p&gt;&lt;em&gt;Back to &lt;a href=&#34;/book&#34;&gt;books home&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;volume-1---a-business-case-for-the-pci-dss-pci-dss-401-edition&#34;&gt;Volume 1 - A Business Case for the PCI DSS (PCI DSS 4.0.1 edition)&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.1 Volume Introduction&lt;/li&gt;&#xA;&lt;li&gt;1.2 Why PCI DSS?&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.2.1 The value of card information&lt;/li&gt;&#xA;&lt;li&gt;1.2.2 The costs of PCI DSS&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;1.3 How We Got Here - An Oversimplified History of the Payment Card Industry (PCI)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.3.1 From metals to paper&lt;/li&gt;&#xA;&lt;li&gt;1.3.2 Development of the financial industry in the USA&lt;/li&gt;&#xA;&lt;li&gt;1.3.3 The credit card era&lt;/li&gt;&#xA;&lt;li&gt;1.3.4 Credit card and the internet - or the automated fraud era&lt;/li&gt;&#xA;&lt;li&gt;1.3.5 Government Reaction to Accounting Scandals and Industry Reaction&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;1.4 Who should care about the PCI DSS?&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.4.1 The payment card model&lt;/li&gt;&#xA;&lt;li&gt;1.4.2 Anatomy of payment card transactions&lt;/li&gt;&#xA;&lt;li&gt;1.4.3 Clearing and Settlement&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;1.5 So what exactly is PCI DSS?&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.5.1 PCI DSS and the PCI SSC&lt;/li&gt;&#xA;&lt;li&gt;1.5.2 Defining the PCI DSS?&lt;/li&gt;&#xA;&lt;li&gt;1.5.3 PCI DSS at a high-level&lt;/li&gt;&#xA;&lt;li&gt;1.5.4 High-level overview of other PCI standards&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.5.4.1 Issuer Standards&lt;/li&gt;&#xA;&lt;li&gt;1.5.4.2 Software Security Standards&lt;/li&gt;&#xA;&lt;li&gt;1.5.4.3 Device Security Standards&lt;/li&gt;&#xA;&lt;li&gt;1.5.4.4 Payment Device and COTS (Commercial off the Shelf) Devices (aka mobile phones)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;1.6 How should PCI DSS compliance be addressed?&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.6.1 From physical security to basic network security: Fort Knox or the &amp;lsquo;castle&amp;rsquo; metaphor&lt;/li&gt;&#xA;&lt;li&gt;1.6.2 Network complexity and virtualization lead to cloud computing&lt;/li&gt;&#xA;&lt;li&gt;1.6.3 New approaches&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;1.7 Demonstrating PCI DSS compliance&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.7.1 RoC vs SAQ (and AoC)&lt;/li&gt;&#xA;&lt;li&gt;1.7.2 Merchant Compliance&lt;/li&gt;&#xA;&lt;li&gt;1.7.3 Service Provider Compliance&lt;/li&gt;&#xA;&lt;li&gt;1.7.4 Other compliance - issuers, acquirers&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;1.8 Where do we go from here? The evolution of the PCI DSS standard&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.8.1 Early PCI DSS versions: versions 1.0, 1.1, 1.2 and 1.2.1&lt;/li&gt;&#xA;&lt;li&gt;1.8.2 PCI DSS 2.0&lt;/li&gt;&#xA;&lt;li&gt;1.8.3 PCI DSS 3.0 and 3.1&lt;/li&gt;&#xA;&lt;li&gt;1.8.4 PCI DSS Designated Entities Supplemental Validation (DESV)&lt;/li&gt;&#xA;&lt;li&gt;1.8.5 PCI DSS 3.2&lt;/li&gt;&#xA;&lt;li&gt;1.8.6 PCI DSS 3.2.1&lt;/li&gt;&#xA;&lt;li&gt;1.8.7 PCI DSS 4.0 and 4.0.1&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1.8.7.1 PCI DSS 4.0 - New terminology (Glossary)&lt;/li&gt;&#xA;&lt;li&gt;1.8.7.2 PCI DSS 4.0 Structural changes&lt;/li&gt;&#xA;&lt;li&gt;1.8.7.3 PCI DSS 4.0 Major Requirement Changes&lt;/li&gt;&#xA;&lt;li&gt;1.8.7.4 PCI DSS 4.0.1&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;1.9 The rise of genAI (summer 2026 status)&lt;/li&gt;&#xA;&lt;li&gt;1.10 Parting thoughts for PCI DSS 4.0.1 version (Summer 2026)&lt;/li&gt;&#xA;&lt;li&gt;End Notes - Volume 1&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>Table of Content - Volume 2 (PCI DSS 4.0.1 edition)</title>
				<link>/book/volume-2-toc/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>/book/volume-2-toc/</guid>
				<description>&lt;p&gt;&lt;em&gt;Back to &lt;a href=&#34;/book&#34;&gt;books home&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;volume-2---pci-dss-scoping-pci-dss-401-edition&#34;&gt;Volume 2 - PCI DSS Scoping (PCI DSS 4.0.1 edition)&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2.1 Volume Terminology and Acronyms&lt;/li&gt;&#xA;&lt;li&gt;2.2 PCI Resources basic diagrams&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2.2.1 PCI Resources Base Network Diagram&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;2.3 Scoping&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2.3.1 It all starts with data&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;2.4 PCI DSS Scoping explained&lt;/li&gt;&#xA;&lt;li&gt;2.5 PCI Resources Simplified PCI DSS Scoping Model and Approach&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2.5.1 Categories Summary&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;2.6 Simplified Approach and Scoping categories&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2.6.1 Simplified Approach Part 1 - CDE (steps 1-3)&lt;/li&gt;&#xA;&lt;li&gt;2.6.2 Simplified Approach Part 2 - Connected systems (steps 4-6)&lt;/li&gt;&#xA;&lt;li&gt;2.6.3 Out-of-scope systems&lt;/li&gt;&#xA;&lt;li&gt;2.6.4 Scope Documentation&lt;/li&gt;&#xA;&lt;li&gt;2.6.5 Comparison to other models&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;2.7 Scope Reduction Methods&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2.7.1 Outsourcing&lt;/li&gt;&#xA;&lt;li&gt;2.7.2 Data Reduction (via PAN Transformations)&lt;/li&gt;&#xA;&lt;li&gt;2.7.3 Segmentation / Isolation&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;2.8 Advanced Scoping&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2.8.1 eCommerce&lt;/li&gt;&#xA;&lt;li&gt;2.8.2 Card Present payments using Mobile payment devices as terminals&lt;/li&gt;&#xA;&lt;li&gt;2.8.3 Virtualization and Cloud&lt;/li&gt;&#xA;&lt;li&gt;2.8.4 Complex Virtualization Cases&lt;/li&gt;&#xA;&lt;li&gt;2.8.5 Scope of Emails and Instant Messaging Solutions&lt;/li&gt;&#xA;&lt;li&gt;2.8.6 Scope using genAI/LLM (summer 2026 status)&lt;/li&gt;&#xA;&lt;li&gt;2.8.7 Non-covered technologies&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;2.9 Sources and References&lt;/li&gt;&#xA;&lt;li&gt;End Notes - Volume 2&lt;/li&gt;&#xA;&lt;li&gt;Appendix 2A - PCI DSS Scope Documentation Guidance for PCI DSS 4.0 .1&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>Table of Content - Volume 3 (PCI DSS 4.0.1 edition)</title>
				<link>/book/volume-3-toc/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>/book/volume-3-toc/</guid>
				<description>&lt;p&gt;&lt;em&gt;Back to &lt;a href=&#34;/book&#34;&gt;books home&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;volume-3---building-a-pci-dss-information-security-program-pci-dss-401-edition&#34;&gt;Volume 3 - Building a PCI DSS Information Security Program (PCI DSS 4.0.1 edition)&lt;/h3&gt;&#xA;&lt;p&gt;Volume 3 - Building a PCI DSS Information Security Program&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.1 Volume Introduction&lt;/li&gt;&#xA;&lt;li&gt;3.2 The High-Level PCI DSS requirements&lt;/li&gt;&#xA;&lt;li&gt;3.3 Building a PCI DSS Information Security Program&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.3.1 Where you come from matters&lt;/li&gt;&#xA;&lt;li&gt;3.3.2 Information Security Programs are meant to address Risks&lt;/li&gt;&#xA;&lt;li&gt;3.3.3 Information Security Frameworks&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;3.4 Considerations for an Information Security Program&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.4.1 Recapping the PCI DSS data elements&lt;/li&gt;&#xA;&lt;li&gt;3.4.2 Data Classification&lt;/li&gt;&#xA;&lt;li&gt;3.4.3 Examples of data classification&lt;/li&gt;&#xA;&lt;li&gt;3.4.4 Governance&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;3.5 The PCI DSS Information Security Program Structure (the head of the program)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.5.1 (Information Security) Policies (Sections 12.1, 12.2, X.1)&lt;/li&gt;&#xA;&lt;li&gt;3.5.2 Responsibilities for the program (Section 12.1)&lt;/li&gt;&#xA;&lt;li&gt;3.5.3 Targeted Risk Assessments (TRA, Section 12.3)&lt;/li&gt;&#xA;&lt;li&gt;3.5.4 PCI DSS Program and Monitoring (Service Provider, Section 12.4)&lt;/li&gt;&#xA;&lt;li&gt;3.5.5 Scope : Documenting usage of card information (Section 12.5)&lt;/li&gt;&#xA;&lt;li&gt;3.5.6 Security awareness (Section 12.6)&lt;/li&gt;&#xA;&lt;li&gt;3.5.7 Human Resource Security (Section 12.7)&lt;/li&gt;&#xA;&lt;li&gt;3.5.8 Managing Third-party service providers (TPSP) (Section 12.8)&lt;/li&gt;&#xA;&lt;li&gt;3.5.10 Incident Response Management (Section 12.10)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;3.6 The body of the program&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.6.1 Objective 1: Build and Maintain a Secure Network and Systems&lt;/li&gt;&#xA;&lt;li&gt;3.6.2 Objective 2: Protect Account Data&lt;/li&gt;&#xA;&lt;li&gt;3.6.3 Objective 3: Maintain a Vulnerability Management Program&lt;/li&gt;&#xA;&lt;li&gt;3.6.4 Objective 4: Implement Strong Access Control Measures&lt;/li&gt;&#xA;&lt;li&gt;3.6.5 Objective 5: Regularly Monitor and Test Networks&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;3.7 Additional Requirements&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.7.1 Requirement Appendix A1:Multi-tenant service provider (previously called shared service provider) requirements&lt;/li&gt;&#xA;&lt;li&gt;3.7.2 Requirement Appendix A2: Secure transmission of CHD from payment devices (cryptography for data in motion)&lt;/li&gt;&#xA;&lt;li&gt;3.7.3 Requirement Appendix A3: Designated Entities Supplemental Validation (DESV)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;3.8 Controls to consider when using, and to protect from, genAI/LLM&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.8.1 Controls when using genAI&lt;/li&gt;&#xA;&lt;li&gt;3.8.2 Use of genAI to supplement controls&lt;/li&gt;&#xA;&lt;li&gt;3.8.3 Impact of genAI and similar tools on the threat landscape&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;3.9 Addressing compliance gaps - prioritization&lt;/li&gt;&#xA;&lt;li&gt;3.10 When you cannot meet the &amp;ldquo;defined approach&amp;rdquo; as is&#xA;&lt;ul&gt;&#xA;&lt;li&gt;3.10.1 Compensating Controls - the old way&lt;/li&gt;&#xA;&lt;li&gt;3.10.2 Customized Approach - the new way&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;3.11 Total Cost of Ownership (TCO) and Return-on-Investment (ROI)&lt;/li&gt;&#xA;&lt;li&gt;End Notes - Volume 3&lt;/li&gt;&#xA;&lt;li&gt;Appendix 3A - Network Primer&lt;/li&gt;&#xA;&lt;li&gt;Appendix 3B - A primer on encryption&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>Table of Content - Volume 4 (PCI DSS 4.0.1 edition)</title>
				<link>/book/volume-4-toc/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>/book/volume-4-toc/</guid>
				<description>&lt;p&gt;&lt;em&gt;Back to &lt;a href=&#34;/book&#34;&gt;books home&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;volume-4---hypothetical-case-studies---from-janes-flower-attic-to-janes-flower-emporium-pci-dss-401-edition&#34;&gt;Volume 4 - Hypothetical Case Studies - From Jane&amp;rsquo;s Flower Attic to Jane&amp;rsquo;s Flower Emporium (PCI DSS 4.0.1 edition)&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Volume 4 - Hypothetical Case Studies&lt;/li&gt;&#xA;&lt;li&gt;4.1 Volume Introduction&#xA;&lt;ul&gt;&#xA;&lt;li&gt;4.1.1 Assumptions&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;4.2 Jane&amp;rsquo;s journey - Step 1 - A small side business&#xA;&lt;ul&gt;&#xA;&lt;li&gt;4.2.1 Jane&amp;rsquo;s Flower Attic (JFA) business&lt;/li&gt;&#xA;&lt;li&gt;4.2.2 Applying SAQ-B-IP using a cellular network connection to the payment device&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;4.3 - Step 2 - Jane&amp;rsquo;s Flower Boutique (JFB)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;4.3.1 JFB Network Security Control (NSC, e.g. firewall) standard&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;4.4 Step 3 - Jane&amp;rsquo;s Flower Chain (JFC)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;4.4.1 Network level controls&lt;/li&gt;&#xA;&lt;li&gt;4.4.2 Identification and Authentication controls&lt;/li&gt;&#xA;&lt;li&gt;4.4.3 Physical security controls&lt;/li&gt;&#xA;&lt;li&gt;4.4.4 System level controls&lt;/li&gt;&#xA;&lt;li&gt;4.4.5 Application level controls&lt;/li&gt;&#xA;&lt;li&gt;4.4.6 Logging and Monitoring&lt;/li&gt;&#xA;&lt;li&gt;4.4.7 Testing&lt;/li&gt;&#xA;&lt;li&gt;4.4.8 Governance, Policies, Procedures&lt;/li&gt;&#xA;&lt;li&gt;4.4.9 Incident Response&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;4.5 - Step 4 - Jane&amp;rsquo;s Flower Depot (JFD)&lt;/li&gt;&#xA;&lt;li&gt;4.6 - Step 4 - Jane&amp;rsquo;s Flower Emporium (JFE)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;4.6.1 JFE Organizational Structure&lt;/li&gt;&#xA;&lt;li&gt;4.6.2 Best-practice in information security governance - Information security separate from IT&lt;/li&gt;&#xA;&lt;li&gt;4.6.3 Payment transactions&lt;/li&gt;&#xA;&lt;li&gt;4.6.4 Card present payments in stores and at delivery&lt;/li&gt;&#xA;&lt;li&gt;4.6.5 Customer Service and MOTO transactions&lt;/li&gt;&#xA;&lt;li&gt;4.6.6 eCommerce&lt;/li&gt;&#xA;&lt;li&gt;4.6.7 The Information Security Program (based on ISO 27002)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;End Notes - Volume 4&lt;/li&gt;&#xA;&lt;li&gt;Appendix 4A - JFA Information Security Policy (simplified example)&lt;/li&gt;&#xA;&lt;li&gt;Appendix 4B - JFB NSC (firewall) standard&lt;/li&gt;&#xA;&lt;li&gt;Appendix 4C - JFC Incident Response Plan&lt;/li&gt;&#xA;&lt;li&gt;Appendix 4D - JFD Payment Device Tampering Review Process&lt;/li&gt;&#xA;&lt;li&gt;Appendix 4E - JFE Information Security Policy&lt;/li&gt;&#xA;&lt;li&gt;Appendix 4F - JFE Risk Assessment&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
	</channel>
</rss>
