creditcard swipe


                            

creditcard and key
Monthly NewsLetter
Issue: November 2010
About
Welcome to the monthly edition of our Compliance, Security and GRC Newsletter.  This is informational news comprising the latest on compliance related topics and other IT Security & Governance updates that impact our clients, friends and other interested parties.

The ControlCase GRC Solution

Please feel free to submit suggestions for topics or provide a relevant article to share with other newsletter recipients for future editions, by contacting us at contact@controlcase.com .

In This Issue
PCI DSS 2.0 Released
PA DSS 2.0 Released
New Guidance on P2P Encryption from PCI Council
ControlCase Announces Multi-tenancy Support with Version 5.0
Quick Links
Join our emailing list!
creditcard swipe
PCI Council releases PCI DSS 2.0 October 28th, 2010
The PCI Security Standards Council issued the new PCI DSS 2.0 standard on October 28, 2010. In addition to providing greater clarity regarding scoping and interpretation of technical security requirements and procedures, Version 2.0 outlines enhanced requirements regarding: monitoring of third parties that process, transmit and store cardholder data; performing cardholder data discovery, process flows, retention and disposal; and, logging and monitoring.

Click for Agreement and to Download PCI DSS 2.0

PCI Council releases PA DSS 2.0 - October 26th 2010
This document is to be used by Payment Application-Qualified Security Assessors (PA-QSAs) to conduct payment application reviews, so that software vendors can validate that a payment application complies with the PCI DSS Payment Application Data Security Standard (PA-DSS). Version 2.0 aligns with PCI DSS Version 2.0 released on October 28th, 2010.

Click to Download PA DSS 2.0

PCI Council releases new guidance papers for P2P Encryption and EMV
 
PCI Security Standards Council has released new guidance papers on the use of point-to-point encryption and EMV technologies in a payment card data environment.  These papers are the first in a series of guidance documents the Council has committed to delivering as part of its ongoing assessment of emerging technologies.

The guidance aims to provide valuable information for organizations that are considering implementations of EMV or P2PE technology within the context of PCI DSS compliance.

[Point-to-Point Encryption Technology and PCI DSS Compliance]

[PCI DSS Applicability in an EMV Environment]
Recently in the News....
The following articles highlight accomplishments, challenges and issues that affect our industry:

  ControlCase GRC Ver. 5.0 now supports  Multi-tenant SaaS Features
With the release of 5.0, ControlCase partners and resellers are now able to host and manage IT GRC software as a service (SaaS) solutions for their clients across diverse industries and geographic regions. Multi-tenancy features provide the ability to 'white label' compliance solutions, manage multiple clients through a single interface and dynamically enable specific services as they are implemented.  Contact sales@controlcase.com for more information.
Please let us know any suggestions you may have. Also, please feel free to forward this to other people who would find this newsletter useful.

Sincerely,

ControlCase Team