creditcard swipe


                            

creditcard and key
Monthly NewsLetter
Issue: August 2011
About
Welcome to the monthly edition of our Compliance, Security and GRC Newsletter.  This is informational news comprising the latest on compliance related topics and other IT Security & Governance updates that impact our clients, friends and other interested parties.

The ControlCase GRC Solution

Please feel free to submit suggestions for topics or provide an article that you would like to share with other newsletter recipients for future editions, by contacting us at contact@controlcase.com.

In This Issue
Managed Compliance Bundle Implemented by Rapid
PCI DSS Tokenization Guidelines
Free Data Discovery Tool
Upcoming Events
Recently in the News...
Quick Links
Join our emailing list!
creditcard swipe

Rapid Investments Inc., Selects ControlCase to Supply Managed PCI Compliance Services

ControlCase is pleased to announce that Rapid Investments, Inc. owner of RefPay.com(TM), RodeoPay.com(TM) and OutPay.net(TM) three of largest niche payment solutions in the United States, has implemented its fully managed PCI Compliance service; a suite of software tools that enable organizations to attain compliance with the Payment Card Industry Data Security Standard (PCI DSS). PCI DSS is a security best practice created to prevent credit card fraud through increased protection of sensitive data. It applies to all companies that store, process or transmit cardholder data.  With the scope of PCI compliance growing beyond the company's desire to manage it manually, Rapid chose ControlCase because it offered an industry leading automation service that would ensure that the business remained continually compliant. Rapid recognized that it needed a managed solution that could intelligently control threats and streamline its business processes, not only saving time but enabling key staff to be allocated to other parts of the business. The entire implementation was completed within a month.   

 

Click here for the full press release.

PCI Security Standards Council releases PCI DSS tokenization guidelines   

The PCI Security Standards Council (PCI SSC), PIN Transaction Security (PTS) requirements and the Payment Application Data Security Standard (PA-DSS), today published the PCI DSS Tokenization Guidelines Information Supplement, the latest in a series of SSC guidance documents aimed at providing the market with greater clarity on how specific technologies relate to the PCI Security Standards and impact PCI DSS compliance.  Tokenization technology replaces a Primary Account Number (PAN) with a surrogate value called a "token". Specific to PCI DSS, this involves substituting sensitive PAN values with non-sensitive token values, meaning a properly implemented tokenization solution can reduce or remove the need for a merchant to retain PAN in their environment once the initial transaction has been processed. Click here for more details.  

ControlCase Releases Free Version of its Data Discovery Scanner  

ControlCase has announced the availability of a free downloadable data discovery tool (ControlCase Data Discovery Desktop Edition) which enables organizations to identify and securely remove unprotected cardholder data that may be stored on their systems. ControlCase Data Discovery (CDD) has been developed to meet risk and compliance requirements as outlined in version 2.0 of the Payment Card Industry Data Security Standard (PCI DSS).  Click here to download the free version of the software.   

Frequently, businesses are unaware that compromised data resides on their systems. This is essentially due to the fact that such data is often created and stored unintentionally. For example, cardholder holder data can be replicated and not protected if a business process is updated or changed (such as modifying your backup system), or if a payment system is misconfigured, or if the data is stored on a web server, application or transaction log. This is why the latest version of the PCI DSS includes the requirements for the regular use of data discovery tools. Click here for more information.  

Upcoming Events and Conferences 

ControlCase is sponsoring two upcoming PCI Security Standards Community (PCI SSC) events:  Scottsdale, AZ on 20-22 September 2011and London, United Kingdom on 17-19 October 2011. The first will be held at the Westin Kierland Resort & Spa, and the second is the third annual PCI SSC Community Meeting in Europe which will be hosted at the Lancaster London hotel.  Click here for more details regarding the PCI SSC community meeting in Scottsdale, Arizona or here for the PCI SSC community meeting in London, UK. 

Recently in the News....

The following articles highlight accomplishments, challenges and issues that affect our industry:

 

 Second thoughts about Visa EMV program.... 

   

Companies that fall below card payment standards risk being fined, ICO says... 

  

Don't hinge security just on PCI DSS...    

 

Top 4 debit fraud risks...   

 

Cybercrime costs rising...                                                                                     


Click here for additional articles............ 
******************************************************************************************************************
******************************************************************************************************************
Please let us know any suggestions you may have. Also, please feel free to forward this to other people who would find this newsletter useful.

Sincerely,

ControlCase Team