PCI DSS Encryption and Compensatory Controls
PCI DSS Encryption and Compensatory Controls
Download the Output Report from this Corporate IT Forum workshop. The report has been produced from input from 23 corporate IT professionals representing 15 organisations from a wide cross-section of enterprises including media, financial services, retailing, utilities, a government body and transport & leisure.
The ‘PCI – V2.0 Suppliers & the Lifecycle’ aimed to uncover the truth about third party involvement, discover what V2.0 means to merchants and what has already worked for compliance managers today. This event provided IT security managers and those involved in the management of PCI within their organisation with a clearer understanding of their responsibilities, what Visa and other acquirers are doing to aid merchants and ideas that can be implemented in delegate organisations.
Understand these technologies, the pitfalls to avoid and recommendations to aid with implementing a solution, and how they can assist in your PCI compliance programme.
The PCI standard continues to present challenges and obstacles to its own implementation. This is the third PCI workshop tif. has held. Here are some delegate comments from this workshop:"I am appalled at this — to hear the real chaos at this level, around this table. MasterCard & Visa must have one standard and one approach." "We need clarity."
Achieving PCI compliance is a slow and expensive process for many, but the collected experience of 19 Security and Compliance managers outlines some of the issues and solutions found on the road to becoming compliant.
This workshop covers concerns raised following the release of Version 1.1 of the PCI DSS Standard (September 2006). Specifically issues relating to; compensatory controls, audio-recorded data and how changes could render a currently-compliant merchant non-compliant. Representatives of Mastercard, and Ambiron Trust Wave Ltd were in attendance and were positive in helping to answer delegates’ questions.
Download this Corporate IT Forum Output Report.
The concept of Business Relationship Managers (BRMs) is not a new one. Three-fifths of the organisations represented in discussions have a separate role or team to manage the business relationship, and whereas in the past the role of the BRM sometimes struggled to deliver the value it promised, the overwhelming majority of organisations are now seeing the value that an IT Business Partner can add to the bottom line.
The IT Business Partner is the...
This report details the conversation from the Outsourcing: Surviving and Thriving workshop, held on the 15th September. The event was made up of a panel session, which four experienced and senior IT professionals shared their knowledge with the members, followed by 5 focused round table discussions.
Download the Output Report from this discussion that focussed on on why and how organisations should outsource IT services, and what constitutes best practice in defining and managing such agreements. Specifically, the workshop considered reducing risk, driving value and improving within outsourced relationships at all stages, from negotiation to re-negotiation and re-tendering.
This event deals with the management of security within Outsourcers and Third Parties fromthe pre contract stage through to exit. Delegates were senior security professionals from 9 large organisationsall with significant outsourcing experience. The report includes a presentation from an IT RiskManager from a large pharmaceutical company collates experience from Risk Managers from a range of business and IT functions.