<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/atom10full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
    <title>Branden Williams' Security Convergence Blog</title>
    <link rel="alternate" type="text/html" href="http://blogs.verisign.com/securityconvergence/" />
    
   <id>tag:blogs.verisign.com,2008:/securityconvergence/7</id>
    <link rel="service.post" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7" title="Branden Williams' Security Convergence Blog" />
    <updated>2008-07-02T12:45:01Z</updated>
    <subtitle>Security In-Depth: Information, Physical, Criminal, and Critical Infrastructure
</subtitle>
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type 3.2</generator>
 
<link rel="self" href="http://feeds.feedburner.com/BrandenWilliamsSecurityConvergenceBlog" type="application/atom+xml" /><feedburner:emailServiceId>1131921</feedburner:emailServiceId><feedburner:feedburnerHostname>http://www.feedburner.com</feedburner:feedburnerHostname><entry>
    <title>Enjoy the Holiday!</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/324839575/enjoy_the_holiday.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=968" title="Enjoy the Holiday!" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.968</id>
    
    <published>2008-07-02T12:42:14Z</published>
    <updated>2008-07-02T12:45:01Z</updated>
    
    <summary>It's time to celebrate American Independence! I'll be taking a holiday for a few days, but will return next week. I will have a post hit on Monday though, so keep your eyes peeled (ouch?)!...</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="Administration" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;It's time to celebrate American Independence!  I'll be taking a holiday for a few days, but will return next week.  I will have a post hit on Monday though, so keep your eyes &lt;a href="http://www.metacafe.com/w/1097676 "&gt;peeled&lt;/a&gt; (ouch?)!&lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=trb3AJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=trb3AJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=etVPnj"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=etVPnj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/324839575" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/07/enjoy_the_holiday.php</feedburner:origLink></entry>
<entry>
    <title>PCI Requirement 6.6 in the news!</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/324239603/pci_requirement_66_in_the_news.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=967" title="PCI Requirement 6.6 in the news!" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.967</id>
    
    <published>2008-07-01T19:13:41Z</published>
    <updated>2008-07-01T19:16:43Z</updated>
    
    <summary>The deadline has passed, do you know where your children web application firewalls are? If you scratched your head and then saw a shiny object fly by to steal your attention, you are not alone. Information Security Magazine interviewed me...</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="Headlines" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;The deadline has passed, do you know where your &lt;del&gt;children&lt;/del&gt; web application firewalls are?  If you scratched your head and then saw a shiny object fly by to steal your attention, you are not alone.  Information Security Magazine &lt;a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1319360,00.html"&gt;interviewed me for an article&lt;/a&gt; on this topic.  Go check it out!&lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=dJz5RJ"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=dJz5RJ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=ZTbcUj"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=ZTbcUj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/324239603" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/07/pci_requirement_66_in_the_news.php</feedburner:origLink></entry>
<entry>
    <title>Not all QSAs are created equal!</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/322715177/not_all_qsas_are_created_equal.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=960" title="Not all QSAs are created equal!" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.960</id>
    
    <published>2008-06-29T19:11:47Z</published>
    <updated>2008-06-29T19:15:02Z</updated>
    
    <summary>The PCI landscape is pretty scary out there. If you are a merchant or service provider that is looking for assistance, there is a long line of companies that are ready to help. What should you expect from your QSA?...</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="PCI" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;The PCI landscape is pretty &lt;a href="http://www.youtube.com/watch?v=2T5_0AGdFic"&gt;scary&lt;/a&gt; out there.  If you are a merchant or service provider that is looking for assistance, there is a long line of companies that are ready to help.  What should you expect from your QSA?  What should your assessment look like to get the best results?&lt;/p&gt;

&lt;p&gt;VeriSign reviewed our findings from our customers and wrote a white paper entitled, "&lt;a href="http://www.computerworld.com/action/whitepapers.do?command=viewWhitePaperDetail&amp;contentId=9103838"&gt;Not All QSAs Are Created Equal: What You Should Know Before You Buy&lt;/a&gt;" that talk about what you should expect.  This paper is a FREE download!  Go check it out!&lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=2wlGVI"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=2wlGVI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=1S6tTi"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=1S6tTi" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/322715177" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/06/not_all_qsas_are_created_equal.php</feedburner:origLink></entry>
<entry>
    <title>Breach got you down?</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/321395691/breach_got_you_down_1.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=958" title="Breach got you down?" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.958</id>
    
    <published>2008-06-27T15:49:41Z</published>
    <updated>2008-06-27T16:00:02Z</updated>
    
    <summary>Well, it has happened again. I received a rather menacing looking note in the mail today. You know, one of those heavy stock sealed letters that has the perforated edges? Yeah. That kind. Inside it looks like my information is...</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="Enterprise Security" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;Well, it has happened again.  I received a rather menacing looking note in the mail today.  You know, one of those heavy stock sealed letters that has the &lt;a href="http://www.youtube.com/watch?v=6-38SfQQZqQ"&gt;perforated&lt;/a&gt; edges?  Yeah.  That kind.&lt;/p&gt;

&lt;p&gt;Inside it looks like my information is on a lost tape from a bank.  The funny thing is, I don't remember banking with this institution... ever.  I have a feeling that one of the brokerage firms I use (or used) was backed by this institution, but nevertheless, I thought of an interesting type of phishing attack that I bet would work.  When I looked through this notice, it did appear to have a corresponding breach on &lt;a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm"&gt;PrivacyRights.org&lt;/a&gt;.  I have already placed my fraud alerts, so I should be good.  &lt;/p&gt;

&lt;p&gt;But what if it didn't?  If I were to target specific individuals (i.e., &lt;a href="http://www.microsoft.com/protect/yourself/phishing/spear.mspx"&gt;spear phishing&lt;/a&gt;) and tell them that their information was compromised from a large bank and provided a number for them to call for &lt;a href="http://www.metacafe.com/w/234602 "&gt;more info&lt;/a&gt;, would they readily give me enough information to steal their identity?  I think people have started to be wary about clicking on things or giving out information over email, but what about through the mail?  Sure it won't have the same reach that electronic attacks will, but how much more lucrative could the loot get?&lt;/p&gt;

&lt;p&gt;My thoughts are that it would work remarkably well against those individuals who don't have lawyers reading their mail, and especially some of the elderly population.&lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=cJSFWI"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=cJSFWI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=wPDx8i"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=wPDx8i" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/321395691" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/06/breach_got_you_down_1.php</feedburner:origLink></entry>
<entry>
    <title>PIN Security finally catching up?</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/319770450/pin_security_finally_catching.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=957" title="PIN Security finally catching up?" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.957</id>
    
    <published>2008-06-25T14:51:49Z</published>
    <updated>2008-06-25T15:41:52Z</updated>
    
    <summary>Wired reports that a Citibank hack may be responsible for a recent ATM crime spree. Edit: Looks like some arrests have been made! I've discussed issues around hacking ATMs and challenges with skimming in the past, but this one appeared...</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="Enterprise Security" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;Wired reports that a Citibank hack may be responsible for a recent &lt;a href="http://blog.wired.com/27bstroke6/2008/06/citibank-atm-se.html"&gt;ATM crime spree&lt;/a&gt;.  &lt;em&gt;Edit: &lt;a href="http://blog.wired.com/27bstroke6/2008/06/fbi-arrests-six.html"&gt;Looks like some arrests have been made&lt;/a&gt;! &lt;/em&gt; I've discussed issues around hacking &lt;a href="http://blogs.verisign.com/securityconvergence/2008/04/tee_hee_eee_pee_cee.php"&gt;ATMs&lt;/a&gt; and challenges with &lt;a href="http://blogs.verisign.com/securityconvergence/2007/12/automatic_fuel_dispensers_skim.php"&gt;skimming&lt;/a&gt; in the past, but this one appeared to be pretty lucrative.  While bank networks are not impenetrable, attacking endpoints is becoming much easier and more lucrative.  &lt;/p&gt;

&lt;p&gt;Anyone remember the old days when you had to make sure the ATM you were going to use &lt;a href="http://www.collisiondetection.net/mt/archives/2005/03/_next_time_you.html"&gt;was real&lt;/a&gt;?  Speaking of that... Ladies, you should beware of &lt;a href="http://www.prankplace.com/atm.htm"&gt;this&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Something of interest to me... As a consumer, do you check your bank statement with all of your receipts?  Would you know if money started disappearing from your account in $10-$30 increments?  Does the state of your personal financial situation dictate your attention to your bank account?  I may be a dying breed, but I have been known to spend twenty minutes &lt;a href="http://www.youtube.com/watch?v=TJiOjiMbvko"&gt;poring&lt;/a&gt; over a bank statement to figure out where I missed a dime.&lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=kLo5EI"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=kLo5EI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=CgIHRi"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=CgIHRi" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/319770450" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/06/pin_security_finally_catching.php</feedburner:origLink></entry>
<entry>
    <title>Listen to my PCI Podcast!</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/316225429/listen_to_my_pci_podcast.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=955" title="Listen to my PCI Podcast!" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.955</id>
    
    <published>2008-06-20T14:46:48Z</published>
    <updated>2008-06-20T14:51:00Z</updated>
    
    <summary>About a month ago an audio guy showed up to my house and pinned a tiny microphone to my shirt for a podcast on PCI. It is a joint podcast with John Pescatore of Gartner. The theme is on managing...</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="PCI" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;About a month ago an &lt;a href="http://www.truveo.com/Beer-Bottle-Symphony-Orchestra/id/3653130681"&gt;audio guy&lt;/a&gt; showed up to my house and pinned a tiny microphone to my shirt for a podcast on PCI.  It is a joint podcast with John Pescatore of Gartner.  The theme is on managing PCI Compliance.&lt;/p&gt;

&lt;p&gt;&lt;a href="http://www.itbriefingcenter.com/programs/gartner_635_podcast_verisign.html"&gt;Go check it out&lt;/a&gt;!&lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=DcMnRI"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=DcMnRI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=F8ATli"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=F8ATli" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/316225429" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/06/listen_to_my_pci_podcast.php</feedburner:origLink></entry>
<entry>
    <title>Where oh where has my little blogger gone?</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/314175387/where_oh_where_has_my_little_b.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=953" title="Where oh where has my little blogger gone?" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.953</id>
    
    <published>2008-06-17T01:41:46Z</published>
    <updated>2008-06-18T00:23:07Z</updated>
    
    <summary>I haven't written, called, emailed, faxed, or even sent you guys anything via carrier pidgeon. For that, I grovel at your feet and request my penance (tee hee, I love the occasional translation error, especially when it reminds me of...</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="Administration" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;I haven't written, called, emailed, faxed, or even sent you guys anything via carrier pidgeon.  For that, I grovel at your feet and request my &lt;a href="http://video.google.com/videoplay?docid=4709095204479401952"&gt;penance&lt;/a&gt; (tee hee, I love the occasional translation error, especially when it reminds me of the &lt;a href="http://www.youtube.com/watch?v=2Lwf3G5eiwo"&gt;most beautiful thing&lt;/a&gt; I have ever seen).  What have I been up to?&lt;/p&gt;

&lt;p&gt;Last week was fun.  Boston &amp; Cincinnati in two days.  Was great seeing many of you out there!  Especially when a coworker and I started eating at the &lt;a href="http://www.youtube.com/watch?v=_O1ogV5kRxc"&gt;wrong party&lt;/a&gt;!  This week, so far, I have met with the Visa CISP and Incident Response teams over two days, and I am headed home to fly out to Atlanta for a couple of customer meetings.  If you are in town, drop me a line!&lt;/p&gt;

&lt;p&gt;Some PCI News for you...&lt;/p&gt;

&lt;p&gt;The PCI Security Standards Council has announced their &lt;a href="https://www.pcisecuritystandards.org/pdfs/06-16-08.pdf"&gt;community meetings&lt;/a&gt; for 2008.  We will be there!  They have also announced training dates for PA-DSS assessors.&lt;/p&gt;

&lt;p&gt;I'm off to DFW!&lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=DhYppI"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=DhYppI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=kbya9i"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=kbya9i" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/314175387" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/06/where_oh_where_has_my_little_b.php</feedburner:origLink></entry>
<entry>
    <title>Are you in Cincinnati?</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/308451878/are_you_in_cincinnati.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=946" title="Are you in Cincinnati?" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.946</id>
    
    <published>2008-06-10T02:38:04Z</published>
    <updated>2008-06-10T02:39:04Z</updated>
    
    <summary>If so, shoot me an email! I will be there for the 5th 3rd Customer event tomorrow (if I can ever get out of Boston!)....</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="Administration" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;If so, shoot me an email!  I will be there for the 5th 3rd Customer event tomorrow (if I can ever get out of Boston!).&lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=ITNb1I"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=ITNb1I" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=UL0u5i"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=UL0u5i" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/308451878" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/06/are_you_in_cincinnati.php</feedburner:origLink></entry>
<entry>
    <title>June Edition of Herding Cats</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/305394457/june_edition_of_herding_cats.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=942" title="June Edition of Herding Cats" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.942</id>
    
    <published>2008-06-05T15:03:34Z</published>
    <updated>2008-06-05T16:15:43Z</updated>
    
    <summary>The ISSA has posted the electronic version of the journal, so if you are itching to read what is coming to you via the post, go check it out! My column this month is titled "Don't Get Cyberjacked!" It may...</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="Enterprise Security" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;The ISSA has posted the electronic version of the journal, so if you are itching to read what is coming to you via the post, go check it out!  My column this month is titled "&lt;a href="https://www.issa.org/Library/Journals/2008/June/Williams-Dont%20Get%20Cyber-Jacked.pdf"&gt;Don't Get Cyberjacked!&lt;/a&gt;"&lt;/p&gt;

&lt;p&gt;It may be the first time that the phrase "This ain't your daddy's security incident" and the word "&lt;a href="http://www.expertvillage.com/video/14471_stripping-sander.htm"&gt;stripper&lt;/a&gt;" appear on the same page (or ever) in that fantastic publication.  Go &lt;a href="http://www.youtube.com/watch?v=eBGIQ7ZuuiU"&gt;check it&lt;/a&gt; out!&lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=nidimI"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=nidimI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=N8fTzi"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=N8fTzi" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/305394457" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/06/june_edition_of_herding_cats.php</feedburner:origLink></entry>
<entry>
    <title>Is PCI Working?</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/300597947/is_pci_working_1.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=909" title="Is PCI Working?" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.909</id>
    
    <published>2008-05-29T15:32:47Z</published>
    <updated>2008-05-29T15:45:02Z</updated>
    
    <summary>I was asked this question while sitting on a panel at RSA, and I think the answer depends on your perspective. I'll answer this from a security industry perspective. If nothing else, you have to credit PCI with forcing the...</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="PCI" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;I was asked this question while sitting on a panel at RSA, and I think the answer depends on your perspective.  I'll answer this from a security industry perspective.&lt;/p&gt;

&lt;p&gt;If nothing else, you have to credit PCI with forcing the issue.  Security among retail enterprises was generally limited to loss prevention and physical security until recently.  &lt;a href="http://www.youtube.com/watch?v=yVjzd320gew"&gt;Information security&lt;/a&gt; &lt;em&gt;usually&lt;/em&gt; existed as a small and buried team within the Information Technology group, and did not have board level attention.  If someone at the board was savvy enough to realize that security reporting to IT is an example of the &lt;a href="http://www.youtube.com/watch?v=42m78c6_K-I"&gt;fox&lt;/a&gt; guarding the hen house, then maybe they moved security into Internal Audit.  &lt;/p&gt;

&lt;p&gt;Now we are seeing a massive amount of development in security and compliance programs.  Where companies had a staff of two or three to handle this, they now have large, global teams to deal with this.  PCI forced the issue, then higher ups started asking questions about HIPAA, GLBA, and others.  &lt;/p&gt;

&lt;p&gt;Security teams now report into the office of the CFO, or Legal, and in many cases have their own seat on the board.  Budgets are opening up, and money is being spent.  Without fail, more issues are found while every stone is turned over to see what &lt;a href="http://www.collegehumor.com/video:23198"&gt;bugs&lt;/a&gt; lie beneath.&lt;/p&gt;

&lt;p&gt;&lt;a href="http://www.youtube.com/watch?v=A2lv-MA6RrI"&gt;Poetic&lt;/a&gt;, don't you think? &lt;/p&gt;

&lt;p&gt;The next test is to see if the strategy component has been handled such that you can sustain the support to the organization, and avoid bureaucratic bloat.  PCI can't get you there, only good old security process will.&lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=dX7stH"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=dX7stH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=Ob37Lh"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=Ob37Lh" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/300597947" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/05/is_pci_working_1.php</feedburner:origLink></entry>
<entry>
    <title>See you at the Gartner IT Security Summit!</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/299263595/see_you_at_the_gartner_it_secu.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=934" title="See you at the Gartner IT Security Summit!" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.934</id>
    
    <published>2008-05-27T19:22:52Z</published>
    <updated>2008-05-27T19:35:45Z</updated>
    
    <summary>Are you making the trek to DC next week for the Gartner IT Security Summit? VeriSign will be there, and I'll be speaking on Monday, June 2, at 4:15PM in Potomac 6. It's time to discuss the classic transmogrification, changing...</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="Headlines" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;Are you making the trek to DC next week for the &lt;a href="http://www.gartner.com/it/page.jsp?id=594029"&gt;Gartner IT Security Summit&lt;/a&gt;?  VeriSign will be there, and &lt;a href="http://agendabuilder.gartner.com/sec14/webpages/SessionList.aspx?Speaker=700075"&gt;I'll be speaking&lt;/a&gt; on Monday, June 2, at 4:15PM in Potomac 6.  It's time to discuss the classic &lt;a href="http://www.lovine.com/hobbes/comics/transmogrifier.html"&gt;transmogrification&lt;/a&gt;, changing the tactical PCI approach to &lt;a href="http://en.wikipedia.org/wiki/Strategery"&gt;strategery&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Phew!&lt;/p&gt;

&lt;p&gt;Anyway... Come see my presentation or stop by the VeriSign booth!&lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=CWi4ZH"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=CWi4ZH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=oOJd9h"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=oOJd9h" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/299263595" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/05/see_you_at_the_gartner_it_secu.php</feedburner:origLink></entry>
<entry>
    <title>Will your QSA Breach your Contract?</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/291668205/will_your_qsa_breach_your_cont_1.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=918" title="Will your QSA Breach your Contract?" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.918</id>
    
    <published>2008-05-16T15:11:36Z</published>
    <updated>2008-05-16T15:15:01Z</updated>
    
    <summary>Your QSA may not be telling you the whole story. No, I'm not talking about sloppy assessment work. What I'm referring to is a clause that is supposed to be in your contract with your QSA. The DSS Validation Requirements...</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="PCI" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;Your QSA may not be telling you the whole story.  &lt;/p&gt;

&lt;p&gt;No, I'm not talking about sloppy assessment work.  What I'm referring to is a clause that is supposed to be in your contract with your QSA.  The &lt;a href="https://www.pcisecuritystandards.org/pdfs/pci_dss_validation_requirements_for_qualified_security_assessors_QSAs_v1-1.pdf"&gt;DSS Validation Requirements for Qualified Security Assessors&lt;/a&gt; requires that QSAs put a notification in their contracts with their customers telling them that the ROC and supporting materials can be disclosed (Section A.6.3 in the doc linked above).  Why does that language need to be in the contract?  Because the QSA agrees to send the ROC to certain parties per the operating agreement!&lt;/p&gt;

&lt;p&gt;In a recent competitive bid situation, we were informed that two (of four) bidders &lt;strong&gt;DID NOT&lt;/strong&gt; have such language in their contracts!  This means that the QSA has a choice.  They can either breach the agreement they have with the Council, thus quickly getting them delisted as a QSA.  Or, &lt;a href="http://www.youtube.com/watch?v=SUsNv45ixwM"&gt;they will breach YOUR contract&lt;/a&gt; and send the info along without your consent!&lt;/p&gt;

&lt;p&gt;I am surprised that QSAs are doing this, and wondering what their intentions are.  If nothing else, if you get a contract without that clause in there, what does that say for the &lt;a href="http://www.youtube.com/watch?v=hibyAJOSW8U"&gt;quality&lt;/a&gt; of the assessment you will receive? &lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=nd443H"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=nd443H" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=FJNjdh"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=FJNjdh" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/291668205" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/05/will_your_qsa_breach_your_cont_1.php</feedburner:origLink></entry>
<entry>
    <title>PCI News Flash!  PCI-DSS Version 1.2 to be released in October</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/290433440/pci_news_flash_pcidss_version.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=917" title="PCI News Flash!  PCI-DSS Version 1.2 to be released in October" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.917</id>
    
    <published>2008-05-14T21:10:52Z</published>
    <updated>2008-05-14T21:28:17Z</updated>
    
    <summary>If you had any action on the Vegas odds for the release of the next DSS and what it might be called, time to cash in. I was speculating that it would occur around the time of the conference this...</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="PCI" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;If you had any &lt;a href="http://www.youtube.com/watch?v=2rBLNRgT3YQ"&gt;action&lt;/a&gt; on the Vegas odds for the release of the next DSS and what it might be called, time to cash in.  I was speculating that it would occur around the time of the conference this year, and it would have been called 1.2 (vs 2.0).  &lt;/p&gt;

&lt;p&gt;Ahh, you win some, and you lose some.&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://www.pcisecuritystandards.org/pdfs/05-14-08.pdf"&gt;official release is here&lt;/a&gt;, and hints that there may be some new requirements coming down the pipe.  They typically give 18-24 months to implement, so no need to panic now.  But watch out for more controls around wireless!&lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=MGLgBH"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=MGLgBH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=wrN7Uh"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=wrN7Uh" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/290433440" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/05/pci_news_flash_pcidss_version.php</feedburner:origLink></entry>
<entry>
    <title>Will you meet the 6.6 PCI Requirement by June 30?</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/289483331/will_you_meet_the_66_pci_requi.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=916" title="Will you meet the 6.6 PCI Requirement by June 30?" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.916</id>
    
    <published>2008-05-13T14:52:16Z</published>
    <updated>2008-05-13T16:45:50Z</updated>
    
    <summary>Well? Will you? We're waiting!?? Hopefully your bank is not taking THAT approach to checking on your status, but I know many merchants are feeling the heat. Jaikumar Vijayan from Computer World writes that when this deadline passes, most people...</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="PCI" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;Well?  Will you?&lt;/p&gt;

&lt;p&gt;We're waiting!??&lt;/p&gt;

&lt;p&gt;Hopefully your bank is not taking THAT approach to checking on your status, but I know many merchants are feeling the heat.  Jaikumar Vijayan from Computer World &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9085038&amp;source=rss_topic17"&gt;writes&lt;/a&gt; that when this deadline passes, most people will not be in compliance.  If you read the letter of the law, yes, I would agree.  But based on the &lt;a href="https://www.pcisecuritystandards.org/pdfs/infosupp_6_6_applicationfirewalls_codereviews.pdf"&gt;guidance released by the council&lt;/a&gt;, if you are compliant with the rest of the standard, there is a pretty good chance you are compliant with 6.6.&lt;/p&gt;

&lt;p&gt;In this clarification, The Council declared the intent of the code review component to include "Manual web application security vulnerability assessment" and "Proper use of automated web application security vulnerability assessment (scanning) tools."  So essentially if you are getting something like &lt;a href="http://www.verisign.com/managed-security-services/information-security/vulnerabilty-assessment/index.html"&gt;VeriSign's Premium Vulnerability Management Service&lt;/a&gt;, you meet this requirement.  You could also count your penetration test as long as the application has not changed since that penetration test was performed, and it covers the entire application with manual interaction.  VeriSign's Penetration Testing services DO cover this.&lt;/p&gt;

&lt;p&gt;There will be some merchants that do not meet the requirement; but those merchants have likely been doing just the bare minimum, or "&lt;a href="http://www.youtube.com/watch?v=xzYHeW3yEJA"&gt;Managing Checkmarks&lt;/a&gt;," as opposed to building a sound security infrastructure and fitting compliance inside it.  Merchants doing that are probably not fully compliant on any given day anyway.&lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=I7bsiH"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=I7bsiH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=SFTPkh"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=SFTPkh" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/289483331" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/05/will_you_meet_the_66_pci_requi.php</feedburner:origLink></entry>
<entry>
    <title>PCI News Flash!  QSA Lookup!</title>
    <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~3/286826841/pci_news_flash_qsa_lookup.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://10.163.156.32/cgi/mt/mt-atom.cgi/weblog/blog_id=7/entry_id=915" title="PCI News Flash!  QSA Lookup!" />
    <id>tag:blogs.verisign.com,2008:/securityconvergence//7.915</id>
    
    <published>2008-05-09T14:14:54Z</published>
    <updated>2008-05-09T14:17:11Z</updated>
    
    <summary>Do you wonder if the consultants that your QSAC sends on-site are actually QSAs? Well now you can check! For some reason, all of VeriSign's QSAs don't appear in this list, but we're diligently working to correct that. I can...</summary>
    <author>
        <name>Branden Williams</name>
        
    </author>
            <category term="PCI" />
    
    <content type="html" xml:lang="en" xml:base="http://blogs.verisign.com/securityconvergence/">
        &lt;p&gt;Do you wonder if the consultants that your QSAC sends on-site are actually QSAs?  Well &lt;a href="https://www.pcisecuritystandards.org/qsa_lookup/index.html"&gt;now you can check&lt;/a&gt;!  For some reason, all of VeriSign's QSAs don't appear in this list, but we're diligently working to correct that.  I can only imagine the large QSACs are probably flooding Cathy with email right now.&lt;/p&gt;
        
    &lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=9ppbxH"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=9ppbxH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?a=W0udGh"&gt;&lt;img src="http://feeds.feedburner.com/~f/BrandenWilliamsSecurityConvergenceBlog?i=W0udGh" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BrandenWilliamsSecurityConvergenceBlog/~4/286826841" height="1" width="1"/&gt;</content>
<feedburner:origLink>http://blogs.verisign.com/securityconvergence/2008/05/pci_news_flash_qsa_lookup.php</feedburner:origLink></entry>

</feed>
