<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Is PCI DSS Useless?</title>
	<atom:link href="http://www.infoseccynic.com/2009/06/07/is-pci-dss-useless/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.infoseccynic.com/2009/06/07/is-pci-dss-useless/</link>
	<description>Security: Life: Cynicism</description>
	<lastBuildDate>Mon, 08 Mar 2010 15:58:47 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Business Plan Service</title>
		<link>http://www.infoseccynic.com/2009/06/07/is-pci-dss-useless/comment-page-1/#comment-202</link>
		<dc:creator>Business Plan Service</dc:creator>
		<pubDate>Thu, 10 Dec 2009 09:09:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.infoseccynic.com/2009/06/07/is-pci-dss-useless/#comment-202</guid>
		<description>Hi,
It’s an interesting article. Thanks for sharing. 

&lt;a href=&quot;http://www.bizplancorner.com/articles/24/Business-Plan-Service.aspx&quot; rel=&quot;nofollow&quot;&gt; Business Plan Service&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Hi,<br />
It’s an interesting article. Thanks for sharing. </p>
<p><a href="http://www.bizplancorner.com/articles/24/Business-Plan-Service.aspx" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/www.bizplancorner.com/articles/24/Business-Plan-Service.aspx?referer=');"> Business Plan Service</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security Nerd</title>
		<link>http://www.infoseccynic.com/2009/06/07/is-pci-dss-useless/comment-page-1/#comment-136</link>
		<dc:creator>Security Nerd</dc:creator>
		<pubDate>Mon, 08 Jun 2009 15:26:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.infoseccynic.com/2009/06/07/is-pci-dss-useless/#comment-136</guid>
		<description>You hit the nail on the head, these controls need to regularly validated as still effective and/or still necessary along with identifying any new gaps and closing them.  Even then, as long as you have the human element involved, you will have mistakes that could lead to security incidents.  Keeps us in job though :)</description>
		<content:encoded><![CDATA[<p>You hit the nail on the head, these controls need to regularly validated as still effective and/or still necessary along with identifying any new gaps and closing them.  Even then, as long as you have the human element involved, you will have mistakes that could lead to security incidents.  Keeps us in job though <img src='http://www.infoseccynic.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christian</title>
		<link>http://www.infoseccynic.com/2009/06/07/is-pci-dss-useless/comment-page-1/#comment-135</link>
		<dc:creator>Christian</dc:creator>
		<pubDate>Mon, 08 Jun 2009 09:03:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.infoseccynic.com/2009/06/07/is-pci-dss-useless/#comment-135</guid>
		<description>A very well written article. This article here http://www.securityfocus.com/columnists/344 makes a very important point w.r.t the Letter of Engagement. Also worth remembering that a QSA verifies compliance with the standard and not that the entity being audited is actually secure.</description>
		<content:encoded><![CDATA[<p>A very well written article. This article here <a href="http://www.securityfocus.com/columnists/344" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/www.securityfocus.com/columnists/344?referer=');">http://www.securityfocus.com/columnists/344</a> makes a very important point w.r.t the Letter of Engagement. Also worth remembering that a QSA verifies compliance with the standard and not that the entity being audited is actually secure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: uk_noodler</title>
		<link>http://www.infoseccynic.com/2009/06/07/is-pci-dss-useless/comment-page-1/#comment-134</link>
		<dc:creator>uk_noodler</dc:creator>
		<pubDate>Mon, 08 Jun 2009 08:55:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.infoseccynic.com/2009/06/07/is-pci-dss-useless/#comment-134</guid>
		<description>Good analysis of PCI DSS.  But you fail to mention that transactions cannot be anywhere near secure while Card Holder Not Present transactions give over all the information needed to make numerous other transactions.

Anyone working on the next generation payment solution?


BTW, captcha still timed out.</description>
		<content:encoded><![CDATA[<p>Good analysis of PCI DSS.  But you fail to mention that transactions cannot be anywhere near secure while Card Holder Not Present transactions give over all the information needed to make numerous other transactions.</p>
<p>Anyone working on the next generation payment solution?</p>
<p>BTW, captcha still timed out.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
