<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!--Web 2.0 Content Powered by MyST Blogsite® (http://blogsite.com)-->
<!--A service of MyST Technology Partners, Inc. (http://myst-technology.com)-->
<?xml-stylesheet href="http://blog.cenzic.com/public/styles/etc/object.xsl" type="text/xsl"?>

<?myst-baseUrl http://blog.cenzic.com/public/?>

<MySmartChannels Public="true" UserID="202607" dT="98" t0="1283905319289">
     <GetChannelItem_Result>
      <Item>
       <Resource>
        <ObjectID>221622</ObjectID>
        <ObjectClass>Resource</ObjectClass>
        <OwnerID ObjectClass="Domain" Title="[Weblog] Application Security News">202618</OwnerID>
        <CreatedByID ObjectClass="User" Title="eswanson">202768</CreatedByID>
        <ModifiedByID ObjectClass="User" Title="eswanson">202768</ModifiedByID>
        <CreateTime Title="2008-12-23 19:05:20 EST">1230077120205</CreateTime>
        <ModifyTime Title="2008-12-24 00:04:15 EST">1230095055648</ModifyTime>
        <SecurityModel>Controlled</SecurityModel>
        <Name>PCI Compliance Does Not Equal Security</Name>
        <Summary>Growing number of firms report hacker attacks after adhering to PCI Compliance regulations</Summary>
        <Description>&lt;p&gt;An article about the &lt;a title="Top 10 Security Breaches of 2008" href="http://www.bankinfosecurity.com/articles.php?art_id=1120&amp;opg=1" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;top 10 security breaches of 2008&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;, cited that 2 out of the 10 breaches were done to companies who were in compliance with PCI regulations.&amp;nbsp; &lt;/p&gt;&lt;p&gt;Both Maine-based &lt;strong&gt;Hannaford Brothers grocery store chain &lt;/strong&gt;and ski resort &lt;strong&gt;Okemo&lt;/strong&gt; were hit by hackers that installed malicious software on their Websites to capture credit card data.&amp;nbsp; And at the time of both attacks, the companies were PCI compliant.&amp;nbsp; These firms now share company with the likes of&amp;nbsp;Forever 21 &amp;ndash; a retail clothing company &amp;ndash; that was &lt;a href="http://linuxinsider.com/story/security/64926.html"&gt;&lt;strong&gt;&lt;u&gt;victim to a similar attack&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; back in October. &lt;/p&gt;&lt;p&gt;I liked how the author summarized PCI compliance:&amp;nbsp; &lt;/p&gt;&lt;blockquote dir="ltr" style="MARGIN-RIGHT: 0px"&gt;&lt;p&gt;&lt;strong&gt;Lesson Learned:&lt;/strong&gt;&amp;nbsp; PCI compliance is like a driver's license -- it may mean that a retailer has passed the test for compliance, but doesn't necessarily mean it is in compliance. &lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;At the risk of sounding redundant, we will stress again, that companies must do more that just attain PCI compliance.&amp;nbsp; They must constantly test and re-test their Websites for the latest vulnerability threats, as 400 new ones emerge every month.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</Description>
        <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
        <ContentType>application/xml</ContentType>
        <ContentDocument>
         <ItemProperties>
               <CommonProperties>
                <Hidden>false</Hidden>

                <Keywords>
                 <Keyword>pci compliance</Keyword>

       </Keywords>

                <Links>
                 <Link>
                  <Title>Top 10 Security Breaches of 2008</Title>

                  <Synopsis>Ghost of Christmas Past (TJX) Still Casts Specter on Present and Future</Synopsis>

                  <URL>http://www.bankinfosecurity.com/articles.php?art_id=1120&amp;opg=1</URL>

        </Link>

                 <Link>
                  <Title>Why Do Bad Things Happen to PCI-Compliant Companies?</Title>

                  <Synopsis>PCI DSS compliance does not equal security</Synopsis>

                  <URL>http://linuxinsider.com/story/security/64926.html</URL>

        </Link>

       </Links>

      </CommonProperties>

               <ns3:Details xmlns="urn:MyST-Technology.Structured.Details" xmlns:ns3="urn:MyST-Technology.Structured.Details">
                <ns3:Collection name="Quote" type="urn:MyST-Technology.Structured.Collection.Captyx.Quote">
                 <ns3:Attribute name="Quote" type="large-text">
                  <ns3:Value>PCI compliance is like a driver's license - it may mean that a retailer has passed the test for compliance, but doesn't necessarily mean it's in compliance.</ns3:Value>

        </ns3:Attribute>

                 <ns3:Attribute name="Name" type="text" value="Linda McGlasson, Managing Editor"/>

                 <ns3:Attribute name="Blog" type="url"/>

                 <ns3:Attribute name="Title" type="text"/>

                 <ns3:Attribute name="Company" type="text" value="BankInfo Security"/>

                 <ns3:Attribute name="Web" type="url" value="http://www.bankinfosecurity.com/articles.php?art_id=1120&amp;opg=1"/>

                 <ns3:Attribute name="Icon" type="checkbox" value="true"/>

                 <ns3:Attribute name="Frame" type="text" value="bars"/>

                 <ns3:Attribute name="HTML" type="checkbox" value="false"/>

                 <ns3:Attribute name="Alignment" type="text" value="right"/>

                 <ns3:Attribute name="Text Size" type="text" value="medium"/>

                 <ns3:Attribute name="Container" type="text" value="div"/>

                 <ns3:Attribute name="Container ID" type="text"/>

                 <ns3:Attribute name="Container Class" type="text" value="Quote"/>

                 <ns3:Attribute name="Container Style" type="text"/>

                 <ns3:Attribute name="_captyx.position" type="text" value="_top"/>

                 <ns3:Attribute name="_captyx.embargo" type="checkbox" value="false"/>

                 <ns3:Attribute name="_captyx.scope" type="text"/>

                 <ns3:Attribute name="_captyx.sortkey" type="text"/>

       </ns3:Collection>

      </ns3:Details>

               <RemoteInfo>
                <UserAgent>Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)</UserAgent>

                <RemoteHost>127.0.0.1</RemoteHost>

                <RemoteAddr>127.0.0.1</RemoteAddr>

                <RemoteUser>eswanson</RemoteUser>

                <ForwardedFor>64.60.123.45</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
        </ContentDocument>
       </Resource>
       <Shares/>
       <Subjects/>
       <UserPermissions>
        <CanDelete>false</CanDelete>
        <CanDiscover>true</CanDiscover>
        <CanEdit>false</CanEdit>
        <CanEditPermissions>false</CanEditPermissions>
        <CanRead>true</CanRead>
       </UserPermissions>
       <CommentInfo>
        <CommentChannelRef AllowAnonymous="true" Inherited="true">
         <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">204329</ChannelID>
         <UserPermissions>
          <CanCreateChannelItem>false</CanCreateChannelItem>
          <CanDelete>false</CanDelete>
          <CanDiscover>true</CanDiscover>
          <CanEdit>false</CanEdit>
          <CanEditPermissions>false</CanEditPermissions>
          <CanPublish>false</CanPublish>
          <CanRead>true</CanRead>
         </UserPermissions>
        </CommentChannelRef>
        <Comments/>
       </CommentInfo>
       <Views>
        <SourceID ObjectClass="Channel" Title="[Weblog] Application Security News">202618</SourceID>

               <View>
                <Name>blog</Name>

                <Model>blogsite/Cenzic/web</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>edit-item</Name>

                <Model>blogsite/Cenzic/right-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>left</Name>

                <Model>blogsite/Cenzic/left-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>right</Name>

                <Model>blogsite/Cenzic/right-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>wide</Name>

                <Model>blogsite/Cenzic/wide-content</Model>

                <Style/>

                <Scheme/>

       </View>

      </Views>
        <Views>
         <SourceID ObjectClass="Channel" Shared="true" Title="[Public] What's New">202621</SourceID>

                <View>
                 <Name>blog</Name>

                 <Model>blogsite/Cenzic/whatsnew</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>edit-item</Name>

                 <Model>blogsite/Cenzic/right-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>left</Name>

                 <Model>blogsite/Cenzic/left-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>right</Name>

                 <Model>blogsite/Cenzic/right-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>wide</Name>

                 <Model>blogsite/Cenzic/wide-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

      </Views>
        </Item>
       </GetChannelItem_Result>
      </MySmartChannels>
