PCI DSS 4.0 represents a philosophical shift from point-in-time validation to continuous, risk-based assurance.

Ready to operationalize compliance as a continuous practice?

Join us today at 10am PT / 1pm ET for a joint session with ControlCase and PCI DSS author Branden R. Williams.

In this webinar, we'll explore:

> The new compliance paradigm: Understanding the intent behind PCI DSS 4.0 changes and what continuous assurance means for your operations.

> Automation at scale: How to automate and scale assessment processes while maintaining control and visibility.

> Infrastructure for compliance: Using the SecOps Cloud Platform as your central compliance data layer with built-in retention, auditability, and integration capabilities.

> MSSP opportunities: How service providers can efficiently scale compliance services and create new revenue streams.

Learn how to build compliance operations that support business growth and trust.

Register now: https://limacharlie.wistia.com/live/events/nm3o9l8509?utm_campaign=pci+webinar+11+12+25&utm_source=mastodon&utm_medium=social

#cybersecurity #pcidss #compliance #secops

Two days until our PCI DSS 4.0 webinar with ControlCase and author Branden R. Williams.

Wednesday, November 12th at 10am PT / 1pm ET.

PCI DSS 4.0 is more than new requirements. It's a shift to continuous, risk-based security that creates opportunities for organizations that embrace it.

We'll cover:

> What's changed and why it matters
> How to interpret the intent behind the requirements
> Operationalizing continuous compliance
> Creating competitive advantages through automated assessment and enforcement

Designed for security engineers, compliance architects, and service providers building scalable compliance operations.

Last chance to register: https://limacharlie.wistia.com/live/events/nm3o9l8509?utm_campaign=pci+webinar+11+12+25&utm_source=mastodon&utm_medium=social

#cybersecurity #pcidss #compliance #secops

PCI DSS 4.0 isn't just a compliance update. It's a fundamental shift to continuous, risk-based security.

Join LimaCharlie, ControlCase, and author Branden R. Williams on Wednesday, November 12th at 10am PT to learn how to turn compliance from a burden into a competitive advantage.

What you'll learn:

> What's changed in PCI DSS 4.0 and why
> How MSSPs can create new revenue opportunities through compliance as a service
> Building continuous compliance operations with automated data collection and enforcement
> Practical approaches to auditability, retention, and integration

Register now: https://limacharlie.wistia.com/live/events/nm3o9l8509?utm_campaign=pci+webinar+11+12+25&utm_source=mastodon&utm_medium=social

#cybersecurity #pcidss #compliance #secops

@Mer__edith again: That isn't magic and if your "#business model" relies on #Azure, #AWS & #GCP, it's inherently and irredeemably flawed to begin with!

Heck, even #Amazon themselves say "#serverless" sucks

  • So why your infrastructure isn't as portable, compact and reproduceable as the one I documented for a payment processor (which unlike #Signal's #ToS has to guarantee compliance with #PSD2, #PCIDSS 4.0, #GDPR, #BDSG & #3Dsecure whilst fulfilling real SLAs) is beyond me.
AWS for the Haters in 100 Seconds

YouTube
Outpost24 launcht flexible Managed PCI-Compliance-Pakete, die ASV-Scans, Schwachstellenanalysen und Penetrationstests automatisiert und zentral steuerbar machen. IT-Teams profitieren von praxisnahem Reporting, schnelleren Audits und können tägliche Compliance-Aufgaben an zertifizierte PCI-Experten auslagern.
#Aktuell #Anwendung #Security #Compliance #ManagedServices #PCIDSS #Security
h...
https://www.it-finanzmagazin.de/compliance-outpost24-kuendigt-managed-pci-service-an-235176/?fsp_sid=12671
Compliance: Outpost24 kündigt Managed PCI-Service an

Outpost24 führt neue PCI-Compliance-Pakete ein. Das Ziel: Den Prozess zur Erreichung und Aufrechterhaltung des PCI DSS vereinfachen.

IT Finanzmagazin

@die_rente Ich hoffe @Bundesregierung geht aktiv gegen solche #Desinformation|s-Kampagnen vor, weil dies nicht mehr mit "Journalistischer Fehlleistung" sondern nur noch #Volksverhetzung erklärbar ist.

@seabass @neil Yes and no.

  • Most OSes these days don't allow incoming connections at random and no reasonable software should expose i.e. servers on the network.

  • Even #WebDevelopers wanting to have a #httpd or #ngnix on the go will bind that to the loopbackinterface.

The few applications that don't do that have no reason to exist and are inherently #ITsec issues.

  • Again: If one can configure stuff to be bound to a specific #VPN then they also can plug that risk as well.

Most corporations use VPNs to fullfill ITsec requirements ranging from #PCIDSS to #HIPAA and from #GDPR to #BDSG as well as protect against #CorporateEspionage and #Hacking by literally only allowing #eMail access through the corporate VPN or #LAN.

  • But that's a different story, espechally for travelling consultants that have to access resources remote whilst in #cyberfascist juristictions (i.e. #USA & "P.R." #China)...

Auch in der Firma geht es voran: Für #pcidss (4.x!!!!)sind die unangenehmen Fragen für uns durch. Nur noch Pakete schnüren und alles hochladen zzgl. gefixter Incidents (Icinga Checks für ClamAV Prozess) und dann abwarten. Die Entwickler haben etwas mehr zu tun.

Und hab neues #logsystem fast schon komplett. #fluentbit wird #nxlog ersetzen. #victorialogs wird eine Weile parallel zum #Graylog laufen und die mangelnde Auth Fähigkeit von vmlog wird mittels #Nginx und #oauthproxy kompensiert. Es gibt auch ein schönes Ticket: Feature Request für fluentbit: Parameter für #yaml oder classic. Dann kann man nämlich fluent Config über Graylog ausrollen 😍

@TobiX @lea @jessew even that is more of an oversight, cuz upcoming #PCIDSS will kill that too...

So either wait for #wero to be mandated or only use merchants that accept #PayPal or #Monero

https://infosec.space/@kkarhan/115230029265034201

Kevin Karhan :verified: (@kkarhan@infosec.space)

@lea@lea.pet yes, if your merchant accepts #Monero: - #Monerujo works fine with #NowPayments... https://nowpayments.io

Infosec.Space

Tired of compliance being a roadblock? Join us on September 24 where we partnered up with Chainguard for a deep dive on automating container security. We'll show you how to use trusted container images and policy-as-code to meet frameworks like #FedRAMP, #PCIDSS, #HIPAA, and #SOC2 without sacrificing speed. It's time to secure your software supply chain for good (and without the copious spreadsheets).

Sign up today https://events.chainguard.dev/02c6031d-d65b-417d-b62d-858f53c144f5/?utm_medium=referral&utm_source=anchore&utm_campaign=FY26-GL-LW-ChainguardxAnchoreWebinar2025

#DevSecOps #Cybersecurity #SupplyChainSecurity