Stay PCI DSSโCompliant
๐ต ๐๐ง๐ง๐ฎ๐๐ฅ ๐๐๐ ๐๐๐ ๐๐ก๐๐๐ค๐ฅ๐ข๐ฌ๐ญ: https://outpost24.com/blog/pci-dss-compliance-checklist/
@adlerweb ja, absolutes unding!
#PCIDSS sagt neinโฆ
Stay PCI DSSโCompliant
๐ต ๐๐ง๐ง๐ฎ๐๐ฅ ๐๐๐ ๐๐๐ ๐๐ก๐๐๐ค๐ฅ๐ข๐ฌ๐ญ: https://outpost24.com/blog/pci-dss-compliance-checklist/
@pastelfluffyfox it's also a trap at best and can be used to frame the user of said details as #carding #fraudster!
NEVER EVER use someone elses' card without authorization and having that being allowed by the card issuer.
So at best someone violated #PCIDSS and their card issuer's ToS'es but most likely they either want to track you and/or frame you for #CreditCard fraud!

@xeraa Das Problem ist auch Graylog. Wir hรคngen an Graylog 6.0.14, weil das die letzte Version ist, die mit dem ELK 7.10 zusammenarbeitet. Fรผr Graylog 6.1 braucht es dann eine sehr aufwende ELK / OpenSearch Migration und die bringt Probleme mit sich. Mein Kollege kรถnnte da genaueres sagen .. aber es war etwas nicht triviales.
Man hat sich dazu entschieden, die Speicherdauer auf 3 Monate zu reduzieren, da unser Syslog (rsyslog) das ganze Jahr speichert, um den #pcidss #auditor glรผcklich zu machen.
Parallel wird geschaut, #victorialogs parallel laufen zu lassen, da der nur einen Bruchteil an Kapazitรคt in Anspruch nimmt.
Ransomware doesnโt just shut down systems โ it triggers compliance violations.
๐๐๐ฃ๐ฅ deadlines. ๐๐๐ฃ๐๐ reporting. ๐ฃ๐๐-๐๐ฆ๐ฆ investigations.
If employees delay reporting, the legal risk multiplies.
Read more: https://threatcop.com/blog/how-ransomware-threatens-compliance/
#Ransomware #CyberCompliance #GDPR #HIPAA #PCIDSS #CyberRisk #DataProtection #PeopleSecurity #InformationSecurity
@neurovagrant @dangoodin @mttaggart @Em0nM4stodon personally, I'd say no #US company can make any privacy claims by design because #CloudAct exists and that applies to everyone (regardless if #ClosedAI or #Signal) having personnel, office, infrastructure or offering services from within the #USA.
#NotLegalAdvice but Cloud Act is irreconcileable with any #privacy & #dataProtection laws, not just #GDPR & #BDSG, but even #HIPAA & #PCIDSS!
@[email protected] well, #CloudAct says they'll have ti hand over *any data they have* - *even without a duely issued warrant*โฆ #USpol #NotLegalAdvice #privacy #AI #AIslop #Enshittification #OpenAI #ClosedAI #AIbubble #DataProtection
๐๐จ๐ฆ๐ฉ๐ฅ๐ข๐๐ง๐๐ ๐๐ซ๐๐ฉ๐ฉ๐๐ ๐๐ฉ ๐๐๐๐จ๐ซ๐ ๐๐๐๐ซ-๐๐ง๐
If PCI compliance isnโt complete, now is the time to close it.
Our team delivers fully managed PCI DSS scans in 24โ48 hours, designed for busy retail and ecommerce environments.
โ No last-minute chaos.
โ No January carry-over.
โ Get your PCI requirements done: https://outpost24.com/products/pci/
GRC rarely feels like โgovernance, risk, and complianceโ and more like alphabet soup with lawyers attached.
I wrote up how I approach GRC as an Associate CCISO: one risk-based program mapped to HIPAA, PCI DSS, NIST CSF, FTC Safeguards, and NIS2 instead of five separate nightmares.
#GRC #CyberSecurity #InfoSec #Compliance #HIPAA #PCIDSS #NISTCSF #NIS2
Chase account tells me that #Animoto is storing my payment card information despite me closing the account. I reached out to them, and they confirmed my account has been closed. That is NOT why I contacted them. I contacted them because my card company believes they are still holding onto my payment information. I do not know how they know that, but apparently they do, and it shows on the security page at Chase. Chase says they cannot remove it and I must contact the merchant.
@jackyan Personally I tend to literally block entire ASNs whenever possible.
Obviously #PCIDSS and @bsi standards do call for "best practises" and for a bona-fide payment processor, blocking known proxies and hosters is basically standard procedure, as there's no scenario why a customer would use a credit card over #aws, #Azure or #GCP instead of their (residential or mobile) internet connection.