SPIguard Blog
Find your PCI validation level
If you want to know what your PCI validation level is, Siva has put together a small app that will ask you some questions and let you know what your level is.
Please note that you need to get the result confirmed. The app is just meant to be a guideline. There might be special situations that might dictate what your PCI validation level is.
Roles and responsibilities in a PA DSS assessment
When we start an engagement (PA DSS, PCI DSS, Security consulting), we try to let our clients know what SPIguard’s role is in it. All parties in the engagement should be on the same page regarding their roles and responsibilities to avoid confusion and frustration.
Read more
Version 2 of PCI and PA DSS Requirements
Version 2.0 of both the PCI and PA DSS requirements were published Oct 28, 2010. They take effect on Jan 11, 2011. PCI and PA DSS compliance submissions can still be made under the previous version till December 2011, after which submissions will need to be under version 2.0.
Read more
Chip rollout delayed
Visa and MasterCard have extended their plans to fully implement chip technology from October 2010, to March 31, 2011 as merchants are not fully ready to adopt the technology.
Read more
New version of PCI and PA DSS to be released
The new versions (v2.0) of PCI and PA DSS standards will be officially released Oct 28, 2010 and will become effective Jan 1, 2011.
Read more
Compromised Pin Entry Devices delisted
Effective immediately, Ingenico i3070MP01 and i3070EP01 are no longer approved PED terminals and have been removed from the Payment Card Industry Security Standards Council (PCI SSC) approval list. Ingenico i3070MP01 and i3070EP01 point-of-sale (POS) PIN-entry devices (PEDs) have been used in tampering and skimming attacks to capture PIN and magnetic stripe card data.
Read more
PA-DSS – Things to remember
The deadline for PA-DSS (in North America) is approaching (June 30, 2010) and payment application vendors are rushing to get their applications validated.
Read more
Catherine’s new book
Catherine Pagliaro, SPIguard CEO, has authored a chapter on security in a new book called “Internet Management for Nonprofits”.
Read more
March 2010 CIPS-SIG Meeting
The CIPS Vancouver Security SIG “wargames” meeting was held at Langara college. There were hacking presentations on browser vulnerabilities and cracking WPA.
Read more
Wyndham hotels hacked
Wyndham hotels, which also operates Days Inn, Ramada and Super 8 motels, reported another break in, resulting in customer card data and magnetic stripe data being stolen.
Read more


