<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: PCI DSS questions left unanswered</title>
	<link>http://www.tssci-security.com/archives/2007/09/21/pci-dss-questions-left-unanswered/</link>
	<description>top secret/secure computing information</description>
	<pubDate>Fri, 21 Nov 2008 17:23:59 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Zeev Solomonik</title>
		<link>http://www.tssci-security.com/archives/2007/09/21/pci-dss-questions-left-unanswered/#comment-1864</link>
		<dc:creator>Zeev Solomonik</dc:creator>
		<pubDate>Wed, 03 Oct 2007 12:12:03 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/09/21/pci-dss-questions-left-unanswered/#comment-1864</guid>
		<description>Dear colleagues,

I would like to inform you that on September 2007 we released an updated version of PTA Professional Edition (1.54 - build 1201) with major usability improvements. The latest version fully supports the PCI DSS 1.1 standard.

PTA – Practical Threat Analysis - is a quantitative method and a software tool that enables you to model the security perimeter of you business, identify threats on an asset-by-asset basis and evaluate the overall risk to the system. The risk level, potential damage and countermeasures required are all presented in real financial values. PTA calculates the level of risk and the available mitigation. It advises on the most cost-effective way to mitigate threats and reduce the risk.

PTA is free-of-charge for students, researchers, software developers and independent security consultants. You are invited to review the latest version's new features and download a free copy of the software from the following link: 

http://www.ptatechnologies.com

PTA fully supports the PCI DSS 1.1 standard. Download a free PTA for PCI DSS security library from the following url:

http://www.ptatechnologies.com/?action=documents



Feel free to introduce PTA to your professional colleagues - it is our contribution to the security community. I'll be happy to have your comments and answer your questions on any issue.

Regards,

Zeev Solomonik
R&#38;D - PTA Technologies
http://www.ptatechnologies.com
zeev_at_ptatechnologies_dot_com
&lt;a href="http://www.ptatechnologies.com" rel="nofollow"&gt;http://www.ptatechnologies.com&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Dear colleagues,</p>
<p>I would like to inform you that on September 2007 we released an updated version of PTA Professional Edition (1.54 - build 1201) with major usability improvements. The latest version fully supports the PCI DSS 1.1 standard.</p>
<p>PTA – Practical Threat Analysis - is a quantitative method and a software tool that enables you to model the security perimeter of you business, identify threats on an asset-by-asset basis and evaluate the overall risk to the system. The risk level, potential damage and countermeasures required are all presented in real financial values. PTA calculates the level of risk and the available mitigation. It advises on the most cost-effective way to mitigate threats and reduce the risk.</p>
<p>PTA is free-of-charge for students, researchers, software developers and independent security consultants. You are invited to review the latest version&#8217;s new features and download a free copy of the software from the following link: </p>
<p><a href="http://www.ptatechnologies.com"  onclick="javascript:urchinTracker ('/outbound/comment/www.ptatechnologies.com');">http://www.ptatechnologies.com</a></p>
<p>PTA fully supports the PCI DSS 1.1 standard. Download a free PTA for PCI DSS security library from the following url:</p>
<p><a href="http://www.ptatechnologies.com/?action=documents"  onclick="javascript:urchinTracker ('/outbound/comment/www.ptatechnologies.com');">http://www.ptatechnologies.com/?action=documents</a></p>
<p>Feel free to introduce PTA to your professional colleagues - it is our contribution to the security community. I&#8217;ll be happy to have your comments and answer your questions on any issue.</p>
<p>Regards,</p>
<p>Zeev Solomonik<br />
R&amp;D - PTA Technologies<br />
<a href="http://www.ptatechnologies.com"  onclick="javascript:urchinTracker ('/outbound/comment/www.ptatechnologies.com');">http://www.ptatechnologies.com</a><br />
zeev_at_ptatechnologies_dot_com<br />
<a href="http://www.ptatechnologies.com"  onclick="javascript:urchinTracker ('/outbound/comment/www.ptatechnologies.com');">http://www.ptatechnologies.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Danny Lieberman</title>
		<link>http://www.tssci-security.com/archives/2007/09/21/pci-dss-questions-left-unanswered/#comment-1863</link>
		<dc:creator>Danny Lieberman</dc:creator>
		<pubDate>Wed, 03 Oct 2007 11:25:14 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/09/21/pci-dss-questions-left-unanswered/#comment-1863</guid>
		<description>Marcin,

You have made some excellent comments - especially the part about the ambiguity of a web application firewall versus a code review.

I don't know what the committee says but the short answer is that you cannot measure a security control's effectiveness based on a checklist or a vendor pitch.   A good database firewall like Imperva will cost $100K and take months to implement.  OTOH - a software security assessment with careful business impact analysis will probably give ANY merchant a lot more mileage.

We have found that Practical Threat Analysis is a good way to understand the threats to a business and do a PCI DSS 1.1 self-assessment and keep it up t date. The application is available as a free download - and we’d love to hear feedback from folks - you can download PTA PCI here - http://www.software.co.il/content/view/214/1/

Best regards
Danny</description>
		<content:encoded><![CDATA[<p>Marcin,</p>
<p>You have made some excellent comments - especially the part about the ambiguity of a web application firewall versus a code review.</p>
<p>I don&#8217;t know what the committee says but the short answer is that you cannot measure a security control&#8217;s effectiveness based on a checklist or a vendor pitch.   A good database firewall like Imperva will cost $100K and take months to implement.  OTOH - a software security assessment with careful business impact analysis will probably give ANY merchant a lot more mileage.</p>
<p>We have found that Practical Threat Analysis is a good way to understand the threats to a business and do a PCI DSS 1.1 self-assessment and keep it up t date. The application is available as a free download - and we’d love to hear feedback from folks - you can download PTA PCI here - <a href="http://www.software.co.il/content/view/214/1/"  onclick="javascript:urchinTracker ('/outbound/comment/www.software.co.il');">http://www.software.co.il/content/view/214/1/</a></p>
<p>Best regards<br />
Danny</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.589 seconds -->
