There is a big different between compliance and security. The PCI-DSS (Payment Council Industry Data Security Standard) is the measure against which e-commerce security is measured and it is now in the process of gearing up for a major update at the end of the year.. Ahead of that update, The PCI Security Standards Council (PCI SSC) has issued new guidance on how organizations can better secure themselves. "A lot of the exploits we're seeing today are older exploits that should not still be happening," said Bob Russo, general manager, PCI SSC. "This set of guidelines is an attempt by the community at large to make sure that people have guidance." The link for this article located at eSecurity Planet is no longer available. . The PCI Security Standards Council has released updated recommendations for businesses to strengthen their data protection measures prior to the updates in PCI-DSS 3.0.. PCI DSS Compliance, Data Security, E-commerce Security. . LinuxSecurity.com Team
Analyst firm Gartner has dismissed a tightening of security rules for US government agencies as a mere "public relations response" to recent high-profile incidents. . During a burglary in May, thieves stole a laptop containing confidential information on 26.5 million veterans and military personal from the home of an employee for the Veterans Authority. The link for this article located at Personal Computer World is no longer available. . During a burglary in May, thieves stole a laptop containing confidential information on 26.5 million. analyst, gartner, dismissed, tightening, security, rules, government, agencies. . Brittany Day
A proposal to create an association to represent the interests of hackers and vulnerability researchers is gaining support, a security expert said Wednesday. The group, which would be geared toward researchers and not software vendors, would provide guidelines on vulnerability disclosures . . . . A proposal to create an association to represent the interests of hackers and vulnerability researchers is gaining support, a security expert said Wednesday. The group, which would be geared toward researchers and not software vendors, would provide guidelines on vulnerability disclosures and would lobby against legislation that could stifle security researchers' ability to tinker with software. Nearly three-dozen people have pledged financial support to help get the yet-unnamed group started, said Thor Larholm, senior security researcher for PivX Solutions. "Initially, what has disturbed me was all the special-interest organisations created by vendors for vendors," he said. "We want to do something for security researchers, and it's not just about disclosure policy, but about helping and supporting The link for this article located at ZDNet is no longer available. . A suggestion to establish a coalition dedicated to advocating for the hacker community and supporting initiatives related to vulnerability discovery.. Hackers Union, Cybersecurity Advocacy, Vulnerability Research, Security Researchers. . Anthony Pell
Cyber-liberty experts are frustrated that the Home Office consultation paper offers no guidelines on the legitimate interception of communications. Privacy experts have slammed the Home Office's draft Code of Practice for accessing communications data as a nebulous attempt . . . . Cyber-liberty experts are frustrated that the Home Office consultation paper offers no guidelines on the legitimate interception of communications. Privacy experts have slammed the Home Office's draft Code of Practice for accessing communications data as a nebulous attempt to justify the Regulation of Investigatory Powers Act (RIPA). The draft Code of Practice addresses the most controversial part of RIPA, which is expected to come into force later this year - it regulates monitoring of electronic communications such as email messages. At the centre of the controversy is the power that RIPA gives to law enforcement officers to monitor email communications. The link for this article located at ZDNet UK is no longer available. . Digital freedom advocates express frustration over the Home Office's lack of clarity in its consultation on monitoring policies.. Data Privacy Guidelines, Communication Surveillance, RIPA Regulation. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.