Archive for the ‘PCI’ Category

In the second of a two-part series, VPN Haus talks to PCI compliance expert Anton Chuvakin about cloud compliance and the prevalence of the “it won’t happen to my company” attitude. Last week, we spoke to Chuvakin about the way the industry has misunderstood – and undervalued – PCI standards. VPN Haus: You’ve mentioned that [...]

In the first of a two-part series, VPN Haus talks to PCI compliance expert Anton Chuvakin about the way the industry has misunderstood – and undervalued – PCI standards. VPN Haus: You’ve noted that PCI standards were intended to provide a minimum foundation of security, but the standards are instead treated like an upper limit. [...]

We’re following a great discussion on LinkedIn as to where to keep a VPN gateway – in the DMZ or on the LAN directly. Pros and cons are argued for both sides (mostly pro-DMZ) and we’d like to hear your views on this debate. The views split over admin setup issues and effective security. Placing [...]

More on PCI DSS

Posted: January 7, 2009 by vpnhaus in PCI, Posts

Pursuant to our recent discussion of PCI DSS issues, we wanted to spotlight another great resource: Payment Card Security & IT Controls Explained James DeLuccia is a security and compliance expert focusing on PCI DSS, and has authored a book on the subject: IT Compliance and Controls: Best Practices for Implementation. His site examines PCI [...]

PCI DSS VPN issues

Posted: December 17, 2008 by vpnhaus in PCI, Posts

Received an interesting message from an end user the other day… We are a large website that deals with a user’s credit card data and therefore must be PCI (Payment Card Industry) compliant.  Some of our workstations are running Windows 2008 Server 64-bit which the Cisco VPN client doesn’t support. However, your NCP VPN client [...]