<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Payment Card Industry (PCI) Blog</title>
	<atom:link href="http://www.pciassessment.org/pci-blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pciassessment.org/pci-blog</link>
	<description>The latest news surrounding PCI DSS Compliance, courtesy NDB Advisory</description>
	<lastBuildDate>Wed, 02 May 2012 16:13:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>PCI DSS Experts &#124; Have Questions? Call QSA Charles Denyer of NDB Advisory</title>
		<link>http://www.pciassessment.org/pci-blog/pci-dss-experts-have-questions-call-qsa-charles-denyer-of-ndb-advisory/</link>
		<comments>http://www.pciassessment.org/pci-blog/pci-dss-experts-have-questions-call-qsa-charles-denyer-of-ndb-advisory/#comments</comments>
		<pubDate>Wed, 02 May 2012 16:13:12 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[PCI News]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[payment card industry data security standards]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[PCI DSS experts]]></category>

		<guid isPermaLink="false">http://www.pciassessment.org/pci-blog/?p=237</guid>
		<description><![CDATA[The PCI DSS experts at NDB Advisory can assist with your all needs regarding compliance with the Payment Card Industry Data Security Standards (PCI DSS) provisions.  We all know PCI can be an arduous, expensive and time-consuming endeavor, but with able guidance from PCI DSS experts, you can achieve compliance in an efficient and cost-effective [...]]]></description>
			<content:encoded><![CDATA[<p>The <a title="PCI DSS experts" href="http://pciassessment.org/contact.php" target="_blank"><strong>PCI DSS experts</strong></a> at NDB Advisory can assist with your all needs regarding compliance with the Payment Card Industry Data Security Standards (PCI DSS) provisions.  We all know PCI can be an arduous, expensive and time-consuming endeavor, but with able guidance from <a title="PCI DSS experts" href="http://pciassessment.org/contact.php" target="_blank"><strong>PCI DSS experts</strong></a>, you can achieve compliance in an efficient and cost-effective manner.</p>
<p>Charles Denyer, who holds both the PCI-QSA and PA-QSA designations, can answer all your pressing questions regarding PCI DSS compliance, and can also provide a sustainable, scalable PCI roadmap consisting of a number of predefined phases and steps. Charles can also help assist in many other ways, such as the following:</p>
<p>1. Provide policy and procedure writing for PCI along with supplying your organization with all the templates needed to develop well-written PCI documentation.</p>
<p>2. Assemble a list of recommended, cost-effective open-source tools for PCI compliance. That&#8217;s right, there&#8217;s no need to spend tens of thousands of dollars on regulatory compliance tools when a number of high-quality open source tools are readily available. Charles has developed an extensive list of tools that he can share with you.</p>
<p>3.Discuss with you the Top 10 PCI issues that cause constraints, compliance delays and many other problems for organizations seeking to become PC compliant. And yes, there&#8217;s quite a few.</p>
<p>4. Assist with filing your Report on Compliance (ROC) to VISA along with also obtaining clearance to be listed on the highly coveted VISA service provider list. This alone can be a very daunting challenge, sometimes taking months for organizations who are unsure of how to proceed. NDB Advisory&#8217;s PCI DSS experts, such as Charles Denyer, have successfully helped a number of organizations with the VISA certification process.</p>
<p>Give Charles Denyer a call at <strong>1-800-277-5415, ext. 705</strong> or email him directly at cdenyer@ndbcpa.com.  Charles is one of NDB Advisory&#8217;s most trusted <a title="PCI DSS Experts" href="http://pciassessment.org/contact.php" target="_blank"><strong>PCI DSS Experts</strong></a> and can help assist organizations with Payment Card Industry Data Security Standards (PCI DSS) compliance.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pciassessment.org/pci-blog/pci-dss-experts-have-questions-call-qsa-charles-denyer-of-ndb-advisory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PA DSS Questions? Call PA QSA Charles Denyer at 1-800-277-5415, ext. 705</title>
		<link>http://www.pciassessment.org/pci-blog/pa-dss-questions-call-pa-qsa-charles-denyer-at-1-800-277-5415-ext-705/</link>
		<comments>http://www.pciassessment.org/pci-blog/pa-dss-questions-call-pa-qsa-charles-denyer-at-1-800-277-5415-ext-705/#comments</comments>
		<pubDate>Tue, 24 Apr 2012 16:52:45 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[PCI News]]></category>
		<category><![CDATA[pa dss questions]]></category>

		<guid isPermaLink="false">http://www.pciassessment.org/pci-blog/?p=234</guid>
		<description><![CDATA[Have PA DSS questions specific to the Payment Application Data Security Standards (PA DSS) for which you need answers for? If so, call Charles Denyer of NDB Advisory at 1-800-277-5415, ext. 705 as Charles will spend the needed time with you to discuss the complexities regarding PA DSS compliance. As you may very well know, [...]]]></description>
			<content:encoded><![CDATA[<p>Have <strong>PA DSS questions</strong> specific to the Payment Application Data Security Standards (PA DSS) for which you need answers for? If so, call Charles Denyer of NDB Advisory at 1-800-277-5415, ext. 705 as Charles will spend the needed time with you to discuss the complexities regarding PA DSS compliance.</p>
<p>As you may very well know, payment applications that store, process, or transmit cardholder data as part of authorization or settlement, and that are sold, distributed, or licensed to third parties must become PA DSS compliant.</p>
<p>And here are some other notable points you might want to remember about PA DSS compliance:</p>
<ul>
<li>Use of a PA DSS compliant application by itself does not make an organization PCI DSS compliant, and that&#8217;s because an application must be implemented into a PCI DSS compliant environment.</li>
<li>The requirements for PA DSS are actually derived from the PCI DSS standards themselves.</li>
<li>PA DSS has thirteen (13) Requirements and supporting assessment procedures along with two (2) critically important appendices.</li>
<li>Appendix A discusses the content and overall requirements for the actual PA DSS Implementation Guide (IG) specific to the application itself.</li>
<li>Appendix B includes measures regarding the testing of an actual PA DSS application in a laboratory environment.</li>
<li>One of the main goals of PA DSS is to allow applications to further enable, rather than prevent PCI compliance, by the companies who actually implement a given application. Thus, developing software that requires customers to disable security features that are required by the actual PCI DSS standards, is not recommended.</li>
<li>PA DSS compliance does apply to payment applications that are generally sold &#8220;off the shelf&#8221; with minimal customization.</li>
</ul>
<p>This is just a small sample of issues you&#8217;ll need to know about regarding PA DSS compliance.  Thus, if you have PA DSS questions, call the experts at NDB Advisory and ask to speak directly with PA QSA Charles Denyer. Additionally, you can email your <strong>PA DSS questions</strong> to him at cdenyer@ndbcpa.com</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pciassessment.org/pci-blog/pa-dss-questions-call-pa-qsa-charles-denyer-at-1-800-277-5415-ext-705/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PA DSS QSA &#124; Competitive, Fixed Fees from a PA-QSA</title>
		<link>http://www.pciassessment.org/pci-blog/pa-dss-qsa-competitive-fixed-fees-from-a-pa-qsa/</link>
		<comments>http://www.pciassessment.org/pci-blog/pa-dss-qsa-competitive-fixed-fees-from-a-pa-qsa/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 13:46:01 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[PCI News]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[PA DSS QSA]]></category>
		<category><![CDATA[payment application data security standard]]></category>
		<category><![CDATA[pci]]></category>

		<guid isPermaLink="false">http://www.pciassessment.org/pci-blog/?p=232</guid>
		<description><![CDATA[Need a PA DSS QSA for assistance in certifying your payment application, and one that can provide you with a competitively priced, fixed fee? Then call PCI QSA &#124; PA QSA Charles Denyer at 1-800-277-5415, ext. 705 or email him at cdenyer@ndbcpa.com.  Charles and his staff at NDB Advisory have years of experience performing assessment [...]]]></description>
			<content:encoded><![CDATA[<p>Need a <a title="PA DSS QSA" href="http://pciassessment.org/index.php" target="_blank"><strong>PA DSS QSA</strong> </a>for assistance in certifying your payment application, and one that can provide you with a competitively priced, fixed fee? Then call PCI QSA | PA QSA Charles Denyer at 1-800-277-5415, ext. 705 or email him at <a href="mailto:cdenyer@ndbcpa.com">cdenyer@ndbcpa.com</a>.  Charles and his staff at <a title="PA DSS QSA" href="http://pciassessment.org/index.php" target="_blank">NDB Advisory</a> have years of experience performing assessment services for the payments industry, and can provide your organization with a comprehensive and efficient PA DSS certification process.</p>
<p>Payment applications that store, process, or transmit cardholder data as part of authorization or settlement, and that are sold, distributed, or licensed to third parties must become PA DSS compliant.  The sheer growth of e-commerce systems, Software as a Service (SaaS) platforms and many other web-facing technologies have propelled many vendors into the regulatory compliance spotlight, particularly that of Payment Application Data Security Standards (PA DSS) compliance. You’ll need to consult with a proven <a title="PA DSS QSA" href="http://www.pciassessment.org" target="_blank"><strong>PA DSS QSA</strong></a> for helping you understand the unique dynamics of PA DSS compliance, particularly scope assessment, technical requirements, and many other PA DSS mandates.</p>
<p>In short, if you’re a software vendor with a payment application, you’ll need to become PA DSS compliant, which means being responsible for the following measures:</p>
<ul>
<li>Creating a PA DSS compliant payment application that facilitates and does not prevent their own customers’ PCI DSS compliance (Please keep in mind that your payment application cannot require an implementation or configuration setting that violates a PCI DSS requirement).</li>
<li>Following the best practices of the <a title="PCI DSS " href="http://www.pciassessment.org/12-pci-dss-requirements.php" target="_blank">PCI DSS requirements</a>, if, you, the software vendor, store, process, or transmit cardholder data.</li>
<li>Creating a PA DSS Implementation Guide, specific to each application, in accordance with the requirements in the Payment Application Data Security Standard Appendix A.</li>
<li>Educating customers, resellers, and integrators and all other applicable parties on the importance of the installation and configuration of the payment application in a PCI DSS-compliant manner.</li>
<li>Ensuring your payment application meet PA-DSS requirements by successfully passing a PA-DSS review as specified in PCI PA DSS Requirements and conducted by a PA DSS QSA.</li>
<li>Providing customers with a copy of the validated payment application’s PA-DSS Implementation Guide.</li>
</ul>
<p>Call today and speak directly with PCI QSA | PA QSA Charles Denyer at 1-800-277-5415, ext. 705 or email him directly at <a href="mailto:cdenyer@ndbcpa.com">cdenyer@ndbcpa.com</a>.  Charles will take the time to discuss your PA DSS needs along with any other general Payment Card Industry Data Security Standards (PCI DSS) questions, comments, or concerns you or your organization may have.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pciassessment.org/pci-blog/pa-dss-qsa-competitive-fixed-fees-from-a-pa-qsa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PA DSS Assessments &#124; Fixed Fee Pricing from a PA-QSA &#124; NDB Advisory</title>
		<link>http://www.pciassessment.org/pci-blog/pa-dss-assessments-fixed-fee-pricing-from-a-pa-qsa-ndb-advisory/</link>
		<comments>http://www.pciassessment.org/pci-blog/pa-dss-assessments-fixed-fee-pricing-from-a-pa-qsa-ndb-advisory/#comments</comments>
		<pubDate>Wed, 14 Mar 2012 16:30:41 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[PCI News]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[PA DSS Assessments]]></category>
		<category><![CDATA[pa-qsa]]></category>

		<guid isPermaLink="false">http://www.pciassessment.org/pci-blog/?p=228</guid>
		<description><![CDATA[PA DSS assessments are fast becoming a mainstay in today’s growing e-commerce business environments. Now more than ever, credit card information is being captured and transmitted all across the internet, forcing many applications to comply with the stringent requirements set forth in the Payment Application Data Security Standards (PA DSS) provisions.  What’s more, PA-DSS is [...]]]></description>
			<content:encoded><![CDATA[<p><a title="PA DSS | PCI DSS Auditors" href="http://www.pciassessment.org"><strong>PA DSS assessments</strong></a> are fast becoming a mainstay in today’s growing e-commerce business environments. Now more than ever, credit card information is being captured and transmitted all across the internet, forcing many applications to comply with the stringent requirements set forth in the Payment Application Data Security Standards (PA DSS) provisions.  What’s more, PA-DSS is different from PCI-DSS compliance, as only a Payment Application Qualified Security Assessor (PA-QSA) can certify one’s payment application.</p>
<p>Additionally, PA DSS assessments are also earning a reputation as complex, expensive, and time-consuming engagements, forcing organizations to spend considerable time and effort in hopes of achieving compliance.  Organizations need to be aware that PA DSS compliance is much more than simply checking the box on a number of prescriptive requirements, rather, it take a collaborative effort between all parties, working closely together in building, and ultimately validating a payment application and its supporting infrastructure.</p>
<p><a title="PA DSS | PCI DSS" href="http://www.pciassessment.org"><strong>PA DSS assessments</strong></a> are here to stay, thus turn to a trusted industry leader in providing PA DSS compliance, and that’s Charles Denyer, who holds both the PCI-QSA and PA-QSA designations as awarded by the Payment Card Industry Security Standards Council (PCI SSC) in Wakefield, Massachusetts.  Charles and his staff at NDB Advisory have spent years helping organizations with their growing regulatory compliance needs, and Mr. Denyer can provide your organization with a fixed fee pricing model for your PA DSS assessments. <strong>Call Charles today at 1-800-277-5415, ext. 705</strong> or email him directly at <a href="mailto:cdenyer@ndbcpa.com">cdenyer@ndbcpa.com</a>. He’ll be happy to speak with you about PA DSS assessments,  costs involved, and any other issues you want to discuss.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pciassessment.org/pci-blog/pa-dss-assessments-fixed-fee-pricing-from-a-pa-qsa-ndb-advisory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Compliance Audits offered at Competitive, Fixed Fee Rates from NDB Advisory &#124; Call 1-800-277-5415, ext. 705</title>
		<link>http://www.pciassessment.org/pci-blog/pci-compliance-audits-offered-at-competitive-fixed-fee-rates-from-ndb-advisory-call-1-800-277-5415-ext-705/</link>
		<comments>http://www.pciassessment.org/pci-blog/pci-compliance-audits-offered-at-competitive-fixed-fee-rates-from-ndb-advisory-call-1-800-277-5415-ext-705/#comments</comments>
		<pubDate>Tue, 06 Mar 2012 19:02:31 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[PCI News]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[fixed fees]]></category>
		<category><![CDATA[PCI Compliance audits]]></category>
		<category><![CDATA[PCI Level 1 assessment]]></category>

		<guid isPermaLink="false">http://www.pciassessment.org/pci-blog/?p=226</guid>
		<description><![CDATA[PCI compliance audits are a mainstay in today’s world of regulatory compliance, and as such, many entities are being required to undergo an annual Level 1 on-site assessment by a Qualified Security Assessor (QSA).  What your organization needs is a seasoned veteran in the payments industry, one who clearly understands the scope of an on-site [...]]]></description>
			<content:encoded><![CDATA[<p><a title="PCI Compliance Audits" href="http://pciassessment.org/"><strong>PCI compliance audits</strong></a> are a mainstay in today’s world of regulatory compliance, and as such, many entities are being required to undergo an annual Level 1 on-site assessment by a <a title="PCI | NDB | QSA" href="http://pciassessment.org/"><strong>Qualified Security Assessor</strong></a> (QSA).  What your organization needs is a seasoned veteran in the payments industry, one who clearly understands the scope of an on-site assessment, and one that can deliver it in an efficient, cost-effective manner; all in an agreed-upon fixed fee. That’s NDB Advisory, a nationally recognized provider of Level 1 on-site assessments for PCI, or more commonly known as PCI compliance audits.</p>
<p>NDB’s lead QSA, Mr. Charles Denyer, has spent years working in the payments industry and has developed a lock-step process for the entire on-site assessment process. It starts with a PCI compliance audit Readiness Assessment, followed by the issuance of a gap analysis, whereby you  correct any areas of remediation found, and move on to other areas of the assessment process, such as developing policies and procedures.</p>
<p><strong>Specifically, the NDB Advisory PCI Level 1 assessment process consists of the following phases:</strong></p>
<p>(1) PCI DSS Readiness Assessment</p>
<p>(2) Policy &amp; Procedure (P&amp;P) Analysis and Development</p>
<p>(3) Remediation Activities</p>
<p>(4) Vulnerability Scanning Services</p>
<p>(5) Penetration Testing Services</p>
<p>(6) PCI DSS Assessment | on-site Fieldwork</p>
<p>(7) Issuance of “Report on Compliance” (ROC) and any other necessary reporting deliverables</p>
<p>(8) Closing Meeting and general auditor comments issued to client</p>
<p>In summary, it’s a proven methodology that’s been constantly refined over the last four years, resulting in a highly efficient and cost-effective assessment process for any entity seeking to undergo an on-site PCI compliance audit in accordance with the Payment Card Industry Data Security Standards (PCI DSS) provisions.</p>
<p>Want to learn more about NDB’s PCI compliance audit services? Then contact PCI-QSA Charles Denyer directly at 1-800-277-5415, ext. 705 or email him at <a href="mailto:cdenyer@ndbcpa.com">cdenyer@ndbcpa.com</a>.  Charles will be take the time to discuss you PCI needs, the scope of your engagement, along with providing you a competitive, fixed fee proposal.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pciassessment.org/pci-blog/pci-compliance-audits-offered-at-competitive-fixed-fee-rates-from-ndb-advisory-call-1-800-277-5415-ext-705/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PA DSS Certification and 5 Critical Points you Need to Know &#124; NDB Advisory</title>
		<link>http://www.pciassessment.org/pci-blog/pa-dss-certification-and-5-critical-points-you-need-to-know-ndb-advisory/</link>
		<comments>http://www.pciassessment.org/pci-blog/pa-dss-certification-and-5-critical-points-you-need-to-know-ndb-advisory/#comments</comments>
		<pubDate>Mon, 05 Dec 2011 15:22:23 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[Implementation Guide]]></category>
		<category><![CDATA[Laboratory Testing]]></category>
		<category><![CDATA[PA]]></category>
		<category><![CDATA[pa dss]]></category>
		<category><![CDATA[PA DSS certification]]></category>
		<category><![CDATA[pa-qsa]]></category>

		<guid isPermaLink="false">http://www.pciassessment.org/pci-blog/?p=222</guid>
		<description><![CDATA[PA DSS Certification is fast becoming a hot topic in today&#8217;s business environment, and for very good reason. Advances in technology have resulted in an explosion of Software as a Service (SaaS) vendors, e-commerce sites, along with many other web, mobile and other wireless portals and platforms that facilitate credit card transactions. As such, these [...]]]></description>
			<content:encoded><![CDATA[<p><a title="PCI DSS Auditors | PA DSS" href="http://www.pciassessment.org"><strong>PA DSS Certification</strong></a> is fast becoming a hot topic in today&#8217;s business environment, and for very good reason. Advances in technology have resulted in an explosion of Software as a Service (SaaS) vendors, e-commerce sites, along with many other web, mobile and other wireless portals and platforms that facilitate credit card transactions. As such, these very applications that are responsible for conducting authorization and settlement functions, and that are also being sold, licensed, or distributed to other parties, will require PA DSS certification.  As such, PCI-QSA and PA-QSA veteran Charles Denyer of NDB Advisory provides 5 critical &#8220;must know&#8221; points for successfully understanding PA DSS certification.</p>
<p>1. <strong>Understanding the relationship between PA-DSS and PCI-DSS.</strong>  In short, becoming PA-DSS compliant does NOT make an entity PCI-DSS compliant.  Remember, the actual PA-DSS certified application will then still need to be implemented into a PCI-DSS compliant environment, either yours or the entity or entities that are using your PA-DSS application.</p>
<p>2. <strong>Determining if your application is truly in scope for PA-DSS.</strong> Want to know if your application is in scope and required to undergo PA-DSS certification?  Read pages 5 and 6 of the PCI PA-DSS Requirements and Security Assessment Procedures, v.2.0, which can be found at pcisecuritystandards.org.  These two (2) pages give excellent examples and explanations of what constitutes and does not constitute a requirement for PA-DSS certification.</p>
<p>3. <strong>The importance of the two PA-DSS appendices</strong>, which are the (a) Implementation Guide (IG) and the (b) Laboratory instructions for testing and validating an actual live environment of the application itself.  Let&#8217;s not forget the two (2) of the most important components of PA-DSS compliance are actually the Appendix A and B. These appendices are not simple instructions, afterthoughts, or additional optional guidelines, rather, they speak to the heart of PA-DSS compliance, thus you&#8217;d be wise to learn more about them. In short, Appendix calls for an Implementation guide to be in place, while Appendix B requires a number of activities for ensuring that the actual payment application undergoes an extremely thorough and comprehensive set of tests in an actual laboratory environment.  You can obtain the actual PA DSS requirements guidelines at <a title="PA DSS | PCI DSS" href="https://www.pcisecuritystandards.org/">pcisecuritystandards.org</a>.</p>
<p>4. <strong>Understanding the need for policies and procedures.</strong> Sure, the vast majority of PA-DSS certification is technical and can be challenging, but don&#8217;t forget that a fair number of policies and procedures will also need to written. Contacting a highly-qualified PA-QSA will be most helpful in this situation, as they should have templates to provide your organization.</p>
<p>5. <strong>Recognizing that a PA-DSS assessment is significantly different from a PCI-DSS assessment.</strong> Though it would be a stretch to call them oil and water, there are significant and meaningful difference between the two. Remember, PA-DSS certification is about the application specifically, while PCI-DSS compliance is a higher-level, broader reaching mandate that covers an organization, or a specific platform within an organization that processes, stores, or transmits cardholder data.</p>
<p>Call today and speak directly with PCI-QSA | PA-QSA <strong>Charles Denyer at 1-800-277-5415, ext. 705</strong> or email him directly at <strong>cdenyer@ndbcpa.com</strong>.  Charles will take the time to discuss your PA-DSS certification needs along with any other general Payment Card Industry Data Security Standards (PCI DSS) questions, comments, or concerns you or your organization may have.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pciassessment.org/pci-blog/pa-dss-certification-and-5-critical-points-you-need-to-know-ndb-advisory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PA DSS Consulting Services offered by NDB Advisory at Competitive, Fixed Fee Pricing</title>
		<link>http://www.pciassessment.org/pci-blog/pa-dss-consulting-services-offered-by-ndb-advisory-at-competitive-fixed-fee-pricing/</link>
		<comments>http://www.pciassessment.org/pci-blog/pa-dss-consulting-services-offered-by-ndb-advisory-at-competitive-fixed-fee-pricing/#comments</comments>
		<pubDate>Fri, 21 Oct 2011 21:45:41 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[PCI News]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[pa dss]]></category>
		<category><![CDATA[PA DSS Consulting]]></category>
		<category><![CDATA[PA DSS Implementation Guide]]></category>
		<category><![CDATA[PA DSS Laboratory Requirements]]></category>
		<category><![CDATA[Payment Application Datat Security Standards]]></category>

		<guid isPermaLink="false">http://www.pciassessment.org/pci-blog/?p=217</guid>
		<description><![CDATA[PA DSS consulting services are a “must have” for organizations seeking to have their payment applications become Payment Application Data Security Standards (PA DSS) compliant.  In short, if you have a payment application that (1) facilitates authorization and settlement functions and (2) is sold, licensed or distributed to another party, then the application itself will [...]]]></description>
			<content:encoded><![CDATA[<p><strong>PA DSS consulting</strong> services are a “must have” for organizations seeking to have their payment applications become Payment Application Data Security Standards (PA DSS) compliant.  In short, if you have a payment application that (1) facilitates authorization and settlement functions and (2) is sold, licensed or distributed to another party, then the application itself will need to become PA DSS compliant.  The rise of payment applications coincides with the tremendous growth of numerous industries now their presence online along with e-commerce systems now permeating the Internet.  As a result, strict security requirements are now being enforced for these web-based applications, with the PA DSS framework leading the way for purposes of regulatory compliance.</p>
<p>What your organization needs is an experienced PA DSS consulting expert that has spent years in the payments industry and can provide your organization with a quality compliance assessment, and with a competitive, fixed-fee pricing model. That’s NDB Advisory, a nationally recognized boutique firm that is a Qualified Security Assessor Company (QSAC) as validated by the Payment Card Industry Security Standards Council (PCI SSC), and more importantly, a firm that employs both PCI and PA Qualified Security Assessors (QSA). The firm’s lead assessor is <strong>Mr. Charles Denyer</strong>, and individual with years of payments industry experience and who hold both PCI-QSA and PA-QSA designations.  Charles has worked with all types of organizations throughout a large number of industries and can assist you with all your PCI DSS and PA DSS compliance needs.  Notable accomplishments that Charles brings to the table with his PA DSS consulting services for NDB Advisory are the following:</p>
<p>•    Customized template to use exclusively as your &#8220;Implementation Guide&#8221;.<br />
•    Numerous PA DSS specific policy and procedures template developed by PCI-QSA | PA-QSA Charles Denyer.<br />
•    Competitive pricing structure for PA DSS assessments.</p>
<p>With thirteen (13) requirements and two (2) critically important appendices, PA DSS compliance can be a lengthy and arduous process, thus it’s vital you retain the services of a competent, well-known PA DSS consulting firm, such as NDB Advisory. And it’s just as important that the firm you hire has capable, well-trained PA DSS consulting experts such as Charles Denyer, who is both a PCI-QSA and a PA-QSA. Contact Charles directly at 1-800-277-5415, ext. 705 or email him at cdenyer@ndbcpa.com if you have questions regarding PCI DSS and PA DSS compliance.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pciassessment.org/pci-blog/pa-dss-consulting-services-offered-by-ndb-advisory-at-competitive-fixed-fee-pricing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PA DSS Compliance Fixed Fee Assessments for Payment Applications offered by NDB Advisory</title>
		<link>http://www.pciassessment.org/pci-blog/pa-dss-compliance-fixed-fee-assessments-for-payment-applications-offered-by-ndb-advisory/</link>
		<comments>http://www.pciassessment.org/pci-blog/pa-dss-compliance-fixed-fee-assessments-for-payment-applications-offered-by-ndb-advisory/#comments</comments>
		<pubDate>Mon, 10 Oct 2011 18:18:53 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[PCI News]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[pa dss]]></category>
		<category><![CDATA[pa-qsa]]></category>
		<category><![CDATA[payment application data security standard]]></category>
		<category><![CDATA[payment applications]]></category>

		<guid isPermaLink="false">http://www.pciassessment.org/pci-blog/?p=214</guid>
		<description><![CDATA[PA DSS compliance is a strict requirement for payment applications that store, process, or transmit cardholder data as part of authorization or settlement, and where these payment applications are sold, distributed, or licensed to third parties.  Simply stated, if your payment application conducts authorization and settlement functions and is also being used by other parties, [...]]]></description>
			<content:encoded><![CDATA[<p>PA DSS compliance is a strict requirement for payment applications that store, process, or transmit cardholder data as part of authorization or settlement, and where these payment applications are sold, distributed, or licensed to third parties.  Simply stated, if your payment application conducts authorization and settlement functions and is also being used by other parties, then the application itself will need to become PA DSS compliant.  PA DSS compliance can be an extremely lengthy, arduous process, consuming significant amount of time and resources from your organization. It’s thus paramount to utilize a trusted, nationally recognized payments consulting firm, one that is approved to issue both PCI DSS and PA DSS reports, that’s NDB Advisory.</p>
<p>Regarding the actual scope of a PA DSS assessment, it consists of thirteen (13) requirements along with two (2) critically important appendix sections. Within each of the 13 requirements are numerous sub-requirements that must be validated by a PA-QSA, an individual who is licensed to perform PA DSS assessments.  Additionally, the 2 appendix sections provide detailed information on the requirements for an Implementation Guide along with laboratory procedures for actually testing the applications and its supporting infrastructure. In short, the scope of a PA DSS assessment is generally considered very encompassing, as it’s much more than just the application itself.</p>
<p>NDB Advisory’s qualified and competent assessors, such as Charles Denyer, who holds the PA-QSA and PCI-QSA designation,  can provide your organization with a scalable, efficient assessment process, and one that include a competitive, fixed-fee for your PA DSS assessment.</p>
<p>Our industry leading PA DSS services include the following:</p>
<p>•    The use of our proprietary, highly sought after PA DSS compliance Implementation Guide template.<br />
•    Readily available policy and procedures template developed exclusively for PA-DSS compliance.<br />
•    Seasoned, veteran assessors with years of experience in the payments industry<br />
•    All at a competitive, fixed-fee price model.</p>
<p>Call today and speak directly with PCI-QSA | PA-QSA Charles Denyer at 1-800-277-5415, ext. 705 or email him directly at cdenyer@ndbcpa.com.  Charles will take the time to discuss your PA-DSS needs along with any other general Payment Card Industry Data Security Standards (PCI DSS) questions, comments, or concerns you or your organization may have.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pciassessment.org/pci-blog/pa-dss-compliance-fixed-fee-assessments-for-payment-applications-offered-by-ndb-advisory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI QSA Birmingham, Alabama Consulting Services offered by NDB Advisory</title>
		<link>http://www.pciassessment.org/pci-blog/pci-qsa-birmingham-alabama-consulting-services-offered-by-ndb-advisory/</link>
		<comments>http://www.pciassessment.org/pci-blog/pci-qsa-birmingham-alabama-consulting-services-offered-by-ndb-advisory/#comments</comments>
		<pubDate>Tue, 13 Sep 2011 19:28:24 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[PCI News]]></category>
		<category><![CDATA[alabama]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[Merchant]]></category>
		<category><![CDATA[Payment Card Industry Data Security Standards Compliance]]></category>
		<category><![CDATA[pci policy and procedures]]></category>
		<category><![CDATA[pci qsa birmingham al]]></category>
		<category><![CDATA[Service Provider]]></category>

		<guid isPermaLink="false">http://www.pciassessment.org/pci-blog/?p=200</guid>
		<description><![CDATA[Looking for a PCI QSA in Birmingham, AL to help assist with your Payment Card Industry Data Security Standards (PCI DSS) compliance needs? If so, then contact PCI QSA Charles Denyer of NDB Advisory at 1-800-277-5415, ext. 705 or email him at cdenyer@ndbcpa.com. Charles has worked with numerous organizations throughout the country regarding PCI compliance, [...]]]></description>
			<content:encoded><![CDATA[<p><!--[if gte mso 9]><xml> <o:OfficeDocumentSettings> <o:AllowPNG /> </o:OfficeDocumentSettings> </xml><![endif]--><!--[if gte mso 9]><xml> <w:WordDocument> <w:View>Normal</w:View> <w:Zoom>0</w:Zoom> <w:TrackMoves /> <w:TrackFormatting /> <w:PunctuationKerning /> <w:ValidateAgainstSchemas /> <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid> <w:IgnoreMixedContent>false</w:IgnoreMixedContent> <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText> <w:DoNotPromoteQF /> <w:LidThemeOther>EN-US</w:LidThemeOther> <w:LidThemeAsian>X-NONE</w:LidThemeAsian> <w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript> <w:Compatibility> <w:BreakWrappedTables /> <w:SnapToGridInCell /> <w:WrapTextWithPunct /> <w:UseAsianBreakRules /> <w:DontGrowAutofit /> <w:SplitPgBreakAndParaMark /> <w:DontVertAlignCellWithSp /> <w:DontBreakConstrainedForcedTables /> <w:DontVertAlignInTxbx /> <w:Word11KerningPairs /> <w:CachedColBalance /> </w:Compatibility> <m:mathPr> <m:mathFont m:val="Cambria Math" /> <m:brkBin m:val="before" /> <m:brkBinSub m:val="&#45;-" /> <m:smallFrac m:val="off" /> <m:dispDef /> <m:lMargin m:val="0" /> <m:rMargin m:val="0" /> <m:defJc m:val="centerGroup" /> <m:wrapIndent m:val="1440" /> <m:intLim m:val="subSup" /> <m:naryLim m:val="undOvr" /> </m:mathPr></w:WordDocument> </xml><![endif]--><!--[if gte mso 9]><xml> <w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"   DefSemiHidden="true" DefQFormat="false" DefPriority="99"   LatentStyleCount="267"> <w:LsdException Locked="false" Priority="0" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Normal" /> <w:LsdException Locked="false" Priority="9" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="heading 1" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8" /> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9" /> <w:LsdException Locked="false" Priority="39" Name="toc 1" /> <w:LsdException Locked="false" Priority="39" Name="toc 2" /> <w:LsdException Locked="false" Priority="39" Name="toc 3" /> <w:LsdException Locked="false" Priority="39" Name="toc 4" /> <w:LsdException Locked="false" Priority="39" Name="toc 5" /> <w:LsdException Locked="false" Priority="39" Name="toc 6" /> <w:LsdException Locked="false" Priority="39" Name="toc 7" /> <w:LsdException Locked="false" Priority="39" Name="toc 8" /> <w:LsdException Locked="false" Priority="39" Name="toc 9" /> <w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption" /> <w:LsdException Locked="false" Priority="10" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Title" /> <w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font" /> <w:LsdException Locked="false" Priority="11" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtitle" /> <w:LsdException Locked="false" Priority="22" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Strong" /> <w:LsdException Locked="false" Priority="20" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Emphasis" /> <w:LsdException Locked="false" Priority="59" SemiHidden="false"    UnhideWhenUsed="false" Name="Table Grid" /> <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text" /> <w:LsdException Locked="false" Priority="1" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="No Spacing" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 1" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 1" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 1" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 1" /> <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision" /> <w:LsdException Locked="false" Priority="34" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="List Paragraph" /> <w:LsdException Locked="false" Priority="29" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Quote" /> <w:LsdException Locked="false" Priority="30" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Quote" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 1" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 1" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 1" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 1" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 1" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 2" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 2" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 2" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 2" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 2" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 2" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 2" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 2" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 2" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 3" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 3" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 3" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 3" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 3" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 3" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 3" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 3" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 3" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 4" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 4" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 4" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 4" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 4" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 4" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 4" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 4" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 4" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 5" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 5" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 5" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 5" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 5" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 5" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 5" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 5" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 5" /> <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 6" /> <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 6" /> <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 6" /> <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6" /> <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6" /> <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 6" /> <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 6" /> <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6" /> <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6" /> <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6" /> <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 6" /> <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 6" /> <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 6" /> <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 6" /> <w:LsdException Locked="false" Priority="19" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis" /> <w:LsdException Locked="false" Priority="21" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis" /> <w:LsdException Locked="false" Priority="31" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference" /> <w:LsdException Locked="false" Priority="32" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Reference" /> <w:LsdException Locked="false" Priority="33" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Book Title" /> <w:LsdException Locked="false" Priority="37" Name="Bibliography" /> <w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading" /> </w:LatentStyles> </xml><![endif]--><!--[if !mso]><object  classid="clsid:38481807-CA0E-42D2-BF39-B33AF135CC4D" id=ieooui></object><br />
<style>
st1\:*{behavior:url(#ieooui) }
</style>
<p> <![endif]--><!--[if gte mso 10]><br />
<style>
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin-top:0in;
	mso-para-margin-right:0in;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0in;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
</style>
<p> <![endif]--></p>
<p class="MsoNormal"><span style="font-size: 12pt; line-height: 115%; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">Looking for a PCI QSA in Birmingham, AL to help assist with your Payment Card Industry Data Security Standards (PCI DSS) compliance needs? If so, then contact PCI QSA Charles Denyer of NDB Advisory at 1-800-277-5415, ext. 705 or email him at cdenyer@ndbcpa.com.<span> </span>Charles has worked with numerous organizations throughout the country regarding PCI compliance, ranging from small, privately held start-ups to large, nationally recognized organizations. He and his dedicated staff at NDB Advisory have developed<span> </span>a proven, efficient, and cost-effective <a title="pci dss ndb advisory compliance roadmap" href="http://www.pciassessment.org/roadmap-to-compliance.php" target="_blank">methodology</a> for meeting all your compliance needs, especially that of Level 1 on-site assessments, which require the use of a Payment Card Industry Qualified Security Assessor (PCI-QSA).</span></p>
<p class="MsoNormal"><span style="font-size: 12pt; line-height: 115%; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">NDB Advisory&#8217;s PCI QSA Birmingham, AL auditing and consulting services consist of the following phases for meeting your level 1 compliance needs, regardless if you are a merchant or a service provider:</span></p>
<p class="MsoNoSpacing"><strong><span style="font-size: 12pt; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">(1) PCI DSS Readiness Assessment</span></strong></p>
<p class="MsoNoSpacing"><strong><span style="font-size: 12pt; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">(2) Policy &amp; Procedure (P&amp;P) Analysis and Development</span></strong></p>
<p class="MsoNoSpacing"><strong><span style="font-size: 12pt; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">(3) Remediation Activities</span></strong></p>
<p class="MsoNoSpacing"><strong><span style="font-size: 12pt; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">(4) Vulnerability Scanning Services</span></strong></p>
<p class="MsoNoSpacing"><strong><span style="font-size: 12pt; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">(5) Penetration Services</span></strong></p>
<p class="MsoNoSpacing"><strong><span style="font-size: 12pt; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">(6) PCI DSS Assessment | on-site Fieldwork </span></strong></p>
<p class="MsoNoSpacing"><strong><span style="font-size: 12pt; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">(7) Issuance of “Report on Compliance” (ROC) and any other necessary reporting deliverables</span></strong></p>
<p class="MsoNormal"><span style="font-size: 12pt; line-height: 115%; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">Each phase is carried out and executed in a thoughtful, diligent manner, thus providing efficiencies of scale, yet producing a comprehensive, quality PCI report, all at a cost-effective fixed fee for your organization.<span> </span>What&#8217;s more, Charles and his staff have developed numerous helpful tools, such as policy and procedure templates, for helping organizations with their PCI DSS compliance needs.<span> </span>From a <a title="pci dss readiness assessment" href="http://www.pciassessment.org/pci-dss-readiness-assessment.php" target="_blank">readiness assessment</a> to the final issuance of the PCI Report on Compliance (ROC), our PCI QSA Birmingham, AL auditing and consulting services will get you up to speed with PCI compliance in no time. </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pciassessment.org/pci-blog/pci-qsa-birmingham-alabama-consulting-services-offered-by-ndb-advisory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI QSA Consultant Charles Denyer Reveals Top 10 Challenges and Recommendations for PCI Compliance &#124; Part III</title>
		<link>http://www.pciassessment.org/pci-blog/pci-qsa-consultant-charles-denyer-reveals-top-10-challenges-and-recommendations-for-pci-compliance-part-iii/</link>
		<comments>http://www.pciassessment.org/pci-blog/pci-qsa-consultant-charles-denyer-reveals-top-10-challenges-and-recommendations-for-pci-compliance-part-iii/#comments</comments>
		<pubDate>Wed, 27 Jul 2011 17:35:12 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[PCI News]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[intrusion detection system]]></category>
		<category><![CDATA[policies and procedures]]></category>

		<guid isPermaLink="false">http://www.pciassessment.org/pci-blog/?p=194</guid>
		<description><![CDATA[8. Intrusion Detection System-Requirement 11 calls for having an IDS in place, thus I recommend snort, an open source IDS. www.snort.org. 9. Policies and Procedures-There are a very large number of various policies, procedures, forms, checklists, etc. that need to be developed for PCI compliance.  And while PCI compliance is considered technical in nature, much [...]]]></description>
			<content:encoded><![CDATA[<p><strong>8. Intrusion Detection System</strong>-Requirement 11 calls for having an IDS in place, thus I recommend snort, an open source IDS. www.snort.org.</p>
<p><strong>9. Policies and Procedures-</strong>There are a very large number of various policies, procedures, forms, checklists, etc. that need to be developed for PCI compliance.  And while PCI compliance is considered technical in nature, much is to be done on the more qualitative, soft-side of technical writing. Companies really struggle with this very issue as they simply don&#8217;t have the time and resources needed to develop quality, highly customized policies and procedures.  If you take the time to thoroughly analyze each of the twelve (12) PCI DSS requirements and their respective sub-components, you often come across mandates calling for &#8220;policies, procedures, authorization forms,&#8221;, etc. that need to be developed and implemented into an organization&#8217;s daily operational environment.  Your best bet here is to find a reputable, quality firm offering PCI policy and procedure writing or to use a company such as pcipolicyportal.com.</p>
<p><strong>10. Operational Commitments from Internal Personnel-</strong>In short, most organizations struggle immensely from an operational perspective with PCI. They either do not have the manpower, applicable skill sets, or budget to provide adequate resources for an engagement of this type. This often leads to delays and missed project milestones for PCI compliance. They have the intent and sincerity of wanting to become compliant, but simply don&#8217;t have the resources to achieve their goals in a timely manner.  Thus, one way to remove some of these burdens associated with PCI compliance is to discuss many of these issues mentioned in my top 10 list and what activities can be immediately undertaken to address these pressing concerns.</p>
<p>I hope this list has been helpful to you and please look for more PCI Top 10 lists in the future.</p>
<p>View <a title="PCI QSA Top 10 Part I" href="http://www.pciassessment.org/pci-blog/pci-qsa-consultant-charles-denyer-reveals-top-10-challenges-and-recommendations-for-pci-compliance-part-i/" target="_blank">Part I</a> and <a title="PCI QSA Top Ten Part II" href="http://www.pciassessment.org/pci-blog/pci-qsa-consultant-charles-denyer-reveals-top-10-challenges-and-recommendations-for-pci-compliance-part-ii/" target="_blank">Part II</a> of Top Ten PCI Challenges</p>
<p><strong>About Charles Denyer</strong><br />
Charles Denyer is a member of NDB Accountants &amp; Consultants, a nationally recognized boutique CPA and advisory firm specializing in Regulation AB, SAS 70, SSAE 16, ISAE 3402, FISMA, NIST, HIPAA, ISO and PCI DSS compliance, along with other regulatory compliance initiatives. Mr. Denyer is actively involved in numerous professional associations and organizations for a wide range of industries and business sectors. He is also an advanced social media expert, having spent years working in the field of search engine optimization (SEO) and various forms of online marketing and social media.<br />
Mr. Denyer holds numerous accounting and technology certifications along with a Masters in Information and Telecommunication Systems from the Johns Hopkins University and a Masters in Nuclear Engineering. He is also currently an MBA candidate for the Johnson School of Business at Cornell University. He can be reached at cdenyer@ndbcpa.com or at 800-277-5415-ext.705.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pciassessment.org/pci-blog/pci-qsa-consultant-charles-denyer-reveals-top-10-challenges-and-recommendations-for-pci-compliance-part-iii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

