8 PCI 4.0.1 Gaps Costing SMBs the Most (ep. 14)
SecurityMetrics, Inc.
0:00 / 0:00
8 PCI 4.0.1 Gaps Costing SMBs the Most (ep. 14)
166 просмотров · 1 мес. назад
SecurityMetrics, Inc.
5,41 тыс. подписчиков
166 просмотров · 1 мес. назад
PCI DSS 4.0.1 isn't new anymore — but a lot of businesses are still struggling with the same requirements. Jen Stone talks with Matt Halbleib, Director of Assessments at SecurityMetrics, about the parts of 4.0.1 that continue to cause problems for small and medium businesses, and what to actually do about them.
Chapters
00:00 Intro
00:39 Meet Matt Halbleib, Director of Assessments
01:17 Why 4.0.1 is still tripping people up
02:04 Advice for getting started on the right foot
04:37 Getting management buy-in and assigning a project manager
07:32 Why scoping still matters
09:26 Targeted Risk Analysis explained
13:22 What changed with MFA
15:34 New service provider responsibilities
20:34 Logging and alerting requirements
24:39 Password Requirements and advice
26:58 Compensating controls: how to use them correctly
28:57 The customized approach: Don't do it!
30:04 E-commerce: why this is where breaches are happening now
35:41 Wrap up
🔗 RESOURCES
PCI DSS 4.0.1 Standard: https://blog.pcisecuritystandards.org...
Shopping Cart Monitor: https://www.securitymetrics.com/shopp...
SecurityMetrics PCI DSS resources: https://www.securitymetrics.com/blog/...
ABOUT THE GUEST
Matt Halbleib is Director of Assessments at SecurityMetrics, where he's worked in information security for nearly 19 years.
Subscribe for more practical guidance on PCI DSS, HIPAA, and CMMC compliance.