<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A Sample Policy for PCI-DSS</title>
	<atom:link href="http://www.pcidssguru.com/policy/a-sample-policy-for-pci-dss/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pcidssguru.com/policy/a-sample-policy-for-pci-dss/</link>
	<description>Practical Implementation Guidance on the Payment Card Industry Data Security Standard</description>
	<lastBuildDate>Fri, 14 Jun 2013 06:29:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.2</generator>
	<item>
		<title>By: Otavio Macedo</title>
		<link>http://www.pcidssguru.com/policy/a-sample-policy-for-pci-dss/comment-page-1/#comment-43622</link>
		<dc:creator>Otavio Macedo</dc:creator>
		<pubDate>Tue, 29 Jan 2013 16:40:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/pci-dss/a-sample-policy-for-pci-dss/#comment-43622</guid>
		<description>Good tips! I was just looking for quick start guide like this.

Now, suppose my company is applying for PCI compliance. Can I show the QSA only these general guidelines? Or will he ask me for the more specific standards and procedures?</description>
		<content:encoded><![CDATA[<p>Good tips! I was just looking for quick start guide like this.</p>
<p>Now, suppose my company is applying for PCI compliance. Can I show the QSA only these general guidelines? Or will he ask me for the more specific standards and procedures?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Binney</title>
		<link>http://www.pcidssguru.com/policy/a-sample-policy-for-pci-dss/comment-page-1/#comment-4179</link>
		<dc:creator>Bob Binney</dc:creator>
		<pubDate>Tue, 12 Jul 2011 19:10:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/pci-dss/a-sample-policy-for-pci-dss/#comment-4179</guid>
		<description>Looking forward to working with your policy template to begin the process.</description>
		<content:encoded><![CDATA[<p>Looking forward to working with your policy template to begin the process.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Cornelius</title>
		<link>http://www.pcidssguru.com/policy/a-sample-policy-for-pci-dss/comment-page-1/#comment-41</link>
		<dc:creator>Tom Cornelius</dc:creator>
		<pubDate>Mon, 15 Sep 2008 20:20:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/pci-dss/a-sample-policy-for-pci-dss/#comment-41</guid>
		<description>The interesting thing most people do not understand is that without the ability to document due care and due diligence on behalf of the company, the company can be found negligent for failing to adhere to known standards.

The PCI DSS is a non-regulatory requirements, so the government does not have a play. However, being a legally-binding document, the PCI DSS can bring a Merchant into a courtroom. If one requirement from the PCI DSS is not met, the Merchant is technically non-compliant. If the Merchant is non-compliant, the Merchant is technically negligent.

Where most business owners do not realize the risk is that insurance does not cover acts of negligence and the entire cost of the data breach, from fines to lawsuits and chargebacks will be completely left to pay by the Merchant. This could spell immediate bankruptcy for most Level 3 or Level 4 merchants.

In simple terms, everyone needs robust policies and ensure those standards are being met. The cost of prevention is immensely less than that to clean up after a breach.</description>
		<content:encoded><![CDATA[<p>The interesting thing most people do not understand is that without the ability to document due care and due diligence on behalf of the company, the company can be found negligent for failing to adhere to known standards.</p>
<p>The PCI DSS is a non-regulatory requirements, so the government does not have a play. However, being a legally-binding document, the PCI DSS can bring a Merchant into a courtroom. If one requirement from the PCI DSS is not met, the Merchant is technically non-compliant. If the Merchant is non-compliant, the Merchant is technically negligent.</p>
<p>Where most business owners do not realize the risk is that insurance does not cover acts of negligence and the entire cost of the data breach, from fines to lawsuits and chargebacks will be completely left to pay by the Merchant. This could spell immediate bankruptcy for most Level 3 or Level 4 merchants.</p>
<p>In simple terms, everyone needs robust policies and ensure those standards are being met. The cost of prevention is immensely less than that to clean up after a breach.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: basic
Database Caching using disk: basic
Object Caching 354/359 objects using disk: basic

Served from: www.pcidssguru.com @ 2013-06-18 16:32:52 -->