<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Steve Shead Dot Net</title>
	<atom:link href="http://www.steve-shead.net/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.steve-shead.net</link>
	<description>An Information Security Blog</description>
	<lastBuildDate>Mon, 25 Jul 2011 14:14:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on allinurl: admin mdb by Admin mdb &#124; Interswitchweb</title>
		<link>http://www.steve-shead.net/information-technology-and-security/allinurl-admin-mdb/#comment-6792</link>
		<dc:creator>Admin mdb &#124; Interswitchweb</dc:creator>
		<pubDate>Mon, 25 Jul 2011 14:14:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.steve-shead.com/?p=1434#comment-6792</guid>
		<description>[...] allinurl: admin mdb &#171; Steve Shead Dot NetApr 30, 2009 &#8230; Normally you would type allinurl: admin mdb into Google, but I&#8217;ve linked the query above for instant gratification, but remember this is &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] allinurl: admin mdb &#171; Steve Shead Dot NetApr 30, 2009 &#8230; Normally you would type allinurl: admin mdb into Google, but I&#8217;ve linked the query above for instant gratification, but remember this is &#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PCI Compliance in the Cloud by Steve Shead</title>
		<link>http://www.steve-shead.net/information-technology-and-security/pci-compliance-in-the-cloud/#comment-1566</link>
		<dc:creator>Steve Shead</dc:creator>
		<pubDate>Sat, 04 Dec 2010 01:31:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.steve-shead.net/?p=3330#comment-1566</guid>
		<description>Sujay - absolutely agree, but the concept still hasn&#039;t matured, and the new PCI DSS standard is now in place without deference to cloud issues, such as multi-tenant environments. Perhaps it&#039;s a maturing view - time will tell - but I do appreciate your insights.

Steve</description>
		<content:encoded><![CDATA[<p>Sujay &#8211; absolutely agree, but the concept still hasn&#8217;t matured, and the new PCI DSS standard is now in place without deference to cloud issues, such as multi-tenant environments. Perhaps it&#8217;s a maturing view &#8211; time will tell &#8211; but I do appreciate your insights.</p>
<p>Steve</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PCI Compliance in the Cloud by Sujay Jaladi</title>
		<link>http://www.steve-shead.net/information-technology-and-security/pci-compliance-in-the-cloud/#comment-1540</link>
		<dc:creator>Sujay Jaladi</dc:creator>
		<pubDate>Thu, 02 Dec 2010 07:30:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.steve-shead.net/?p=3330#comment-1540</guid>
		<description>Sorry if I am off-track with the topic here but what rings in my mind after reading your article is the following. 

Compliance requirements definitely need to be redefined with the considerations of ever changing technology I would say. At this point even though we are speaking about PCI compliance in the cloud understanding it as “Compliance with the evolving technology” seems to be more appropriate and again this is not me taking a position but this is definitely my understanding of the ever-changing trends.  Compliance rule set is a living document and just because it is not mentioned in the set does not mean it cannot be applied as due diligence. 

The more threats we have the more controls will be added to the compliance requirements. It is very important to know what, where and who has the data and infrastructure that is being used by an organization. Without the right understanding of this it is difficult to implement controls to enforce compliance. For e.g. clouds is a new concept but how about collocations? This is not a new concept but we have successfully implemented compliance in collocations. If we request information on who have entered the location we will not be given access to all the information that is available but just the information that is applicable to the requesting organization is what is provided but there are alternative controls or compensating controls on whether you own the cage and if you can trace and audit entry to the cage by everyone. Trace and audit capabilities is what it comes down to at the end of the day in compliance and it does not really matter whether an organization is in the cloud or in its own data center, as long as all due diligence is administered and every transaction &amp; action can be traced and audited to the satisfaction of the auditors (means enough auditable proof) and to protect the customers from being impacted the organization will be compliant.</description>
		<content:encoded><![CDATA[<p>Sorry if I am off-track with the topic here but what rings in my mind after reading your article is the following. </p>
<p>Compliance requirements definitely need to be redefined with the considerations of ever changing technology I would say. At this point even though we are speaking about PCI compliance in the cloud understanding it as “Compliance with the evolving technology” seems to be more appropriate and again this is not me taking a position but this is definitely my understanding of the ever-changing trends.  Compliance rule set is a living document and just because it is not mentioned in the set does not mean it cannot be applied as due diligence. </p>
<p>The more threats we have the more controls will be added to the compliance requirements. It is very important to know what, where and who has the data and infrastructure that is being used by an organization. Without the right understanding of this it is difficult to implement controls to enforce compliance. For e.g. clouds is a new concept but how about collocations? This is not a new concept but we have successfully implemented compliance in collocations. If we request information on who have entered the location we will not be given access to all the information that is available but just the information that is applicable to the requesting organization is what is provided but there are alternative controls or compensating controls on whether you own the cage and if you can trace and audit entry to the cage by everyone. Trace and audit capabilities is what it comes down to at the end of the day in compliance and it does not really matter whether an organization is in the cloud or in its own data center, as long as all due diligence is administered and every transaction &amp; action can be traced and audited to the satisfaction of the auditors (means enough auditable proof) and to protect the customers from being impacted the organization will be compliant.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

