Every now and then I come across a piece of work product that just provides an example of what not to do. This week was one of those times. I received a Service Provider Responsibility Matrix from a prospective client for their eCommerce solution. This document was for a major player in the Cloud. The Continue reading What Not To Do – Service Provider Responsibility Matrix
I have been guilty in the past of agreeing to this and have always regretted it. Clients think that an audit/assessment is like assembling a widget. The more times you do it the faster and more efficiently you get and therefore you should pass along some sort of discount for doing year over year audits/assessments. Continue reading The Audit Efficiency Myth
“We have totally outsourced our eCommerce site to a third party service provider. The third party operates the site and all we do is update marketing graphics and the like. The site does have integrated access to our inventory management system, but that is through a private VPN connection to the Web hosting system. Our Continue reading I Get Questions – ASV Scanning
Just a quick note about merchant identification numbers, aka MID. A few weeks back, Jim Seaman posted on LinkedIn about a situation where the merchant had totally outsourced their eCommerce environment to a third party and he stated that the merchant was still in scope for PCI compliance. I weighed in and stated that it Continue reading The Magic Of The MID
On Wednesday, June 11, 2026, the PCI SSC released an Information Supplement for Compensating Controls and the Customized Approach. The biggest value provided in this publication is the appendices that provide examples of compensating controls and the customized approach. Those examples are a must read for all QSAs, ISAs and anyone performing quality assurance (QA) Continue reading Guidance…
In the May 2026 Assessor Newsletter, the FAQ of the Month portion of the newsletter focused on FAQ #1588. The Council said that this was the result of the significant number of questions on the Q1 All Assessor Session in March regarding how merchants using SAQ A are supposed to show that their websites are Continue reading SAQ A Rears Its Ugly Head Again
Here is one that is new. “If a segmentation test (for service provider) let s say starts in February, but does not conclude until May. Should the next six month test be scheduled from when the test concluded or from when it first began? IMO, it should be after concluding the test. What s your thought please?” Continue reading I Get Questions – Timeframes In PCI
This subject came up the other day in a conversation with an ISA who wanted to check if they were on the correct path. The question that the ISA wanted guidance on related to scoping and ‘connected to’ systems. As a reminder, the Council defines ‘connected to’ and/or ‘security impacting systems’ as those that are: Continue reading ‘Connected To’ Systems
This is a post for all the recruiters out there searching for a “contract QSA”. There is effectively no such thing as a contract QSA. If you want to talk about trying to find a Unicorn, here is a huge one. The reason why? Because to have a contract QSA, a sole proprietor must be Continue reading Contract QSAs
The Wall Street Journal is reporting that a fired Chick-fil-a employee refunded themselves $80K in mac-n-cheese. “Jones was fired from the Dallas-suburb location in October 2025. But the following month, detectives reviewed surveillance footage and found Jones behind the counter without authorization. There, prosecutors allege, Jones began using the restaurant’s register to ring up roughly…