An SLA Starter For PCI Compliance In The Cloud
April 6th, 2011As a QSA, PCI Columnist Walt Conway argues that he would pay particular attention to patches the vendor identifies as critical, because those have to be installed within 30 days. Will you be able to see a log or other evidence that the patches were installed on all in-scope systems? Another example is your internal and external vulnerability scans. You need to have the CSP provide reporting each quarter on both your complete internal vulnerability scans and your external scans, which an ASV must perform. Read more...
Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code.
-Marc
