Logo
    Search

    Cybersecurity Sense

    CyberSecurity Sense is LBMC Information Security's podcast that provides insight and updates on such information security topics as: IPS Monitoring and Managed IDS Services, Security Information Event Management, Digital Forensic Analysis, Electronic Discovery and Litigation Support, Computer Security Incident Response, Penetration Testing, Risk Assessments, Security Program Planning, Web Application Security Assessments, ACAB LADMF Certification Assessments, CMS Information Security, FedRAMP, FISMA Compliance, HIPAA Compliance, HITRUST CSF Certifications, NIST 800-171 Certifications, PCI Data Security Standards, SOC Reporting and SOX Compliance.
    enTiffany Orth64 Episodes

    Episodes (64)

    PCI Monthly Update: Gearing Up for Version 4.0, Mastering Requirement 9, and QSA Insights

    PCI Monthly Update: Gearing Up for Version 4.0, Mastering Requirement 9, and QSA Insights

    In this January edition of the PCI Monthly Update, we’re on the brink of exciting changes with version 4.0 just around the corner! We start with a spotlight on the ongoing Request for Comments (RFC) period for PCI DSS v4.0, inviting insights from industry experts. Plus, we discuss the Global Content Library, showcasing insights from the 2023 Community Meetings.

    Our focus then shifts to Requirement 9, where we break down the critical protocols for restricting physical access to cardholder data. We'll cover everything from documenting security policies to managing visitor access, ensuring secure storage and destruction of media with cardholder data, and protecting Point of Interaction (POI) devices from security threats.

    Wrap up with us as we consolidate today's takeaways and prepare you for what these updates mean for your compliance strategy.

    This podcast is your monthly briefing on PCI standards - an indispensable listen for anyone tasked with safeguarding payment card data.

    PCI Monthly Update: December News, Deep Dive into Requirement 8, and QSA Q&A

    PCI Monthly Update: December News, Deep Dive into Requirement 8, and QSA Q&A

    Join us for the latest episode of our PCI Monthly Update podcast, where we explore the latest developments in the world of payment card industry security.

    We begin with a news segment highlighting the PCI SSC's TRA Guidance. Next, we delve into Requirement 8 of the PCI DSS, dedicated to identifying users and authenticating access to system components. We'll explore the intricate details of this requirement, covering sub-requirements 8.1 to 8.6. These discussions will include processes for user identification, strict management of user and administrator accounts, strong authentication methods, and the implementation of multi-factor authentication (MFA) to ensure the security of cardholder data environments (CDE).

    Our QSA Q&A segment then addresses a critical question: Do all accounts need to comply with these requirements? We'll provide clarity on the scope, applicability, and exceptions, helping listeners understand the nuances of compliance.

    Tune in for a comprehensive review of December's PCI updates, an in-depth analysis of Requirement 8, and valuable insights from our QSA experts. This episode is a must-listen for professionals seeking to stay informed and improve their organization's payment security and compliance.

    PCI Monthly Update: October - New SAQ Review, Focused Look at Requirement 7, and Expert QSA Insights

    PCI Monthly Update: October - New SAQ Review, Focused Look at Requirement 7, and Expert QSA Insights

    Dive into the latest in the PCI landscape with our October update. We kick off with a news segment spotlighting the new SAQ SPOC (Software PIN Entry on COTS) which includes portions of PCI DSS Requirements 3, 8, 9, and 12.

    Transitioning to Requirement 7, we discuss restricting access to system components and cardholder data based on business necessity, delving into sub-requirements 7.1 to 7.3, and discussing the principles of 'need to know' and 'least privileges.'

    Our QSA Q&A segment addresses the applicability of Requirement 7 to customer/cardholder accounts, clarifying the scope and the specific entities impacted by this requirement.

    Join us for a comprehensive exploration of this month's PCI developments, an in-depth look at Requirement 7, and expert insights in our QSA dialogue, paving your way towards enhanced compliance and security.

    PCI Monthly Update: September Highlights & Requirement 6 Deep Dive

    PCI Monthly Update: September Highlights & Requirement 6 Deep Dive

    Catch the latest news in our September "PCI Monthly Update" from Tuesday, September 26, 2023. We kick things off with key insights from the recent PCI Community Meeting. Next, we dive into Requirement 6, discussing the essence of secure software development, from processes to security vulnerabilities, web application protection, and change management.

    Our QSA Q&A segment addresses a vital question: What documentation should you expect from PCI DSS compliant service providers?

    Join us for a succinct roundup of September's essential PCI updates and insights. Perfect for both newcomers and seasoned PCI professionals.

    PCI Monthly Update: August Highlights & Requirement 5 Breakdown

    PCI Monthly Update: August Highlights & Requirement 5 Breakdown

    Tune in to the August edition of our PCI Monthly Update. We kick off with a sneak peek into the upcoming PCI North America Community Meeting in Portland and introduce the newly launched PCI Community Job Board—a dedicated platform for security talent and job postings in the payment industry.

    Next, we delve into Requirement 5, shedding light on anti-malware solutions. We explore the criteria for system components which do not require anti-malware, delve into the specifics of anti-malware implementation, and highlight the periodic evaluations required for maintaining optimal security.

    Wrapping up, our QSA Q&A segment addresses a common query: the rotation of QSAs in organizations.

    Whether you're a PCI pro or new to the domain, this episode offers a concise overview of August's essential PCI topics. Join us for these insights and more!

    PCI Monthly Update: July Insights & Innovations

    PCI Monthly Update: July Insights & Innovations

    Dive into the latest PCI news in our July PCI Update. This episode covers key PCI developments, an in-depth exploration of Requirement 4, and a helpful QSA Q&A.

    We kick off this episode by previewing the upcoming PCI Community Meeting in Portland and discuss our hosts' presentation on "Generative AI: Your New Secret Weapon or an Insider Threat?" We also talk about the INFI worksheet and the importance of Continuous Compliance.

    In the Requirement 4 segment, we focus on strong cryptography, robust security protocols, and the need to secure PAN during transmission over public networks. We highlight industry best practices for wireless networks transmitting PAN and the necessity to secure PAN when using end-user messaging technologies.

    A QSA Q&A session wraps up our episode and tackles the issue of responsibility for PCI compliance when using third-party payment services.

    Whether you're an industry veteran or new to PCI, this episode offers a concise, informative roundup of the month's most significant PCI topics.

    Worried about Ransomware?

    Worried about Ransomware?

    Do you know the average payout organizations are hit with for every attack? William Parks and Bill Dean discuss a service dedicated to helping your organization (big or small) withstand a ransomware attack. Bill and his team are ready to help you and your organization obtain peace of mind when it comes to these advanced threats. 

    Questions for Bill?

    Find him here: bill.dean@lbmc.com

    Advance Guard Could Save You

    Advance Guard Could Save You

    LBMC Shareholder Bill Dean and William Parks spend today’s episode discussing Advance Guard, a new service offering from LBMC's Security Technical Team. Learn how Advance Guard may help protect your organization's most valuable assets, save time on compliance audits, and give peace of mind about your current security stance.

     Want to see Bill’s “Prescription”? Check out the link below:

    https://www.lbmc.com/wp-content/uploads/2023/01/AdvanceGuard-Sample-Schedule.pdf

    Questions for Bill?

    Find him here: bill.dean@lbmc.com

    PCI Monthly Update: March News & Requirement 3

    PCI Monthly Update: March News & Requirement 3

    Stay up to date with the latest in PCI compliance. In this episode, William Parks, Andy Kerr, and Kyle Hinterberg discuss the latest in PCI news, new restrictions around PAN data, and how to master Requirement 3 while preparing for PCI 4.0.

    Don't miss our upcoming webinar: "How to Reduce Your PCI Scope: Tips & Technology Your Organization Needs to Know" on Thursday, April 13 at 11am CT. Register Now!

    For any questions, feel free to reach out to us here:

    Kyle Hinterberg: kyle.hinterberg@lbmc.com
    Andy Kerr: andy.kerr@lbmc.com
    William Parks: william.parks@lbmc.com

    ChatGPT: What You Need to Know

    ChatGPT: What You Need to Know

    ChatGPT is making headlines worldwide and its impact is making a lot of business owners uncomfortable. What is ChatGPT? How will this tool change how you do business? Is ChatGPT a security risk? What to expect from ChatGPT4? William Parks interviews LBMC's Data Insights team members to discuss this controversial topic, dive into facts your organization needs to know, and explore probable scenarios that could happen with this level of Artificial Intelligence.

    Want more insights? Contact LBMC's Data Insights team:

    Jon Hilton, Shareholder (jon.hilton@lbmc.com)

    Will Son, Senior Manager (will.son@lbmc.com)

     

    Interviewing a Real Hacker

    Interviewing a Real Hacker

    William Parks takes this podcast to introduce a key member of LBMC Information Security’s Technical Services team, Daniel Nguyen. Daniel is a manager on the team with quite the insightful background. William and Daniel spend time discussing current steps to keep your organization successful in their journey to a healthier security posture.

    Questions for Daniel?

    Find him here: daniel.nguyen@lbmc.com

     

    PCI Monthly Update: December News & FAQs

    PCI Monthly Update: December News & FAQs

    William Parks, Andy Kerr, and Kyle Hinterberg discuss the latest PCI news, share how to create and what should be covered in an executive summary for a PCI assessment, and answer a few questions from our listeners.

    If you’d like us to answer and address questions on our next episode, reach out to us here:

    Andy Kerr – andy.kerr@lbmc.com

    Kyle Hinterberg – kyle.hinterberg@lbmc.com

    William Parks – William.parks@lbmc.com

    PCI SSC Community Meeting Top Takeaways

    PCI SSC Community Meeting Top Takeaways

    In this podcast, Host William Parks discusses with LBMC Information Security Senior Managers Andy Kerr and Kyle Hinterberg some of the top takeaways at this year’s PCI SSC Community Meeting.

    Topics discussed during this episode include changes to the “In-Place with Remediation” reporting option which was added in PCI DSS v4.0, what to do if you miss an ASV Scan, new ways to interact with the PCI Council, SAQ updates, and much more!

    Keeping Your Digital Identity Secure with Mark Burnette

    Keeping Your Digital Identity Secure with Mark Burnette

    The Internet provides access to lots of good data, useful websites, social media options, and entertainment, but unfortunately, it also poses some risks to the security and privacy of individuals. In this episode, William Parks and Mark Burnette will share some practical tips for how you can keep yourself and your family safe and secure online. You will learn how to keep your kids safe on social media, how to avoid having to remember hundreds of online passwords (and how to avoid having them hacked), and how to protect your privacy while surfing the Internet.

    Episode Bonus: LBMC's free interactive resource, "Keeping Your Digital Identity Secure." Download Now!

    Women in Cybersecurity

    Women in Cybersecurity

    To celebrate Women's History Month, LBMC interviews a panel of our women cybersecurity experts on their unique career journeys, what advice they would give to women looking to work in the field, and goals for the future. 

    Cybersecurity Sense
    enMarch 24, 2022

    Hiring Perspectives

    Hiring Perspectives

    In this episode, the LBMC team gives listeners insight into what to expect when interviewing for a role in information security. Learn what qualities hiring managers are looking for as you prepare for your job interview.

    Cybersecurity Sense
    enDecember 08, 2020