interview

Phishing – Would you Click?

As part of our ongoing series on social engineering, this article highlights phishing, the most widely used social engineering tactic.  Like other social engineering schemes, phishing relies solely on an individual’s trust and/or gullibility to provide a criminal with open access to sensitive information. How is Phishing Done? Phishing occurs when a criminal sends a […]

Phishing – Would you Click? Read More »

PCI DSS 3.1

April 15, 2015 brought us more than tax day; it brought us the much-anticipated release of the PCI DSS standard from the PCI Council.  As SSL and early TLS are no longer considered strong cryptography, this release describes how the industry is to move forward in regard to the use of SSL and early TLS

PCI DSS 3.1 Read More »

PA-DSS 3.1

The PCI Security Standards Council (PCI SSC) has released Payment Application Data Security Standard (PA-DSS) Version 3.1 to address vulnerabilities in the Secure Socket Layer (SSL) protocol.  This update removes SSL and early TLS as examples of strong cryptography.  PA-DSS 3.1 is effective June 1, 2015.  The PCI DSS requirements that are directly affected by

PA-DSS 3.1 Read More »

Dara Security expands into the Latin American and Caribbean Region

Dara Security, an award-winning information security company, is pleased to announce a partnership alliance with Manexe, Inc., a growing provider of advanced technology for card payment management based in the Latin American and Caribbean (LAC) region. With this partnership, Dara Security will provide to companies in the LAC region a suite of compliance and risk

Dara Security expands into the Latin American and Caribbean Region Read More »

national cyber security awareness month October 2016 logo

The Importance of Cyber Security Awareness

October was National Cyber Security Awareness Month (NCSAM).  This annual campaign, now in its thirteenth year, is a collaborative effort between government and private industry to educate and engage everyone about cybersecurity.  Through the years, NCSAM has raised cybersecurity awareness for consumers of all ages, small businesses, corporations, and educational institutions. This year’s theme was

The Importance of Cyber Security Awareness Read More »

Vulnerability Handling Policy – An Unexpected PA-DSS Surprise?

Point of Sale software vendors that have or are planning to go through the PA-DSS validation process are aware of the requirement detailed within the Payment Application standard.  These requirements range from ensuring proper software development and testing processes and support procedures are in place to include detailed technical requirements around password and logging controls. 

Vulnerability Handling Policy – An Unexpected PA-DSS Surprise? Read More »