Switch to full style
This forum is to promote member-owned businesses and publicize services that members offer. One thread per business or service please, and please only create a thread for YOUR business or service.
Post a reply

Compliance and Network Security

Wed Apr 27, 2016 6:37 pm

Noticed a post in the FFL area about a vendor working on PCI compliance for taking credit cards. I wanted to offer free consultation to any small FFL if they run in to issues or have concerns regarding PCI compliance or security. I've been in this field for 10 years, and I'd love to help anyone that needs it.

Re: Compliance and Network Security

Wed Apr 27, 2016 6:49 pm

Generous offer.
PCI compliance is a whole new can of worms for a lot of people.
I've had prospective clients bitching about why they couldn't download malware screensavers, store credit card numbers in plain text, and couldn't keep the same password they used for the past 8 years.

Re: Compliance and Network Security

Wed Apr 27, 2016 7:03 pm

Guntrader wrote:Generous offer.
PCI compliance is a whole new can of worms for a lot of people.
I've had prospective clients bitching about why they couldn't download malware screensavers, store credit card numbers in plain text, and couldn't keep the same password they used for the past 8 years.


My first day at a really well known company, IT told us "just use a pets name and add the number one on the end, then when you have to update, you just make it two"

Re: Compliance and Network Security

Wed Apr 27, 2016 7:11 pm

I have seen the 'increment by one' scheme, may have even been in literature from PCI.

My ex was a pension analyst for the Teamsters Trust.
They had to change passwords every two weeks, couldn't contain more than 7 characters from the last password, upper, lower, number, extended characters, etc.
So they just taped them to their monitors or desk.

Weakest link in infosec is always people.

Re: Compliance and Network Security

Wed Apr 27, 2016 7:12 pm

Guntrader wrote:I have seen the 'increment by one' scheme, may have even been in literature from PCI.

My ex was a pension analyst for the Teamsters Trust.
They had to change passwords every two weeks, couldn't contain more than 7 characters from the last password, upper, lower, number, extended characters, etc.
So they just taped them to their monitors or desk.

Weakest link in infosec is always people.


For sure, sometimes people forget the balance between productivity and security. Too Secure = No business

Re: Compliance and Network Security

Wed Apr 27, 2016 7:38 pm

Very generous of you- for my business, I am going to run the SAQ again and see if I am compliant. Last time I was only one or two questions shy of the green light.

PCI compliance is far beyond password security in complexity, scope, and depth.

It has been an experience...

Re: Compliance and Network Security

Wed Apr 27, 2016 10:07 pm

It sucks having to make any services I offer ITAR compliant.

Re: Compliance and Network Security

Sat May 25, 2019 11:49 am

Are you looking or interested in working with other companies on this compliance?
I know its a pain and some of my clients have been messing with it off and on. When it comes up again you have any desire to assist (for pay of course).

Re: Compliance and Network Security

Sat May 25, 2019 12:35 pm

Col_Temp wrote:Are you looking or interested in working with other companies on this compliance?
I know its a pain and some of my clients have been messing with it off and on. When it comes up again you have any desire to assist (for pay of course).


Paris... This was a 3 year old thread man... :bonghit:

Re: Compliance and Network Security

Fri Jun 07, 2019 1:45 pm

Massivedesign wrote:
Col_Temp wrote:Are you looking or interested in working with other companies on this compliance?
I know its a pain and some of my clients have been messing with it off and on. When it comes up again you have any desire to assist (for pay of course).


Paris... This was a 3 year old thread man... :bonghit:

:bigsmile: Yeah but I'm pretty sure he is still around....
I'll message him and see.
Post a reply