Re: CISP Compliance

2007-08-21 Thread Aaron D. Wrasman
Identify the systems and networks that store or transmit cardholder information. Isolate those behind state firewalls. Label everything else as public networks. Now only the isolated network(s) and serer(s) have to comply with PCI. Once you have policies in place your systems and networks have t

Re: CISP Compliance

2007-08-21 Thread Michael Loftis
CISP compliance is more about policy and practices than about software. --On August 20, 2007 6:14:36 PM -0500 Jonathan Wilson <[EMAIL PROTECTED]> wrote: Sorry if this is the wrong place for this, but: Does anyone know of a place I can get information on setting up CISP (VISA credi

Re: CISP Compliance

2007-08-21 Thread Jeremy Melanson
Hi Jonathan. My company just got PCI certified (we're on our way to CISP). From what I've discovered through the process of getting PCI-certified, most of the work has to do with creating policies, and doing a lot of social engineering to enforce and maintain those policies. ` Beaurocracy aside, m

Re: CISP Compliance

2007-08-20 Thread John Keimel
On 8/20/07, Jonathan Wilson <[EMAIL PROTECTED]> wrote: > Sorry if this is the wrong place for this, but: > > Does anyone know of a place I can get information on setting up CISP (VISA > credit card) compliant Debian systems - or Linux in general, if there's no > Debian-specific info. I've been sear

CISP Compliance

2007-08-20 Thread Jonathan Wilson
Sorry if this is the wrong place for this, but: Does anyone know of a place I can get information on setting up CISP (VISA credit card) compliant Debian systems - or Linux in general, if there's no Debian-specific info. I've been searching the web for a couple hours and I don't know if I'm sear