<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PCI DSS Position on Patching May Be Unjustified</title>
	<atom:link href="http://www.bloginfosec.com/2008/06/27/pci-dss-position-on-patching-may-be-unjustified/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bloginfosec.com/2008/06/27/pci-dss-position-on-patching-may-be-unjustified/</link>
	<description>An Information Security Magazine in a Blog Format</description>
	<lastBuildDate>Mon, 30 Jan 2012 11:01:25 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Adam Shostack</title>
		<link>http://www.bloginfosec.com/2008/06/27/pci-dss-position-on-patching-may-be-unjustified/comment-page-1/#comment-8875</link>
		<dc:creator>Adam Shostack</dc:creator>
		<pubDate>Mon, 30 Jun 2008 15:33:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.bloginfosec.com/?p=463#comment-8875</guid>
		<description>Thanks for the mention, Jeff!  I&#039;m glad we inspired you to do this, and I&#039;ve posted some thoughts in response at http://www.emergentchaos.com/archives/2008/06/in_the_land_of_the_blind.html</description>
		<content:encoded><![CDATA[<p>Thanks for the mention, Jeff!  I&#8217;m glad we inspired you to do this, and I&#8217;ve posted some thoughts in response at <a href="http://www.emergentchaos.com/archives/2008/06/in_the_land_of_the_blind.html" rel="nofollow">http://www.emergentchaos.com/archives/2008/06/in_the_land_of_the_blind.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jens Laundrup</title>
		<link>http://www.bloginfosec.com/2008/06/27/pci-dss-position-on-patching-may-be-unjustified/comment-page-1/#comment-8874</link>
		<dc:creator>Jens Laundrup</dc:creator>
		<pubDate>Mon, 30 Jun 2008 15:32:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.bloginfosec.com/?p=463#comment-8874</guid>
		<description>Well said Jeff.  
I would be willing to bet that they (The Payment Card Industry) do not follow their own patching mandate.   It reflects the overall problem with PCI DSS, that it is too prescriptive but fails to meet the intended objective.  We can draw a similar parallel to the Department of Defense where they often have a checklist that they have to go through to show compliance with a security directive. The problem with them is you can show compliance with the checklist or with PCI and be inadequately secured, thus meeting the letter of law but failing at the intent.  It is time for the PCI to start thinking about adopting a different tactic.  
In my opinion, certification to ISO/IEC 27001 would do much more to meet the intent of PCI DSS than PCI DSS does today.</description>
		<content:encoded><![CDATA[<p>Well said Jeff.<br />
I would be willing to bet that they (The Payment Card Industry) do not follow their own patching mandate.   It reflects the overall problem with PCI DSS, that it is too prescriptive but fails to meet the intended objective.  We can draw a similar parallel to the Department of Defense where they often have a checklist that they have to go through to show compliance with a security directive. The problem with them is you can show compliance with the checklist or with PCI and be inadequately secured, thus meeting the letter of law but failing at the intent.  It is time for the PCI to start thinking about adopting a different tactic.<br />
In my opinion, certification to ISO/IEC 27001 would do much more to meet the intent of PCI DSS than PCI DSS does today.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

