<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: [Chinese]PCI-SSC发表最新版本PCI-DSS v1.2</title>
	<atom:link href="http://sbin.cn/blog/2008/10/14/pci-ssc-pci-dss-v12/feed/" rel="self" type="application/rss+xml" />
	<link>http://sbin.cn/blog/2008/10/14/pci-ssc-pci-dss-v12/</link>
	<description>Technologies and comments on cloud and telecom security, bridging China and the world!</description>
	<lastBuildDate>Mon, 19 Sep 2011 01:16:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Wang</title>
		<link>http://sbin.cn/blog/2008/10/14/pci-ssc-pci-dss-v12/comment-page-1/#comment-35580</link>
		<dc:creator>Wang</dc:creator>
		<pubDate>Sun, 15 Mar 2009 23:32:20 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=466#comment-35580</guid>
		<description>Speaking of China:

The people of China would despise George W. Bush.

Bush is a raging racist.

Bush committed hate crimes of epic proportions and with the stench of terrorism (indicated in my blog).

And I do solemnly swear by Almighty God that Bush committed other hate crimes of epic proportions and with the stench of terrorism which I am not at liberty to mention.

Many people know what Bush did.

And many people will know what Bush did—even to the end of the world.

Bush was absolute evil.

Bush is now like a fugitive from justice.

Bush is a psychological prisoner.

In any case, Bush will go down in history in infamy.

Respectfully Submitted by Andrew Yu-Jen Wang, J.D. Candidate
B.S., Summa Cum Laude, 1996
Messiah College, Grantham, PA
Lower Merion High School, Ardmore, PA, 1993

(I can type 90 words per minute. In only 7 days, posts basically like this post of mine have come into existence—all over the Internet (hundreds of copies). One can go to Google right now, type “George W. Bush committed hate crimes of epic proportions and with the stench of terrorism,” hit “Enter,” and find more than 550 copies indicating the content of this post. All in all, there are probably more than 2,000 copies on the Internet indicating the content of this post—it has, in a way, become headline news. One cannot be too dedicated when it comes to anti-Bush activities. As I looked back at my good computer work, I thought how fun and easy it was to do it.)

“GEORGE W. BUSH IS THE WORST PRESIDENT IN U.S. HISTORY” BLOG OF ANDREW YU-JEN WANG
_________________
I am not sure where I had read it before, but anyway, it goes kind of like this: “If only it were possible to ban invention that bottled up memories so they never got stale and faded.” Oh wait—off the top of my head—I think it came from my Lower Merion High School yearbook.</description>
		<content:encoded><![CDATA[<p>Speaking of China:</p>
<p>The people of China would despise George W. Bush.</p>
<p>Bush is a raging racist.</p>
<p>Bush committed hate crimes of epic proportions and with the stench of terrorism (indicated in my blog).</p>
<p>And I do solemnly swear by Almighty God that Bush committed other hate crimes of epic proportions and with the stench of terrorism which I am not at liberty to mention.</p>
<p>Many people know what Bush did.</p>
<p>And many people will know what Bush did—even to the end of the world.</p>
<p>Bush was absolute evil.</p>
<p>Bush is now like a fugitive from justice.</p>
<p>Bush is a psychological prisoner.</p>
<p>In any case, Bush will go down in history in infamy.</p>
<p>Respectfully Submitted by Andrew Yu-Jen Wang, J.D. Candidate<br />
B.S., Summa Cum Laude, 1996<br />
Messiah College, Grantham, PA<br />
Lower Merion High School, Ardmore, PA, 1993</p>
<p>(I can type 90 words per minute. In only 7 days, posts basically like this post of mine have come into existence—all over the Internet (hundreds of copies). One can go to Google right now, type “George W. Bush committed hate crimes of epic proportions and with the stench of terrorism,” hit “Enter,” and find more than 550 copies indicating the content of this post. All in all, there are probably more than 2,000 copies on the Internet indicating the content of this post—it has, in a way, become headline news. One cannot be too dedicated when it comes to anti-Bush activities. As I looked back at my good computer work, I thought how fun and easy it was to do it.)</p>
<p>“GEORGE W. BUSH IS THE WORST PRESIDENT IN U.S. HISTORY” BLOG OF ANDREW YU-JEN WANG<br />
_________________<br />
I am not sure where I had read it before, but anyway, it goes kind of like this: “If only it were possible to ban invention that bottled up memories so they never got stale and faded.” Oh wait—off the top of my head—I think it came from my Lower Merion High School yearbook.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://sbin.cn/blog/2008/10/14/pci-ssc-pci-dss-v12/comment-page-1/#comment-35559</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Thu, 26 Feb 2009 09:25:56 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=466#comment-35559</guid>
		<description>I read through the qualified PCI scanning vendor list. Unfortunately, I didn&#039;t find one vendor from China. The link is: https://www.pcisecuritystandards.org/pdfs/asv_report.html</description>
		<content:encoded><![CDATA[<p>I read through the qualified PCI scanning vendor list. Unfortunately, I didn&#8217;t find one vendor from China. The link is: <a href="https://www.pcisecuritystandards.org/pdfs/asv_report.html" rel="nofollow">https://www.pcisecuritystandards.org/pdfs/asv_report.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guan</title>
		<link>http://sbin.cn/blog/2008/10/14/pci-ssc-pci-dss-v12/comment-page-1/#comment-35557</link>
		<dc:creator>Guan</dc:creator>
		<pubDate>Tue, 24 Feb 2009 07:22:38 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=466#comment-35557</guid>
		<description>anyway, many thanks for your reply:)</description>
		<content:encoded><![CDATA[<p>anyway, many thanks for your reply:)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://sbin.cn/blog/2008/10/14/pci-ssc-pci-dss-v12/comment-page-1/#comment-35541</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Fri, 20 Feb 2009 03:02:22 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=466#comment-35541</guid>
		<description>I am not an expert on this, even I am preparing the compliance for this.  It means a lot of jobs and money. PCI-DSS has very clear and specific technical requirements. This is very unique compared against ISO27001, CoBit, SOX/COSO and etc. 
BTW, I am afraid I don&#039;t time to prepare and deliver the training. You are welcome to send me emails on this.  -- Richard.</description>
		<content:encoded><![CDATA[<p>I am not an expert on this, even I am preparing the compliance for this.  It means a lot of jobs and money. PCI-DSS has very clear and specific technical requirements. This is very unique compared against ISO27001, CoBit, SOX/COSO and etc.<br />
BTW, I am afraid I don&#8217;t time to prepare and deliver the training. You are welcome to send me emails on this.  &#8212; Richard.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guan</title>
		<link>http://sbin.cn/blog/2008/10/14/pci-ssc-pci-dss-v12/comment-page-1/#comment-35531</link>
		<dc:creator>Guan</dc:creator>
		<pubDate>Fri, 13 Feb 2009 10:27:26 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=466#comment-35531</guid>
		<description>Dear Richard, i was interested in your above topic about PCI SSC Standard. are you a expert of this field? 

we are looking for a facilitator with Chinese language to conduct relevant training. Do you interest it? if yes, pls contact me at 13922264698 anytime for further details ASAP. thanks!</description>
		<content:encoded><![CDATA[<p>Dear Richard, i was interested in your above topic about PCI SSC Standard. are you a expert of this field? </p>
<p>we are looking for a facilitator with Chinese language to conduct relevant training. Do you interest it? if yes, pls contact me at 13922264698 anytime for further details ASAP. thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://sbin.cn/blog/2008/10/14/pci-ssc-pci-dss-v12/comment-page-1/#comment-33325</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Thu, 16 Oct 2008 06:55:51 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=466#comment-33325</guid>
		<description>The below is a very concise summary from one friend:

1 Requirement 1 was changed to include all routers as well as just firewalls
2 Firewall rules are now required to be reviewed every six months instead of quarterly
3 Removed the requirement to disable broadcasting SSID
4 For new wireless installation after March 31, 2009,  they may not use WEP
5 For current wireless implementations,  after June 30, 2010,  they may no longer use WEP</description>
		<content:encoded><![CDATA[<p>The below is a very concise summary from one friend:</p>
<p>1 Requirement 1 was changed to include all routers as well as just firewalls<br />
2 Firewall rules are now required to be reviewed every six months instead of quarterly<br />
3 Removed the requirement to disable broadcasting SSID<br />
4 For new wireless installation after March 31, 2009,  they may not use WEP<br />
5 For current wireless implementations,  after June 30, 2010,  they may no longer use WEP</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://sbin.cn/blog/2008/10/14/pci-ssc-pci-dss-v12/comment-page-1/#comment-33323</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Wed, 15 Oct 2008 13:33:46 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=466#comment-33323</guid>
		<description>支付卡行业安全标准委员会发布1.2版支付卡行业数据安全标准 
--对标准的修订包括解释和对简易执行的其他细微改动--
http://forum.10jqka.com.cn/html/10,5992/2300,1.html

商业编辑

美国商业资讯2008年10月1日马萨诸塞州威克费尔德消息——

提供支付卡行业数据安全标准(PCI DSS)、PCI PIN码输入设备(PED)安全要求和支付程序数据安全标准(PA-DSS)管理的全球性、开放式行业标准机构支付卡行业安全标准委员会(PCI SSC)今日宣布了PCI DSS 1.2版的全面发布时间。最新版本积累了两年间来自行业利益相关方的反馈和建议，旨在解释和简易执行最重要的标准以保证持卡人帐户安全。1.2版将即时生效，而该标准的1.1版将于2008年12月31日起取消。有关更新后的标准和支持文件可访问委员会网站 https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml 。

委员会提前宣布了1.1版和1.2版的变更摘要，以确保对标准的未来最新变更的认识。1.2版包括对提高灵活性的要求的解释和说明，从而满足目前的安全挑战并确保组织充分遵循标准。尽管1.2版将不介绍自委员会成立以来的现有12项要求范围的新核心要求，该更新仍对某些做法作了更改，例如到 2010年6月取消实施有线等效加密(WEP)无线安全。

数据安全咨询公司SecurityCurve合伙人兼分析师Diana Kelley说：“在商家和服务提供商竭力应对支付交易系统的最新安全威胁时，PCI DSS的最新版本对他们来说都是受欢迎的消息。解释和语言修订应对简易实施问题大有帮助，并有助于降低合规成本。”

自从委员会于2006年9月成立及PCI SSC 1.1版发布以来，其参与组织和顾问委员会一直不断为标准提供反馈，全球行业也纷纷关注修订。此前，委员会制定了生命周期流程，它将确保PCI DSS标准按两年的周期进行修订和更新。参与组织有机会获得所有即将对委员会的标准进行的修订的草案初稿，并在此过程中提供大量反馈。PCI DSS 1.2版是最近在佛罗里达州奥兰多落下帷幕的委员会年会上的主要讨论话题，500多名与会者聚集于此开始进一步增强标准。

支付卡行业安全标准委员会总经理Bob Russo说：“得知在全球行业反馈中包括PCI DSS 1.2版，我们感到非常满意。这确保我们能继续为商家和服务提供商提供一种渠道，保护易察觉且可获得的持卡人帐户数据。”

更多信息：

有关支付卡行业安全标准委员会及成为其参与组织的更多详情，请访问pcisecuritystandards.org ，或通过电子邮件participation@pcisecuritystandards.org联系支付卡行业安全标准委员会。

关于支付卡行业安全标准委员会

支付卡行业安全标准委员会的使命是，通过推动支付卡行业安全标准以及其他能够提高支付数据安全性的标准的教育和认知，提高支付账户的安全性。

支付卡行业安全标准委员会由美国运通、美国发现金融服务公司（Discover Financial Services）、JCB International、万事达卡全球组织、Visa卡全球组织这几大支付卡品牌共同组建，旨在提供一个透明的论坛，让所有的权益人都能通过这个论坛为PCI数据安全标准、个人识别号码输入设备安全要求和支付应用数据安全标准的持续发展、改进和推广做出贡献。欢迎商户、银行、数据处理机构以及其他提供商加入委员会，成为会员机构。

免责声明：本公告之原文版本乃官方授权版本。译文仅供方便了解之用，烦请参照原文，原文版本乃唯一具法律效力之版本。</description>
		<content:encoded><![CDATA[<p>支付卡行业安全标准委员会发布1.2版支付卡行业数据安全标准<br />
&#8211;对标准的修订包括解释和对简易执行的其他细微改动&#8211;<br />
<a href="http://forum.10jqka.com.cn/html/10,5992/2300,1.html" rel="nofollow">http://forum.10jqka.com.cn/html/10,5992/2300,1.html</a></p>
<p>商业编辑</p>
<p>美国商业资讯2008年10月1日马萨诸塞州威克费尔德消息——</p>
<p>提供支付卡行业数据安全标准(PCI DSS)、PCI PIN码输入设备(PED)安全要求和支付程序数据安全标准(PA-DSS)管理的全球性、开放式行业标准机构支付卡行业安全标准委员会(PCI SSC)今日宣布了PCI DSS 1.2版的全面发布时间。最新版本积累了两年间来自行业利益相关方的反馈和建议，旨在解释和简易执行最重要的标准以保证持卡人帐户安全。1.2版将即时生效，而该标准的1.1版将于2008年12月31日起取消。有关更新后的标准和支持文件可访问委员会网站 <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" rel="nofollow">https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml</a> 。</p>
<p>委员会提前宣布了1.1版和1.2版的变更摘要，以确保对标准的未来最新变更的认识。1.2版包括对提高灵活性的要求的解释和说明，从而满足目前的安全挑战并确保组织充分遵循标准。尽管1.2版将不介绍自委员会成立以来的现有12项要求范围的新核心要求，该更新仍对某些做法作了更改，例如到 2010年6月取消实施有线等效加密(WEP)无线安全。</p>
<p>数据安全咨询公司SecurityCurve合伙人兼分析师Diana Kelley说：“在商家和服务提供商竭力应对支付交易系统的最新安全威胁时，PCI DSS的最新版本对他们来说都是受欢迎的消息。解释和语言修订应对简易实施问题大有帮助，并有助于降低合规成本。”</p>
<p>自从委员会于2006年9月成立及PCI SSC 1.1版发布以来，其参与组织和顾问委员会一直不断为标准提供反馈，全球行业也纷纷关注修订。此前，委员会制定了生命周期流程，它将确保PCI DSS标准按两年的周期进行修订和更新。参与组织有机会获得所有即将对委员会的标准进行的修订的草案初稿，并在此过程中提供大量反馈。PCI DSS 1.2版是最近在佛罗里达州奥兰多落下帷幕的委员会年会上的主要讨论话题，500多名与会者聚集于此开始进一步增强标准。</p>
<p>支付卡行业安全标准委员会总经理Bob Russo说：“得知在全球行业反馈中包括PCI DSS 1.2版，我们感到非常满意。这确保我们能继续为商家和服务提供商提供一种渠道，保护易察觉且可获得的持卡人帐户数据。”</p>
<p>更多信息：</p>
<p>有关支付卡行业安全标准委员会及成为其参与组织的更多详情，请访问pcisecuritystandards.org ，或通过电子邮件participation@pcisecuritystandards.org联系支付卡行业安全标准委员会。</p>
<p>关于支付卡行业安全标准委员会</p>
<p>支付卡行业安全标准委员会的使命是，通过推动支付卡行业安全标准以及其他能够提高支付数据安全性的标准的教育和认知，提高支付账户的安全性。</p>
<p>支付卡行业安全标准委员会由美国运通、美国发现金融服务公司（Discover Financial Services）、JCB International、万事达卡全球组织、Visa卡全球组织这几大支付卡品牌共同组建，旨在提供一个透明的论坛，让所有的权益人都能通过这个论坛为PCI数据安全标准、个人识别号码输入设备安全要求和支付应用数据安全标准的持续发展、改进和推广做出贡献。欢迎商户、银行、数据处理机构以及其他提供商加入委员会，成为会员机构。</p>
<p>免责声明：本公告之原文版本乃官方授权版本。译文仅供方便了解之用，烦请参照原文，原文版本乃唯一具法律效力之版本。</p>
]]></content:encoded>
	</item>
</channel>
</rss>

