<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: PCI and SOX, HIPAA, GLBA, et.al.</title>
	<atom:link href="http://pciguru.wordpress.com/2011/03/11/pci-and-sox-hipaa-glba-et-al/feed/" rel="self" type="application/rss+xml" />
	<link>http://pciguru.wordpress.com/2011/03/11/pci-and-sox-hipaa-glba-et-al/</link>
	<description>A common sense approach to achieving PCI compliance and retaining your sanity</description>
	<lastBuildDate>Tue, 18 Jun 2013 10:50:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: PCIGuru</title>
		<link>http://pciguru.wordpress.com/2011/03/11/pci-and-sox-hipaa-glba-et-al/#comment-931</link>
		<dc:creator><![CDATA[PCIGuru]]></dc:creator>
		<pubDate>Tue, 26 Apr 2011 01:28:43 +0000</pubDate>
		<guid isPermaLink="false">http://pciguru.wordpress.com/?p=742#comment-931</guid>
		<description><![CDATA[A QSA should confirm that the access control system was being used across the cardholder data environment (CDE) and the processes followed to manage and maintain the access control system were also consistently used across the CDE.  If no CDE users were tested as part of the SOX testing, then I would also expect to test some of them as well to ensure that all forms and the like were also consistently implemented.  As long as this work all comes out without any findings, I would accept the SOX results for the remainder of testing.]]></description>
		<content:encoded><![CDATA[<p>A QSA should confirm that the access control system was being used across the cardholder data environment (CDE) and the processes followed to manage and maintain the access control system were also consistently used across the CDE.  If no CDE users were tested as part of the SOX testing, then I would also expect to test some of them as well to ensure that all forms and the like were also consistently implemented.  As long as this work all comes out without any findings, I would accept the SOX results for the remainder of testing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://pciguru.wordpress.com/2011/03/11/pci-and-sox-hipaa-glba-et-al/#comment-930</link>
		<dc:creator><![CDATA[John]]></dc:creator>
		<pubDate>Mon, 25 Apr 2011 22:13:53 +0000</pubDate>
		<guid isPermaLink="false">http://pciguru.wordpress.com/?p=742#comment-930</guid>
		<description><![CDATA[Question - if a company has the same process for user access control across a number of systems (in scope PCI systems included) and during SOx or some other audit/assessment, the access control process is tested and validated, but somehow no PCI in scope system was in the sample, would you still accept the validation because access control for all systems follow the same process, or would you perform some level of testing for in scope systems?]]></description>
		<content:encoded><![CDATA[<p>Question &#8211; if a company has the same process for user access control across a number of systems (in scope PCI systems included) and during SOx or some other audit/assessment, the access control process is tested and validated, but somehow no PCI in scope system was in the sample, would you still accept the validation because access control for all systems follow the same process, or would you perform some level of testing for in scope systems?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eli</title>
		<link>http://pciguru.wordpress.com/2011/03/11/pci-and-sox-hipaa-glba-et-al/#comment-888</link>
		<dc:creator><![CDATA[Eli]]></dc:creator>
		<pubDate>Thu, 17 Mar 2011 10:17:20 +0000</pubDate>
		<guid isPermaLink="false">http://pciguru.wordpress.com/?p=742#comment-888</guid>
		<description><![CDATA[Hey,
Its effective for SOX purposes, 
One accounting firm can relies on the work of another accounting firm (they &quot;Speak the same language&quot;)
If we look at cost / benefit for PCI DSS purposes - Its to risky.]]></description>
		<content:encoded><![CDATA[<p>Hey,<br />
Its effective for SOX purposes,<br />
One accounting firm can relies on the work of another accounting firm (they &#8220;Speak the same language&#8221;)<br />
If we look at cost / benefit for PCI DSS purposes &#8211; Its to risky.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PCI and SOX, HIPAA, GLBA, et.al.</title>
		<link>http://pciguru.wordpress.com/2011/03/11/pci-and-sox-hipaa-glba-et-al/#comment-883</link>
		<dc:creator><![CDATA[PCI and SOX, HIPAA, GLBA, et.al.]]></dc:creator>
		<pubDate>Wed, 16 Mar 2011 05:30:06 +0000</pubDate>
		<guid isPermaLink="false">http://pciguru.wordpress.com/?p=742#comment-883</guid>
		<description><![CDATA[[...] it happen.&#160; So you need to keep in mind that such efforts may be for naught.Cross-posted from PCI Guru        Share This! &#124;         var addthis_config = [...]]]></description>
		<content:encoded><![CDATA[<p>[...] it happen.&nbsp; So you need to keep in mind that such efforts may be for naught.Cross-posted from PCI Guru        Share This! |         var addthis_config = [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
