<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Compliance vs. Security: a thought exercise</title>
	<atom:link href="http://tylerhannan.com/2009/12/compliance-vs-security-a-thought-exercise/feed/" rel="self" type="application/rss+xml" />
	<link>http://tylerhannan.com/2009/12/compliance-vs-security-a-thought-exercise/</link>
	<description>reflections from the intersection of technology and payments</description>
	<lastBuildDate>Thu, 29 Jul 2010 01:07:48 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: tylerhannan</title>
		<link>http://tylerhannan.com/2009/12/compliance-vs-security-a-thought-exercise/comment-page-1/#comment-50</link>
		<dc:creator>tylerhannan</dc:creator>
		<pubDate>Fri, 18 Dec 2009 07:44:04 +0000</pubDate>
		<guid isPermaLink="false">http://tylerhannan.com/?p=198#comment-50</guid>
		<description>Brad,&lt;br&gt;&lt;br&gt;Good to hear from you!  I will have to agree that I love the way in which you&#039;ve presented the information regarding continuous compliance in the linked video.  &lt;br&gt;&lt;br&gt;The milestone approach is, definitely, not sufficient in adopting a risk-based stance.  I suppose my query, in specific, was regarding PCI-DSS and what folk would choose to do differently than stated in the requirements if they did, in fact, not have to worry about compliance verification and instead only focused on risk.&lt;br&gt;&lt;br&gt;For me, the difference in activity would seem to be rather minimal...at least notionally.</description>
		<content:encoded><![CDATA[<p>Brad,</p>
<p>Good to hear from you!  I will have to agree that I love the way in which you&#39;ve presented the information regarding continuous compliance in the linked video.  </p>
<p>The milestone approach is, definitely, not sufficient in adopting a risk-based stance.  I suppose my query, in specific, was regarding PCI-DSS and what folk would choose to do differently than stated in the requirements if they did, in fact, not have to worry about compliance verification and instead only focused on risk.</p>
<p>For me, the difference in activity would seem to be rather minimal&#8230;at least notionally.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bradgarland</title>
		<link>http://tylerhannan.com/2009/12/compliance-vs-security-a-thought-exercise/comment-page-1/#comment-49</link>
		<dc:creator>bradgarland</dc:creator>
		<pubDate>Fri, 18 Dec 2009 02:40:50 +0000</pubDate>
		<guid isPermaLink="false">http://tylerhannan.com/?p=198#comment-49</guid>
		<description>Hey Tyler, &lt;br&gt;&lt;br&gt;Well looky there, now you guys are getting into my world. ;)  I totally agree that the traditional model of auditing once a year (milestones) is broken.  We have shifted our perspective in this and moved to what we call &quot;continuous compliance&quot;.  Instead of this one point in time mentality we instead work to ingrain compliance in everyday processes and distribute the workload across the year.  Lastly, we&#039;ve big fans of what the collaboration tools do to enable this type of process and see them going hand in hand.&lt;br&gt;&lt;br&gt;If you&#039;re interested, we did a video that talks about continuous compliance that we&#039;re pretty proud of located here: &lt;a href=&quot;http://bit.ly/8Glen9&quot; rel=&quot;nofollow&quot;&gt;http://bit.ly/8Glen9&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Hey Tyler, </p>
<p>Well looky there, now you guys are getting into my world. <img src='http://tylerhannan.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />   I totally agree that the traditional model of auditing once a year (milestones) is broken.  We have shifted our perspective in this and moved to what we call &#8220;continuous compliance&#8221;.  Instead of this one point in time mentality we instead work to ingrain compliance in everyday processes and distribute the workload across the year.  Lastly, we&#39;ve big fans of what the collaboration tools do to enable this type of process and see them going hand in hand.</p>
<p>If you&#39;re interested, we did a video that talks about continuous compliance that we&#39;re pretty proud of located here: <a href="http://bit.ly/8Glen9" rel="nofollow">http://bit.ly/8Glen9</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tylerhannan</title>
		<link>http://tylerhannan.com/2009/12/compliance-vs-security-a-thought-exercise/comment-page-1/#comment-48</link>
		<dc:creator>tylerhannan</dc:creator>
		<pubDate>Thu, 17 Dec 2009 23:44:04 +0000</pubDate>
		<guid isPermaLink="false">http://tylerhannan.com/?p=198#comment-48</guid>
		<description>Brad,&lt;br&gt;&lt;br&gt;Good to hear from you!  I will have to agree that I love the way in which you&#039;ve presented the information regarding continuous compliance in the linked video.  &lt;br&gt;&lt;br&gt;The milestone approach is, definitely, not sufficient in adopting a risk-based stance.  I suppose my query, in specific, was regarding PCI-DSS and what folk would choose to do differently than stated in the requirements if they did, in fact, not have to worry about compliance verification and instead only focused on risk.&lt;br&gt;&lt;br&gt;For me, the difference in activity would seem to be rather minimal...at least notionally.</description>
		<content:encoded><![CDATA[<p>Brad,</p>
<p>Good to hear from you!  I will have to agree that I love the way in which you&#39;ve presented the information regarding continuous compliance in the linked video.  </p>
<p>The milestone approach is, definitely, not sufficient in adopting a risk-based stance.  I suppose my query, in specific, was regarding PCI-DSS and what folk would choose to do differently than stated in the requirements if they did, in fact, not have to worry about compliance verification and instead only focused on risk.</p>
<p>For me, the difference in activity would seem to be rather minimal&#8230;at least notionally.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bradgarland</title>
		<link>http://tylerhannan.com/2009/12/compliance-vs-security-a-thought-exercise/comment-page-1/#comment-47</link>
		<dc:creator>bradgarland</dc:creator>
		<pubDate>Thu, 17 Dec 2009 18:40:50 +0000</pubDate>
		<guid isPermaLink="false">http://tylerhannan.com/?p=198#comment-47</guid>
		<description>Hey Tyler, &lt;br&gt;&lt;br&gt;Well looky there, now you guys are getting into my world. ;)  I totally agree that the traditional model of auditing once a year (milestones) is broken.  We have shifted our perspective in this and moved to what we call &quot;continuous compliance&quot;.  Instead of this one point in time mentality we instead work to ingrain compliance in everyday processes and distribute the workload across the year.  Lastly, we&#039;ve big fans of what the collaboration tools do to enable this type of process and see them going hand in hand.&lt;br&gt;&lt;br&gt;If you&#039;re interested, we did a video that talks about continuous compliance that we&#039;re pretty proud of located here: &lt;a href=&quot;http://bit.ly/8Glen9&quot; rel=&quot;nofollow&quot;&gt;http://bit.ly/8Glen9&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Hey Tyler, </p>
<p>Well looky there, now you guys are getting into my world. <img src='http://tylerhannan.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />   I totally agree that the traditional model of auditing once a year (milestones) is broken.  We have shifted our perspective in this and moved to what we call &#8220;continuous compliance&#8221;.  Instead of this one point in time mentality we instead work to ingrain compliance in everyday processes and distribute the workload across the year.  Lastly, we&#39;ve big fans of what the collaboration tools do to enable this type of process and see them going hand in hand.</p>
<p>If you&#39;re interested, we did a video that talks about continuous compliance that we&#39;re pretty proud of located here: <a href="http://bit.ly/8Glen9" rel="nofollow">http://bit.ly/8Glen9</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
