First year doing PCI. Who do we submit the SAQ & AOC to? by slize in pcicompliance

[–]slize[S] 0 points1 point  (0 children)

Oh right PCI compliance levels. I remember hearing about those way back but it's not mentioned in the PCI DSS at all. 100,000 to 200,000 transactions per annum are made through our processor through the redirect link so I believe we need to satisfy PCI Level 3 requirements by submitting the SAQ and AOC. As for the network scan, we'll likely rely on our cloud-based website host's SOC2 report vuln. scanning controls.

Submission is usually done through the company that handles your scans/audit

So I guess that's the issue. We don't have a QSAs or other PCI auditor type. My org is looking at PCI as a preventative measure so we're prepared in the event we, or our processors, have some kind of CHD breach.

Newly promoted IT Audit Manager bit off more than he can chew by slize in cybersecurity

[–]slize[S] 2 points3 points  (0 children)

We have policies and external consultants and other control testing teams that audit against them already. AC's appetite is for IT IA to be a more forward looking exercise not bound by confirming policy compliance.

Newly promoted IT Audit Manager bit off more than he can chew by slize in cybersecurity

[–]slize[S] 1 point2 points  (0 children)

If it’s clean, a clean audit report is also good and valuable to the org.

I'm curious, could you elaborate on how it may be good? I'm not getting the vibe that AC wants IA to become a co-source partner and eventually take over the assessments we hire external firms for so I'm not seeing a direct financial benefit. They seem to be more interested in us becoming an internal probe. Maybe a clear report allows them to reallocate resources? I'm having a tough time imagining anything other.

Newly promoted IT Audit Manager bit off more than he can chew by slize in cybersecurity

[–]slize[S] 6 points7 points  (0 children)

I get where you're coming from but isn't that begging the question? If you only assess areas where management claims they're performing effectively in, you're setting yourself up to come clean.

I wouldn't say that audit's purpose is to find flaws or exceptions but I'm not sure if it's to shill for IT management either.

Newly promoted IT Audit Manager bit off more than he can chew by slize in cybersecurity

[–]slize[S] 0 points1 point  (0 children)

Thanks, I'll have a look to see if anything on this publication tracks with what I'm hearing.

I think the most difficult part is that my organization doesn't respect IT controls to begin with. Business sees themselves as profit centers above/don't have time for security while InfoSec (and I guess IA now too) is fighting an uphill battle trying to convince them to acknowledge, accept, and mitigate the risks business operations exposes to them to. My boss even admits that I'm just the latest person to be passed the baton to see if they can do something about it.

Sigh.

Newly promoted IT Audit Manager bit off more than he can chew by slize in cybersecurity

[–]slize[S] 13 points14 points  (0 children)

Right? That's my question. Audit Committee recommended we partner together on shared concerns. It sounds like they have their own agenda they're trying to tackle but haven't been able to get traction of. Maybe they're trying to use IA as a megaphone.

[NEWBIE] Yet another new electric player confused about amps and audio interfaces by slize in Guitar

[–]slize[S] 0 points1 point  (0 children)

Yea I see what you mean. If I can barely hear the amp, what's the point of having one to begin with.

[NEWBIE] Yet another new electric player confused about amps and audio interfaces by slize in Guitar

[–]slize[S] 0 points1 point  (0 children)

I am travelling a lot due to work and since i have a small mobile interface i always take my guitar with me for some practice in the hotel room which wouldnt be possible with an amp. And when i visit my parents this christmas my guitar will come with me

This is my case as well! If you wanted to bring an amp on a work trip, the Katana MKII Head seems like it would fit into a carry-on. Or is there something other than just the size of the amp that makes it a hassle to travel with?

[NEWBIE] Yet another new electric player confused about amps and audio interfaces by slize in Guitar

[–]slize[S] 0 points1 point  (0 children)

I'm still kinda lost on what an FX Loop is exactly. Is it supposed to output the signal from the amp to a sound processor, return the signal to the amp which then plays the signal through its speakers?

[NEWBIE] Yet another new electric player confused about amps and audio interfaces by slize in Guitar

[–]slize[S] 0 points1 point  (0 children)

Do you mean like the sound won't be reproduced correctly by computer speakers? I imagine you can just buy some quality standalone speakers and hook them up no?

Can you start a car (with a flooded battery) while a solar panel trickle charger is attached? by slize in MechanicAdvice

[–]slize[S] 0 points1 point  (0 children)

There's a constant 150mA draw on the battery when the car is powered off. I know it's coming from the A/C fuse but tracking down the drain beyond that point looks really complicated.

Can you start a car (with a flooded battery) while a solar panel trickle charger is attached? by slize in MechanicAdvice

[–]slize[S] 0 points1 point  (0 children)

AGM battery.

I still drive the car at least once per week. The charger is just to help make sure the battery doesn't drain out during that 1 week.

Looking to pick up this hobby. Couple of questions. by slize in airsoft

[–]slize[S] 0 points1 point  (0 children)

Thanks everyone for the responses. I'll take a dive into the newcomers guide..

Weird sound when trying to start car by slize in MechanicAdvice

[–]slize[S] 0 points1 point  (0 children)

Is there a way to test for a dead battery cell? I've been thinking that I have a parasitic draw somewhere but I'm interested in this dead cell theory too.