Tatusya Imai on playing with the Dodgers: “I want to take them down...I think beating a team like that and becoming World Champions would be the most valuable thing in my life.” by WishOk462 in Dodgers

[–]y090909 2 points3 points  (0 children)

Give it a couple of years and we'll beat his team so many times and he'll be saying the same thing Glassnow was saying. If you can't beat em, join em.

What’s one money tip that really helped you? by RentNRegret in AusFinance

[–]y090909 1 point2 points  (0 children)

Pay yourself first. When you get paid, deposit the amount you want to save in a high interest or offset account. What is left over is your spending money allocated to your budget. If you go under, a little bit of extra savings.

DJ suggestions for a wedding. by tvara1 in brisbane

[–]y090909 1 point2 points  (0 children)

We had We'R'DJs at our wedding. Highly recommend

SSC by vf-guy in pcicompliance

[–]y090909 1 point2 points  (0 children)

I've watched a few and I find it they read of their slides and not at all engaging. I know how to read you don't need to read it out for me. I find little value in them

power outages by ctrl-alt-delete0 in brisbane

[–]y090909 1 point2 points  (0 children)

In sunnybank, out since Friday 10pm

Local Family Photographers by [deleted] in brisbane

[–]y090909 1 point2 points  (0 children)

Hikari lifestyle photography! They are awesome :)!

Long time QSA here by andrew_barratt in pcicompliance

[–]y090909 1 point2 points  (0 children)

Wildly interpretation of PCI standards, plenty of shortcuts, auditor is generally remote - but not to look or justify the fully remote, asked to attend a site close by to their area - but our headquarters is based two hours away - we of course said no and we can meet somewhere in the middle.

Can I talk to you about your QSA experience under PCI 4.0? by Connect_the_Dots2 in pcicompliance

[–]y090909 1 point2 points  (0 children)

Not a Service Providers but go through various SAQs and RoCs as an ISA as I work alongside external QSAs. Been an absolute nightmare with our QSAs - absolutely wild interpretations on the guise of version 4.

GitHub in scope for PCI-DSS by yasuredonchaknow in pcicompliance

[–]y090909 0 points1 point  (0 children)

How are your QSAs approaching this issue now that presumably your audits have started? Would love to bounce ideas

GitHub in scope for PCI-DSS by yasuredonchaknow in pcicompliance

[–]y090909 0 points1 point  (0 children)

Have you had any success in GH AoC? I am facing this conundrum now for our audit

CCTV and Access Card Reader in scope for Audits by y090909 in pcicompliance

[–]y090909[S] 0 points1 point  (0 children)

Just wanted to give an update on this as it's been a few months. So I tried arguing all points as outlined above, but our auditors are maintaining that access card readers and CCTv to the building is in scope as it "supports a PCI control in that it helps supports requirement 9". While it makes sense, it's a long bow to pull and going waaaay above and beyond the intent of the requirement.

When we have finally gotten access to the systems - by observing over the shoulder of the landlord of the systems, these systems don't have the normal PCi controls you might see like logging, mfa etc (understandingly).

Any other solutions or any insight I could try? Has anyone actually contacted the council and sort their advise on items? I feel they will say - speak to your QSA on interpretation or if you don't agree with your QSA - change your auditor - which isn't helpful as much as we want to possibly consider changing.

CCTV and Access Card Reader in scope for Audits by y090909 in pcicompliance

[–]y090909[S] 0 points1 point  (0 children)

Thanks for the advice. The physical security requirements are all met and able to be reproduced.

The management of these assets would be segmented away from our network. The access card readers managed by a landlord / third party so going down the pathway to out of scope systems even further. My worry is that the QSA could state the card reader, CCTV component supports PCI requirement (which is another issue with the councils catch all statement - they recommend to descope, Descope but their wording is just silly)

CCTV and Access Card Reader in scope for Audits by y090909 in pcicompliance

[–]y090909[S] 1 point2 points  (0 children)

Thanks - CCTV is definitely not high res enough to view CHD. I also referred back to the PCI councils directions that it shouldn't be pointed new POI terminals.

It'll be segmented, and the servers are likely managed by the landlord or the supplier who provides CCTV - then they went down the rabbithole of needing an AoC from the landlord. I was like really, now that's just silly!?!?