<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>27k1 PCI DSS and ISO 27001 Security Software</title>
	<atom:link href="https://27k1.com/feed" rel="self" type="application/rss+xml" />
	<link>https://27k1.com</link>
	<description>PCI DSS v4.0 Credit Card Security Applications &#38; ISO 27001 Information security management software</description>
	<lastBuildDate>Fri, 13 Dec 2024 11:56:16 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://27k1.com/wp-content/uploads/27k1squarewhitelogo-100x100.png</url>
	<title>27k1 PCI DSS and ISO 27001 Security Software</title>
	<link>https://27k1.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>27k1 ROC Management System &#8211; Features and QSA References</title>
		<link>https://27k1.com/27k1-roc-management-system-features-and-qsa-references</link>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Fri, 13 Dec 2024 11:52:10 +0000</pubDate>
				<category><![CDATA[27k1 News]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://27k1.com/?p=2695</guid>

					<description><![CDATA[December 2024 It&#8217;s a fact that the full, PCI DSS v4.0.1 ROC template requires the QSA to complete 577 fields in Part I and 3552 fields in Part II. Part I being focused upon the Assessment Overview, with Part II split between Sampling &#38; Evidence and Findings &#38; Observations. Completing 4,129 fields across all Requirements is a challenging task that ...]]></description>
										<content:encoded><![CDATA[<p>December 2024</p>
<p>It&#8217;s a fact that the full, PCI DSS v4.0.1 ROC template requires the QSA to complete 577 fields in Part I and 3552 fields in Part II. Part I being focused upon the Assessment Overview, with Part II split between Sampling &amp; Evidence and Findings &amp; Observations. Completing 4,129 fields across all Requirements is a challenging task that demands accuracy in order to deliver a high quality ROC assessment. A Physical Storage Service Provider or Multi-Tenant Service Provider ROC&#8217;s may be shorter, but still require the same attention to detail.</p>
<p>The 27k1 RMS has been developed as a digitized version of the analogue, ROC assessment template. In developing this software, 27k1 has devised numerous automated and time saving features that intelligently, auto-populate the ROC , AOC and Customized Control worksheets.</p>
<p>Of the 4,129 fields, the 27k1 RMS auto-populates 3755 fields across Parts 1 and 2.</p>
<p>Starting by selecting the correct ROC assessment type and establishing the Eligibility Criteria, the logic built into the software instantly populates hundreds of fields that are drawn from a tailored, Response Library. Specific fields will immediately be justified as &#8220;Not Applicable&#8221; and hundreds more will move to an &#8220;In Progress&#8221; status, waiting for the QSA to continue the work until it is ready for QA.</p>
<p>Because Parts I and II have been integrated, the QSA can easily move around the digitized ROC assessment, referencing evidence, interviews, observations and findings, all of which being hyper-linked to the application and located within a secure data repository. Clear reports across every Section and Requirement highlight the status of the ROC, which may be shared with the client.</p>
<p>The QSA may work in an agile way, such that QA may be completed on a section-by-section basis, rather than wait for the entire ROC assessment to have been prepared for final review. Work completed by the QSA and QA team within the 27k1 RMS software, will output into their branded, analogue ROC template.</p>
<p>Feedback from QSA companies using the system suggest that up to 7 days may be saved from a 10 day ROC assessment, based on a 7-hour working day. At $1,000 per day, this will translate to an immediate return on investment, saving the QSAC around $7,000 per ROC assessment.</p>
<p>Here&#8217;s what 27k1&#8217;s QSA clients had to say:</p>
<p><img decoding="async" class="wp-image-2696 alignleft" src="https://27k1.com/wp-content/uploads/3Factor.png" alt="27k1 ROC Management System - Features and QSA References 4" width="100" height="112"></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong><em>&#8220;The 27k1 ROC Management System has proven invaluable with the updates to PCI DSS and the revised ROC reporting template, which requires numerous radio buttons to be selected and completed. The application is highly user-friendly, and the customer support is exceptional, with the team responding to inquiries and requests almost immediately. The time savings we&#8217;ve achieved by using the 27k1 ROC Management System has allowed us to dedicate more effort to guiding our customers on how best to meet PCI DSS requirements.  Overall, the application is a great tool, completely recommend it to maximize efficiencies and increase productivity.&#8221;</em> </strong> Tania Nicholas, QSA, Director of PCI Compliance Services at 3Factor (<a href="https://www.3factor.com/" target="_blank" rel="noopener">https://www.3factor.com/</a>).</p>
<p><img decoding="async" class="wp-image-2697 alignleft" src="https://27k1.com/wp-content/uploads/RGP-logo.png" alt="27k1 ROC Management System - Features and QSA References 5" width="150" height="84" srcset="https://27k1.com/wp-content/uploads/RGP-logo.png 138w, https://27k1.com/wp-content/uploads/RGP-logo-100x56.png 100w" sizes="(max-width: 150px) 100vw, 150px" /></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong><em>&#8220;I want to thank everyone at 27k1 for their support in recent weeks as we completed our first ROC using the 27k1 RMS tool! Your openness to our suggestions for streamlining our work has been invaluable. This collaboration improves the product for everyone, and I&#8217;m so excited to be a part of this user community.&#8221;</em></strong> Jacqueline Bertram &#8211; Senior Director, Cyber Security &#8211; <a href="https://rgp.com/" target="_blank" rel="noopener">RGP &#8211; RGP global consulting and project execution for business transformation</a></p>
<p><img decoding="async" class="alignnone wp-image-2698" src="https://27k1.com/wp-content/uploads/Evolve-Online-Logo.png" alt="27k1 ROC Management System - Features and QSA References 6" width="215" height="76" srcset="https://27k1.com/wp-content/uploads/Evolve-Online-Logo.png 215w, https://27k1.com/wp-content/uploads/Evolve-Online-Logo-100x35.png 100w" sizes="(max-width: 215px) 100vw, 215px" /></p>
<p><span style="font-family: 'Arial',sans-serif;"><em><strong>&#8220;The 27K1 PCI DSS auditing tool offers a comprehensive and user-friendly solution for managing our PCI DSS compliance. Its </strong></em></span><span style="font-family: 'Arial',sans-serif;"><em><strong>intuitive </strong></em></span><span style="font-family: 'Arial',sans-serif;"><em><strong>interface made the auditing process seamless and efficient.&#8221;</strong></em> Ritchie Jeune &#8211; Managing Director, <a href="https://evolve-online.com/" target="_blank" rel="noopener">Home &#8211; Evolution Global Security Company</a></span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Brigantia Partners Limited &#8211; Customer Reference &#8211; December 2023</title>
		<link>https://27k1.com/brigantia-partners-limited-customer-reference-december-2023</link>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Fri, 15 Dec 2023 15:53:07 +0000</pubDate>
				<category><![CDATA[27k1 News]]></category>
		<category><![CDATA[27k1]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[International Standards Organisation]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[ISO/IEC 27001]]></category>
		<guid isPermaLink="false">https://27k1.com/?p=2432</guid>

					<description><![CDATA[Brigantia Partners Limited is a reseller of &#8220;best-in-class&#8221; cybersecurity software, based in Thirsk, Yorkshire.  The business supports numerous security software vendors and thousands of channel partners, helping them to grow and in turn, secure their customers&#8217; businesses. Given the nature of the software products and services that they sell, the client base and commercial relationships, Brigantia recognised the need to ...]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class=" wp-image-2425 aligncenter" src="https://27k1.com/wp-content/uploads/Brigantia-OIP-1-300x93.jpeg" alt="Brigantia Partners Limited - Customer Reference - December 2023 8" width="294" height="91" srcset="https://27k1.com/wp-content/uploads/Brigantia-OIP-1-300x93.jpeg 300w, https://27k1.com/wp-content/uploads/Brigantia-OIP-1-100x31.jpeg 100w, https://27k1.com/wp-content/uploads/Brigantia-OIP-1.jpeg 350w" sizes="auto, (max-width: 294px) 100vw, 294px" /></p>
<p>Brigantia Partners Limited is a reseller of &#8220;best-in-class&#8221; cybersecurity software, based in Thirsk, Yorkshire.  The business supports numerous security software vendors and thousands of channel partners, helping them to grow and in turn, secure their customers&#8217; businesses. Given the nature of the software products and services that they sell, the client base and commercial relationships, Brigantia recognised the need to achieve ISO 27001 certification to demonstrate that they operate a robust and secure Information Security Management System. The task of setting up the ISMS and achieving ISO 27001 certification was charged to Rupert Abrahams. Brigantia Partners received their ISO 27001 certificate in December 2023 and this is what Rupert had to say:</p>
<p><em><strong>&#8220;The 27k1 application has been great at simplifying and guiding us through the process of achieving the ISO 27001 accreditation. When we started our implementation, we were using multiple spreadsheets to manage our Information Security management system. We bought the application to try and simplify this and since using it the whole process has been a lot easier. We have found that we can manage all aspects of our system within it including the documentation, asset management and running the audits and risk assessments. </strong></em></p>
<p><em><strong>It is very easy to use and navigate as the application is laid out very clearly with different sections and intuitive to use, and we required only minimal training. When we have need any support 27k1 have responded very quickly and dealt with our queries.</strong></em></p>
<p><em><strong>When doing our full audit, the application made it so easy to demonstrate our compliance against the controls and the reports module was particularly helpful in showing activities that had been carried out. Our auditor did say that he thought the application was particularly helpful in guiding us through the process and the proof of this is that we breezed through our certification!&#8221;</strong></em></p>
<p>Rupert Abrahams &#8211; Information Security and Technical Manager</p>
<p>Brigantia Partners Limited &#8211; www.brigantia.com &#8211; 0203 358-0090</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What I learned at the Portland, PCI Community Meeting&#8230;</title>
		<link>https://27k1.com/what-i-learned-at-the-portland-pci-community-meeting</link>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Wed, 27 Sep 2023 09:47:23 +0000</pubDate>
				<category><![CDATA[27k1 News]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[PCI DSS v4.0]]></category>
		<category><![CDATA[PCI SSC]]></category>
		<guid isPermaLink="false">https://27k1.com/?p=2368</guid>

					<description><![CDATA[I absolutely admire and respect QSA&#8217;s! QSA’s are highly qualified, very experienced and hold deep, PCI DSS subject matter knowledge. They need these attributes since completing the PCI DSS v4.0 Report On Compliance is complex, stressful and frequently leads to burnout! Regarding PCI DSS v4.0 &#8211; QSA’s start by understanding the client’s organisation, then review them against: Part 1: Assessment ...]]></description>
										<content:encoded><![CDATA[<p><strong>I absolutely admire and respect QSA&#8217;s!</strong></p>
<p>QSA’s are highly qualified, very experienced and hold deep, PCI DSS subject matter knowledge. They need these attributes since completing the PCI DSS v4.0 Report On Compliance is complex, stressful and frequently leads to burnout!</p>
<p><strong>Regarding PCI DSS v4.0 &#8211; QSA’s start by understanding the client’s organisation, then review them against:</strong></p>
<ul>
<li>Part 1: Assessment Overview – 46 pages</li>
<li>Part 2: Breakdown of section requirements – 440 pages</li>
<li>Validation fields – 700: covering Interviews, Observations, Document fields etc</li>
</ul>
<p><img loading="lazy" decoding="async" class=" wp-image-2369 aligncenter" src="https://27k1.com/wp-content/uploads/PCI-Community-Meeting-Portland-2023-225x300.jpg" alt="What I learned at the Portland, PCI Community Meeting... 10" width="243" height="324"></p>
<p><strong>As if that wasn’t enough….</strong> try adding the new INFI &#8211; Items Noted For Improvement report. Along with completing all the N/A fields for the unused Customised Approaches or Compensating Control Worksheets, QSAs now need to document whether there is an INFI or not for each and every PCI DSS requirement. Moreover, this could involve the creation of an internal report that potentially lists all 260 PCI DSS Requirements as either being N/A or as not having any INFI&#8217;s.</p>
<p><strong>Did I say that this is complex, stressful and frequently leads to burnout? </strong></p>
<p>Taking into account the time constraints wrapped around a Level 1 assessment, the Quality Assurance process and the commercial demands to achieve validation and signature before moving onto the next ROC, I now appreciate how demanding this role has become.</p>
<p><strong>The 27k1 RMS – ROC Management System</strong></p>
<p>27k1 Ltd recently introduced the 27k1 RMS to QSA companies attending the PCI Community Meeting, Portland, Oregon. The 27k1 RMS digitizes the ROC, so that the compliance work completed by QSA’s within the software, automatically populates the Level 1 assessment. We believe that the software will save up to 6 days from the completion of each assessment and reduce burnout.</p>
<p>The responses that we received from 27k1 RMS system demonstrations was overwhelming. Feedback from the QSA community confirmed that this purpose built software, intended for use by qualified QSA companies is unique, especially because a license agreement between the PCI SSC and 27k1 will allow the integration of their ROC template in word format into the software, so that the QSA’s compliance work will automatically populate the ROC. 27k1 will be the first company to offer this incredible feature.</p>
<p>For a no-obligation, system demonstration, simply contact: <a href="www.27k1.com/contact">www.27k1.com/contact</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>27k1 ROC Management System (RMS) &#8211; Launching September at the 2023 PCI SSC Community Meeting, Portland, USA</title>
		<link>https://27k1.com/27k1-roc-edition-launching-in-september-at-the-pci-ssc-community-meeting-portland-usa</link>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Fri, 14 Jul 2023 09:54:44 +0000</pubDate>
				<category><![CDATA[27k1 News]]></category>
		<category><![CDATA[27k1]]></category>
		<category><![CDATA[PCI DSS ROC]]></category>
		<category><![CDATA[PCI DSS v4.0]]></category>
		<category><![CDATA[PCI SSC]]></category>
		<category><![CDATA[Report On Compliance]]></category>
		<guid isPermaLink="false">https://27k1.com/?p=2324</guid>

					<description><![CDATA[Managing the security of financial transactions using credit cards and on-line payment systems is complex and problematic. At the same time, compliance with PCI DSS v4.0 requirements is essential, since system breaches and data corruption within a merchant organisation carries the threat of sanctions or expulsion from the credit card provider. To manage this situation, 27k1 Ltd has integrated the ...]]></description>
										<content:encoded><![CDATA[<p>Managing the security of financial transactions using credit cards and on-line payment systems is complex and problematic. At the same time, compliance with PCI DSS v4.0 requirements is essential, since system breaches and data corruption within a merchant organisation carries the threat of sanctions or expulsion from the credit card provider.</p>
<p>To manage this situation, 27k1 Ltd has integrated the PCI DSS v4.0 standard with its 27k1 ISMS software, creating 2 class leading compliance solutions:</p>
<p style="text-align: center;">1. The 27k1 ROC Management System (RMS), for use by PCI SSC approved QSA’s</p>
<p style="text-align: center;">2. The 27k1 SAQ Management System (SAQMS), for use by Level, 1, 2 and 3 Merchants</p>
<p><img loading="lazy" decoding="async" class=" wp-image-2325 aligncenter" src="https://27k1.com/wp-content/uploads/PCI-Levels-300x124.jpeg" alt="27k1 ROC Management System (RMS) - Launching September at the 2023 PCI SSC Community Meeting, Portland, USA 12" width="305" height="126" srcset="https://27k1.com/wp-content/uploads/PCI-Levels-300x124.jpeg 300w, https://27k1.com/wp-content/uploads/PCI-Levels-100x41.jpeg 100w, https://27k1.com/wp-content/uploads/PCI-Levels.jpeg 310w" sizes="auto, (max-width: 305px) 100vw, 305px" /></p>
<p>For QSA companies, completing the Report On Compliance for their Level 1 clients is an arduous task. The ROC requires accurate responses to 12 Requirements sections comprising in excess of 300 questions, with responses supported by Risk Assessments, Appendices, Network Scans, Diagrams, Interviews and more.</p>
<p>From selection of a Self-Assessment Questionnaire &#8211; SAQ, the correct PCI DSS v4.0 requirements are presented along with actions that need to be undertaken. Full progress reporting assists this activity, along with feature rich, automated reports.</p>
<p>Selection of more than one SAQ will enable a combined approach to be selected, automatically populating SAQ D with any exclusions nominated as “Not Applicable”, with a supporting justification.</p>
<p>Companies and ISA’s using the <a href="https://27k1.com/27k1-pci-dss-product-information">27k1 </a>SAQMS will benefit from this functionality as well as being able to run Risk Assessments on all IS Assets, manage Documents, take Audits, control their entire ISMS and produce rich, granular reporting.</p>
<p>Compliance work within the 27k1 software automatically populates SAQs, Appendices, Worksheets and the AOC. The software retains this work, so that subsequent SAQ completion in following years is fully supported.</p>
<p>The system has been architected to enable remote access by QSA’s so that they can support their clients.</p>
<p>Jeremy Martin, Co-Founder at 27k1 will be demonstrating this ground-breaking software at September’s <a href="https://events.pcisecuritystandards.org/2023-portland/speakers/jeremy-martin/" target="_blank" rel="noopener">PCI SSC Community Meeting</a> .</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>27k1 is coming to the U.S.A.</title>
		<link>https://27k1.com/27k1-is-coming-to-the-u-s-a</link>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Tue, 18 Apr 2023 11:21:30 +0000</pubDate>
				<category><![CDATA[27k1 News]]></category>
		<category><![CDATA[NIST CSF]]></category>
		<category><![CDATA[PCI DSS v4.0]]></category>
		<category><![CDATA[PCI SSC]]></category>
		<guid isPermaLink="false">https://27k1.com/?p=2296</guid>

					<description><![CDATA[18 April 2023 27k1 Ltd has agreed to showcase the ground-breaking, 27k1 PCI DSS v4.0 compliance software at the PCI SSC’s North America Community Meeting: Home &#8211; 2023 North America Community Meeting (pcisecuritystandards.org) In addition to reserving an exhibition booth, 27k1 plan to sponsor a slot within the Tech Exchange. Jeremy Martin will demonstrate the way in which the software supports ...]]></description>
										<content:encoded><![CDATA[<h2>18 April 2023</h2>
<p>27k1 Ltd has agreed to showcase the ground-breaking, 27k1 PCI DSS v4.0 compliance software at the PCI SSC’s North America Community Meeting: <a href="https://events.pcisecuritystandards.org/2023-portland" target="_blank" rel="noopener">Home &#8211; 2023 North America Community Meeting (pcisecuritystandards.org)</a></p>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-2297 aligncenter" src="https://27k1.com/wp-content/uploads/PCI-SSC-Portland-Meeting-300x74.png" alt="27k1 is coming to the U.S.A. 15" width="382" height="94" srcset="https://27k1.com/wp-content/uploads/PCI-SSC-Portland-Meeting-300x74.png 300w, https://27k1.com/wp-content/uploads/PCI-SSC-Portland-Meeting-100x25.png 100w, https://27k1.com/wp-content/uploads/PCI-SSC-Portland-Meeting.png 602w" sizes="auto, (max-width: 382px) 100vw, 382px" /></p>
<p>In addition to reserving an exhibition booth, 27k1 plan to sponsor a slot within the Tech Exchange. Jeremy Martin will demonstrate the way in which the software supports PCI DSS v4.0 compliance, automatically populating selected SAQs and the RoC from the compliance work completed across the requirements, controls and test requirements.</p>
<p>Full progress reporting with detailed actions assists this activity, along with feature rich, automated reports, so that Tech Exchange visitors will see how the software completes the Appendices, AoC and any CC worksheets that may have been used.</p>
<p>The system will support several types of organisation:</p>
<ol>
<li>QSA companies that are engaged by Level 1 entities to provide a Report on Compliance.</li>
<li>Entities that possess in-house, ISA capability, that need the services of a QSA to validate their SAQ submissions.</li>
<li>Level 2 and 3 entities that wish to manage an advanced ISMS from which selected SAQ’s may be automatically completed by the system and combined into a SAQ D Merchant or Service Provider, as necessary.</li>
</ol>
<p>The 27k1 PCI DSS software will enable risk assessments using the NIST Cyber Security Framework and will include a full list of PCI DSS v4.0 documents to support the compliance process.</p>
<p>In advance of the PCI SSC meeting, you can request a detailed, system review by contacting 27k1 at: <a href="https://27k1.com/contact">Contact 27k1 &#8211; 27k1 ISMS</a></p>
<p><img loading="lazy" decoding="async" class=" wp-image-2298 aligncenter" src="https://27k1.com/wp-content/uploads/27k1-jpeg-logo-300x83.jpg" alt="27k1 is coming to the U.S.A. 16" width="311" height="86" srcset="https://27k1.com/wp-content/uploads/27k1-jpeg-logo-300x83.jpg 300w, https://27k1.com/wp-content/uploads/27k1-jpeg-logo-100x28.jpg 100w, https://27k1.com/wp-content/uploads/27k1-jpeg-logo.jpg 400w" sizes="auto, (max-width: 311px) 100vw, 311px" /></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>A review of the 27k1 PCI DSS compliance software by Jim Seaman, IS Centurion Consulting Ltd</title>
		<link>https://27k1.com/a-review-of-the-27k1-pci-dss-compliance-software-by-jim-seaman-is-centurion-consulting-ltd</link>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Thu, 29 Dec 2022 12:25:20 +0000</pubDate>
				<category><![CDATA[27k1 News]]></category>
		<guid isPermaLink="false">https://27k1.com/?p=2090</guid>

					<description><![CDATA[&#160; 29.12.2022 The ever-present threat of payment card fraud and the increasing burden that comes with the effective management of your payment card program has made the implementation of a management system a business critical requirement. Now, imagine being able to harmonise the management system of the ISO/IEC 27001:2022 standard with the robustness of the PCI DSS 12 requirements? This ...]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class=" wp-image-2091 aligncenter" src="https://27k1.com/wp-content/uploads/centu_JPG.jpg" alt="A review of the 27k1 PCI DSS compliance software by Jim Seaman, IS Centurion Consulting Ltd 18" width="347" height="132" srcset="https://27k1.com/wp-content/uploads/centu_JPG.jpg 263w, https://27k1.com/wp-content/uploads/centu_JPG-100x38.jpg 100w" sizes="auto, (max-width: 347px) 100vw, 347px" /></p>
<p><strong>29.12.2022</strong></p>
<p>The ever-present threat of payment card fraud and the increasing burden that comes with the effective management of your payment card program has made the implementation of a management system a business critical requirement.</p>
<p>Now, imagine being able to harmonise the management system of the ISO/IEC 27001:2022 standard with the robustness of the PCI DSS 12 requirements? This is exactly the approach taken by the 27k1 PCI DSS platform.</p>
<p>Employing the principles from Clause 6.1.3 of the ISO/IEC 27001:2022, Clauses 4 to 10 remain whilst the Annex A controls are replaced by the PCI DSS 12 requirements &#8211; creating a PCI DSS Statement of Applicability (SOA). This helps entities to create a suitable management system for the treatment of the risks to their payment card operations.</p>
<p>Consequently, entities can create a hybrid between two ‘Best in Class’ industry information security standards, aka:</p>
<ul>
<li>A Payment Card Security Management System (PCSMS)</li>
</ul>
<p>Such an approach will help to meet some of the latest enhancements that arrived in March 2022 with the release of PCI DSS v4.0, e.g:</p>
<ul>
<li>#.1.1 – Requirement specific policies.
<ul>
<li>27k1 includes a document management system.</li>
</ul>
</li>
<li>#.1.2 – Defined roles.
<ul>
<li>Incorporated as part of the 27k1 management system.</li>
</ul>
</li>
<li>– Risk Management.
<ul>
<li>3.1 – Tactical Risk Assessments, supported through the 27k1 Risk Manager</li>
</ul>
</li>
<li>– PCI DSS Program Management.</li>
<li>– PCI DSS Scope validation and documentation.</li>
</ul>
<p>In addition, the 27k1 solution also helps to simplify the annual compliance submission by automatically populating the official Self-Assessment Questionnaires (SAQs) from the inputs into the 27k1 platform.</p>
<p>Furthermore, imagine the potential enhancements that can be gained:</p>
<ul>
<li>An effective management system to help ensure that all mandatory tasks have been assigned and tracked for completion.</li>
<li>An integrated solution to ensure that all supporting documentation and evidence is easily accessible.</li>
<li>The potential to use your PCSMS to have your payment card operations certified against ISO/IEC 27001:2022.</li>
<li>The potential to use your ISO/IEC 27001:2022 certified payment card operations (PCSMS) to meet the requirements of GDPR article 42 – Certification, by an accredited certification body (GDPR article 43) / UK DPA 2018 &#8211; Chapter 2, Para 17.</li>
</ul>
<p>The harmonisation between the management system, from the ISO/IEC 27001:2022, and the payment card specific PCI DSS security controls can help you to create a ‘Best in Class’ PCSMS, which in turn will enable you to simplify your PCI DSS compliance obligations and to significantly reduce the risks to your payment card operations.</p>
<p><span style="text-decoration: underline;">About Jim Seaman</span></p>
<p>Jim is the founder of IS Centurion Consulting Ltd, based in Castleford, Yorkshire. Jim has been dedicated to the pursuit of security throughout his extensive career. He served 22 years in the RAF Police, covering a number of specialist areas including physical security, aviation security, information security management, IT security management, cybersecurity management, security investigations, intelligence operations, and incident response and disaster recovery.</p>
<p>He has successfully transitioned his skills to the corporate environment and now works in areas such as financial services, banking, retail, manufacturing, e-commerce, and marketing. He is highly qualified within the information security sector, applying his skills to help businesses enhance their cybersecurity and InfoSec defensive measures and work with various industry security standards.</p>
<p>Jim is a published author, writing definitive guides to PCI DSS compliance and Protective Security, the books being available to purchase on Amazon.</p>
<p><a href="https://www.iscenturion.com/" target="_blank" rel="noopener">Computer security | IS Centurion Consulting Ltd | Castleford</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Sedcom Networks Limited &#8211; Customer Reference – 15th December 2022</title>
		<link>https://27k1.com/sedcom-networks-limited-customer-reference-15th-december-2022</link>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Thu, 15 Dec 2022 13:23:13 +0000</pubDate>
				<category><![CDATA[27k1 News]]></category>
		<guid isPermaLink="false">https://27k1.com/?p=2081</guid>

					<description><![CDATA[Sedcom is an IT support company, specialising in assisting SMEs (small and medium-sized businesses) within London and the South East. Sedcom was established over 15 years ago, and has grown to become one of the leading IT support providers in the region, winning several awards for its services and customer support. &#8220;27k1 played a huge part in making our ISO27001 ...]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="wp-image-2082 aligncenter" src="https://27k1.com/wp-content/uploads/Sedcom-logo.jpeg" alt="Sedcom Networks Limited - Customer Reference – 15th December 2022 20" width="242" height="242" srcset="https://27k1.com/wp-content/uploads/Sedcom-logo.jpeg 200w, https://27k1.com/wp-content/uploads/Sedcom-logo-150x150.jpeg 150w, https://27k1.com/wp-content/uploads/Sedcom-logo-100x100.jpeg 100w" sizes="auto, (max-width: 242px) 100vw, 242px" />Sedcom is an IT support company, specialising in assisting SMEs (small and medium-sized businesses) within London and the South East. Sedcom was established over 15 years ago, and has grown to become one of the leading IT support providers in the region, winning several awards for its services and customer support.</p>
<p><strong><em>&#8220;27k1 played a huge part in making our ISO27001 certification journey as simple as possible. With minimal training, it was very easy to use, and we were able to spin it up in no time at all. If we had any queries about the application the 27k1 team got back to us very quickly and were great to deal with.</em></strong></p>
<p><strong><em>We found navigating around the application very straightforward as each Management section is clearly laid out, allowing us to jump straight to information we needed as we progressed our alignment to the ISO27001 framework. </em></strong></p>
<p><strong><em>What made everything so simple for us, our consultants, and the auditors was the reports module. This easily generated everything our auditor needed to see around risk management, management reviews, alignment to the controls and so much more, where we were able to pass our audit with flying colours.&#8221;</em></strong></p>
<p>Martyn Harvey, Technical Director</p>
<p>92c High Street, Billericay, Essex, CM12 9BT</p>
<p>www.sedcom.net</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Social Value Portal &#8211; Customer Reference – 7th October 2022</title>
		<link>https://27k1.com/social-value-portal-customer-reference-7th-october-2022</link>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Fri, 07 Oct 2022 15:57:35 +0000</pubDate>
				<category><![CDATA[27k1 News]]></category>
		<guid isPermaLink="false">https://27k1.com/?p=2051</guid>

					<description><![CDATA[Social Value Portal works across 4 UK offices, employing around 120 personnel. The company is dedicated to enabling organisations to empirically measure their social performance and contribution to their communities. By proving social performance, companies and organisations build trust with their customers and suppliers. They lead with purpose, demonstrating sustainability, stakeholder engagement and environmental wellbeing. To do this, Social Value Portal ...]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class=" wp-image-2044 aligncenter" src="https://27k1.com/wp-content/uploads/Social-Value-Portal-300x99.jpg" alt="Social Value Portal - Customer Reference – 7th October 2022 22" width="342" height="113" srcset="https://27k1.com/wp-content/uploads/Social-Value-Portal-300x99.jpg 300w, https://27k1.com/wp-content/uploads/Social-Value-Portal-100x33.jpg 100w, https://27k1.com/wp-content/uploads/Social-Value-Portal.jpg 347w" sizes="auto, (max-width: 342px) 100vw, 342px" /></p>
<p>Social Value Portal works across 4 UK offices, employing around 120 personnel. The company is dedicated to enabling organisations to empirically measure their social performance and contribution to their communities. By proving social performance, companies and organisations build trust with their customers and suppliers. They lead with purpose, demonstrating sustainability, stakeholder engagement and environmental wellbeing. To do this, Social Value Portal has developed TOMS – a data driven software solution that measures National Themes, Outcomes and Measures, which proves exactly how the organisation and its’ suppliers are making a difference.</p>
<p>Given the quantity and sensitivity of data received, Social Value Portal required a software solution that would help them to protect this data and enable them to achieve ISO 27001 certification.</p>
<p><strong>Social Value Portal chose the 27k1 ISMS software and this is what Peter Armitage had to say:</strong></p>
<p><em>“The 27k1 application provided much needed clarity and structure in aligning the information security processes and documentation at Social Value Portal with the ISO27001 requirements. The application allowed us to clearly link assets, documents, risks, and other organisational information against the controls, as well as tracking actions and managing our meetings and internal audits. During our full audit, the application and the reports that it generated made it straightforward to demonstrate our compliance against each control, and we were pleased to achieve accreditation within a year of working with the 27k1 ISMS.”</em></p>
<p><strong>Peter Armitage, Director of Technology</strong></p>
<p><strong>Social Value Portal &#8211; https://socialvalueportal.com</strong></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Guidelines for implementing PCI DSS v4.0 &#8211; 16.09.2022</title>
		<link>https://27k1.com/guidelines-for-implementing-pci-dss-v4-0</link>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Fri, 16 Sep 2022 13:07:34 +0000</pubDate>
				<category><![CDATA[27k1 News]]></category>
		<guid isPermaLink="false">https://27k1.com/?p=2001</guid>

					<description><![CDATA[Recent data shows that the global pandemic and the contraction of normal trading practices led to an increase in e-commerce and a consequent rise in online payments of 43%. In the US, this equated to an increase of $244.2 billion in 2020 alone. Recognising these increases, the Payment Card Industry Data Security Council updated PCI DSS v 3.2.1 and on ...]]></description>
										<content:encoded><![CDATA[<p>Recent data shows that the global pandemic and the contraction of normal trading practices led to an increase in e-commerce and a consequent rise in online payments of 43%. In the US, this equated to an increase of $244.2 billion in 2020 alone. Recognising these increases, the Payment Card Industry Data Security Council updated PCI DSS v 3.2.1 and on March 31<sup>st</sup> 2022, introduced PCI DSS v4.0</p>
<p>For those companies that manage high volumes of financial transactions using credit cards and on-line payment systems, compliance is essential. Enforcement of compliance with PCI Standards and determination of any non-compliance penalties are carried out by the individual payment brands, not by the PCI SSC. Non-compliance, system breaches and data corruption within a merchant organisation carries the threat of sanctions or expulsion from the credit card provider.</p>
<p>PCI DSS v4.0 will become mandatory for all organizations that process or store cardholder data by March 2024. The proliferation of online transactions isn’t the only reason the PCI Council created the v4.0 standard. Recent years have also seen a surge in cloud use, the rise of contactless payments and cybercriminals using increasingly sophisticated methods of intrusion and fraud.</p>
<p>PCI DSS v4.0 is intended to improve payment card industry security and mitigate against the growing threats posed by cyber criminals. Recent initiatives include:</p>
<ul>
<li>Expanded multi-factor authentication requirements</li>
<li>Updated password requirements</li>
<li>New e-commerce and phishing requirements to address ongoing threats</li>
</ul>
<p>The overall intention is to promote security as a continuous process, for example;</p>
<ul>
<li>Allocating clearly assigned roles and responsibilities for each requirement</li>
<li>Providing guidance to help people better understand how to implement and maintain security</li>
<li>Requirements for new reporting option to highlight areas for improvement and provide more transparency for report reviewers.</li>
</ul>
<p>PCI DSS adds further information security requirements, hence v4.0 is a major overhaul that requires a complete refocus on the technology behind the way in which payment card data is processed, managed and secured.</p>
<p>If your organization isn’t up to speed on current practice, it will certainly need to apply expert resources in order to comply with the v4.0 requirements. Indeed, a shift in mindset and culture may also be needed, since compliance is not a one-off exercise, but a continuous process. The PCI DSS approach places emphasis on top-down organizational change and best practice alignment.</p>
<p><img loading="lazy" decoding="async" class=" wp-image-1988 aligncenter" src="https://27k1.com/wp-content/uploads/PCI-DSS-v4.0-timetble.jpg" alt="Guidelines for implementing PCI DSS v4.0 - 16.09.2022 24" width="327" height="200" srcset="https://27k1.com/wp-content/uploads/PCI-DSS-v4.0-timetble.jpg 294w, https://27k1.com/wp-content/uploads/PCI-DSS-v4.0-timetble-100x61.jpg 100w" sizes="auto, (max-width: 327px) 100vw, 327px" /></p>
<p>The following steps will guide your business towards attaining compliance within the allocated timeframe as well as avoiding any audit fines or publicised data breaches.</p>
<ol>
<li>Create a detailed, auditable action plan for the implementation of PCI DSS v4.0, securing buy-in and resources from senior management.</li>
<li>Contrast PCI DSS v3.2.1 with PCI DSS v4.0 and upgrade to the new security requirements. For example, this will cover areas such as the protection of account data as opposed to the previous cardholder data. It may be necessary to restructure your network to adequately protect account data.</li>
<li>PCI DSS v4.0 emphasises the cultivation of a security mindset within the organization. Personnel must begin to view compliance as a continuous activity that protects sensitive data more so than simply a set of tasks designed to pass audits. Security and compliance teams should work together to implement a defined process for maintaining the security of the Cardholder Data Environment (CDE), including routine reviews of configurations and security.</li>
<li>Strengthen Security Configuration Management processes. Requirement 2 broadens the scope of SCM. Rather than focusing on vendor-defined defaults, the onus is now put on organizations to have their own security configuration program. In order to meet v4.0’s wider SCM scope, ensure that you monitor the configurations of networks, servers, firewalls, and all other components. SCM also helps auditors track compliance status over time. SCM tools help to reduce the time it takes to prepare for an audit and speed up the actual audit process as well.</li>
<li>Software solutions: The best way to achieve continuous PCI DSS v4.0 compliance is to deploy a total, software solution that supports the new, v4.0 controls, checks SCM and ensures that all assets are held securely. The 27k1 Enterprise Application has been developed with assistance from PCI DSS industry experts and will readily support compliance to PCI DSS v4.0.</li>
</ol>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>27k1 to launch the 27k1 ISMS Hybrid Software at DTX Europe, Excel Arena, LONDON &#8211; 12-13 October</title>
		<link>https://27k1.com/27k1-to-launch-the-27k1-enterprise-system-at-dtx-europe-excel-arena-london-12-13-october</link>
		
		<dc:creator><![CDATA[]]></dc:creator>
		<pubDate>Mon, 15 Aug 2022 15:25:08 +0000</pubDate>
				<category><![CDATA[27k1 News]]></category>
		<guid isPermaLink="false">https://27k1.com/?p=1952</guid>

					<description><![CDATA[Digital Transformation EXPO ( DTX ) is coming to ExCel LONDON on the 12th &#8211; 13th October and 27k1 Ltd will be taking its rightful place alongside the world’s leading IT brands and systems. In addition to promoting the 27k1 ISMS software, we are delighted to announce that we shall be using this opportunity to launch the new, 27k1 ISMS ...]]></description>
										<content:encoded><![CDATA[<p><strong><img loading="lazy" decoding="async" class="wp-image-1957 aligncenter" src="https://27k1.com/wp-content/uploads/DTX-NE17-Visit-Us-2022-300x37.png" alt="27k1 to launch the 27k1 ISMS Hybrid Software at DTX Europe, Excel Arena, LONDON - 12-13 October 26" width="510" height="63" srcset="https://27k1.com/wp-content/uploads/DTX-NE17-Visit-Us-2022-300x37.png 300w, https://27k1.com/wp-content/uploads/DTX-NE17-Visit-Us-2022-100x12.png 100w, https://27k1.com/wp-content/uploads/DTX-NE17-Visit-Us-2022.png 728w" sizes="auto, (max-width: 510px) 100vw, 510px" /></strong></p>
<p><strong>Digital Transformation EXPO ( DTX ) is coming to ExCel LONDON on the 12th &#8211; 13th October and 27k1 Ltd will be taking its rightful place alongside the world’s leading IT brands and systems.</strong></p>
<p>In addition to promoting the 27k1 ISMS software, we are delighted to announce that we shall be using this opportunity to launch the new, 27k1 ISMS Hybrid Software, which will extend the control sets within the software to support selected compliance standards.</p>
<p>Building on the ISO 27002 framework and 27k1 ISMS software platform, the 27k1 Hybrid software will now support PCI DSS version 4.0 &#8211; the latest, Payment Card Industry Digital Security Standard, published on March 31<sup>st</sup>, 2022.</p>
<p>The PCI DSS is a global standard set by the PCI Security Standards Council (PCI SSC) and is designed to improve the security of payment card transactions and reduce credit card fraud. The standard is set by the PCI DSS Council &#8211; a global forum led by a policy-setting Executive Committee composed of representatives from American Express, Discover, JCB International, Mastercard, UnionPay and Visa Inc.</p>
<p>For those companies that manage high volumes of financial transactions using credit cards and on-line payment systems, compliance is essential. Enforcement of compliance with PCI Standards and determination of any non-compliance penalties are carried out by the individual payment brands, not by the PCI SSC. Non-compliance, system breaches and data corruption within a merchant organisation carries the threat of sanctions or expulsion from the credit card provider.</p>
<p>Whilst there’s no “certification” for PCI DSS compliance, merchants are required to prove their compliance through self-assessment i.e. by completing the SAQ and the AOC – Attestation of Compliance, subject to the annual volume of transactions.</p>
<p>The 27k1 Enterprise Application has been developed with assistance from PCI industry experts and will readily support compliance to PCI DSS version 4.</p>
<p><strong>Come to DTX Europe and visit Stand NE17 to discuss your ISO 27001 or PCI DSS compliance needs with industry experts.</strong></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
