Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
dTub
Скачать

Security Training for Beginners | Cyber Security Training | Get into Cyber

Автор: Mike Miller - Break in Cyber

Загружено: 16 нояб. 2022 г.

Просмотров: 47 943 просмотра

Описание:

What is the most overlooked position when getting into the Cyber Security field? As promised in my last video I'll break it down.

Let's talk about being a "Security Auditor"

Fortunately and unfortunately one of the biggest drivers for information security is compliance driven.

Fortunately compliance forces companies and organizations to comply with certain standards around their security implementation. Unfortunately, many companies are only spending money because of compliance. Compliance absolutely does not equal security, but it is still the reason that companies are spending proactive money to protect their digital assets.

There are various types of security frameworks that companies must comply to, but for this particular post I'm going to talk about one that I have been working in and out of for years, which is PCI compliance. PCI stands for Payment Card Industry, meaning credit/debit cards.

The PCI framework was set in place to protect consumers from having their credit card information go into the wrong hands. PCI standards for compliance are developed and managed by the PCI Security Standards Council.

Any business that takes a certain amount of credit cards must comply to PCI standards. There are 4 levels of merchants, which are determined by the amount of credit card transactions per year. Today I'm just going to talk about Level 1 merchants.

Level 1 merchants (processing over 6 million transactions) each year must have a RoC (Report on Compliance) sign off from a PCI-QSA which is someone who has been certified as an auditor from the PCI Council. These RoC reports have over 300 security requirements that must be met by the business. At a high level, these include 12 major requirements for things such as firewalls, passwords, encryption, antivirus, physical protection requirements, vulnerability scans, penetration testing, and others.

A third party QSA is the only person that can sign off on a RoC for the business. QSAs are in extremely high demand. They do not have to be extremely technical, but they must know how to use their resources to gather documentation and evidence that the company is meeting standards.

Many merchants that I have worked with over the years do not understand the PCI security requirements. It is the QSAs job to explain the requirements as effectively as possible to the business.

However, often times there are PCI GAP assessments conducted prior to an actual QSA doing their assessment. This assessment can be done by anyone who understands the PCI requirements and is able to help the business understand how well their infrastructure aligns with being compliant. It costs much less to have the business work with someone to do a GAP assessment to help them align with compliance before a QSA does the actual assessment.

It doesn't cost a penny to learn the requirements. Reach out for questions!

#cybersecurity #infosec #security

Security Training for Beginners | Cyber Security Training | Get into Cyber

Поделиться в:

Доступные форматы для скачивания:

Скачать видео mp4

  • Информация по загрузке:

Скачать аудио mp3

Похожие видео

Cyber Security Full Course 2024 | Cyber Security Course Training For Beginners 2024 | Simplilearn

Cyber Security Full Course 2024 | Cyber Security Course Training For Beginners 2024 | Simplilearn

Cybersecurity For Beginners | Basics of Cyber security For Beginners Complete Course, Google

Cybersecurity For Beginners | Basics of Cyber security For Beginners Complete Course, Google

Nightcore Music Mix 2025 🎧 EDM Remixes of Popular Songs 🎧 EDM Best Gaming Music Mix

Nightcore Music Mix 2025 🎧 EDM Remixes of Popular Songs 🎧 EDM Best Gaming Music Mix

Таймер 30 Минут

Таймер 30 Минут

Mega Hits 2025 🌱 The Best Of Vocal Deep House Music Mix 2025 🌱 Summer Music Mix 2025 #4

Mega Hits 2025 🌱 The Best Of Vocal Deep House Music Mix 2025 🌱 Summer Music Mix 2025 #4

Cyber Security Training for Beginners: Get into Cybersecurity with Zero Experience

Cyber Security Training for Beginners: Get into Cybersecurity with Zero Experience

Ethical Hacking in 12 Hours - Full Course - Learn to Hack!

Ethical Hacking in 12 Hours - Full Course - Learn to Hack!

How I Would Learn Cyber Security If I Could Start Over in 2025 (6 Month Plan)

How I Would Learn Cyber Security If I Could Start Over in 2025 (6 Month Plan)

How I Got a Cyber Security Job With No Experience in 2024

How I Got a Cyber Security Job With No Experience in 2024

TECHNO MIX 2024 💥 Remixes Of Popular Songs 💥 Only Techno Bangers #023

TECHNO MIX 2024 💥 Remixes Of Popular Songs 💥 Only Techno Bangers #023

© 2025 dtub. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]