·970 words·5 mins
What the new mapping actually buys you, where teams misread it as control equivalence, and how much rework that mistake creates.
·1090 words·6 mins
The Council named future technology and AI innovation in its request for comments. Here’s how the RFC process works and what happens next.
·1118 words·6 mins
Blockchain C2 removes the domain you’d normally report. Why that pushes defense to exactly where PCI DSS 6.4.3 and 11.6.1 already point.
·1872 words·9 mins
Two weeks after writing about the structural problems with compliance platforms, the allegations landed. What assessors already knew.
·1754 words·9 mins
If the AppsFlyer script loads on your payment pages, you may have been serving malicious code. What the requirements actually ask you to do.
·1414 words·7 mins
A reality check on compliance automation platforms, the gap between generated evidence and assessed controls, and the questions to ask.
·1453 words·7 mins
PCI DSS v4.x wasn’t written with AI in mind. Here’s where the framework holds up, where there’s room to grow, and how the Council is engaging.
·1265 words·6 mins
Twenty years of standards, assessor programs, and a global ecosystem. What the Council’s inaugural annual report says about where it’s heading.
·1363 words·7 mins
Read-only evidence collection for assessor review: FortiGate, Palo Alto, Cisco, Azure, AWS, and OS-level configuration exports.
·1649 words·8 mins
Stolen card data is sold at industrial scale. What the carding economy means for your PCI DSS scoping, and why many programs frame it wrong.