<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Pragmatic Auditor</title>
	<atom:link href="http://www.thepragmaticauditor.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://www.thepragmaticauditor.com</link>
	<description>the practical approach to assurance, compliance, and security</description>
	<lastBuildDate>Mon, 13 May 2013 15:56:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
		<item>
		<title>Colocation Strategies – Perspectives from Data Center World</title>
		<link>http://www.thepragmaticauditor.com/?p=1369</link>
		<comments>http://www.thepragmaticauditor.com/?p=1369#comments</comments>
		<pubDate>Mon, 13 May 2013 15:56:51 +0000</pubDate>
		<dc:creator>Douglas Barbin</dc:creator>
				<category><![CDATA[Compliance and Certification]]></category>
		<category><![CDATA[FedRAMP]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Industry Topics]]></category>
		<category><![CDATA[Payment Card Industry (PCI) Data Security]]></category>
		<category><![CDATA[SOC 1]]></category>
		<category><![CDATA[SOC 2]]></category>
		<category><![CDATA[SOC Reports]]></category>
		<category><![CDATA[SSAE 16 / ISAE 3402]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[certifications]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[Colocation]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[Data Center]]></category>
		<category><![CDATA[Data Center World]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[outsource]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[procurement]]></category>
		<category><![CDATA[regulations]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SOC]]></category>
		<category><![CDATA[SOC 3]]></category>
		<category><![CDATA[SSAE 16]]></category>

		<guid isPermaLink="false">http://www.thepragmaticauditor.com/?p=1369</guid>
		<description><![CDATA[I was delighted to be invited to speak on security and compliance during the Colocation Tutorial at Data Center World last week in Las Vegas, Nevada.  The tutorial was an all-day session for enterprise data center operations executives &#8211; mostly data center operators from large corporations that currently outsource to a colocation facility.  I had [...]]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter" title="colocation perspectives" src="https://www.brightline.com/App_Themes/Sas70/image/colocation-strategies-perspectives-from-data-center-world-614.png" alt="" width="614" height="176" /></p>
<p>I was delighted to be invited to speak on security and compliance during the Colocation Tutorial at <a href="http://www.datacenterworld.com/spring2013/">Data Center World</a> last week in Las Vegas, Nevada.  The tutorial was an all-day session for enterprise data center operations executives &#8211; mostly data center operators from large corporations that currently outsource to a colocation facility.  I had the privilege of joining a panel comprising of executives from RagingWire, Equinix, Schneider Electric, Dominion Virginia Power, Transitional Data Center Services, and Neustar.</p>
<p>I wanted to give the readers who were not able to attend the conference or tutorial session some of my key takeaways from the event:</p>
<p><strong>Not all colos are created equal</strong> – Fundamentally most individuals think that a colo facility just provides power and space.  However, those of us familiar with the business know that there can be embedded service providers and data centers within data centers.  Then, add a layer of complexity to the increased prominence of real estate companies, such as Digital Realty Trust, that specialize in data center property management.    Lee Tamassia from Equinix provided an excellent overview of the different models from wholesale to retail up to and including cloud services.  Mr. Tamassia then discussed how these models integrate with different data center standards.  I was then able to add onto these comments to discuss compliance responsibility between a data center and its tenants.</p>
<p><strong>Data center operators may not think compliance is #1 priority </strong>– Imagine that!  When Jim Leach from RagingWire asked the audience who either managed or was exposed to compliance initiatives on a frequent basis – very few raised their hands.  Make no mistake – everyone expects the environment to be secure and more importantly reliable.  A few participants stated that compliance often was mandated from legal, IT security, or external auditors.  However, the day-to-day activities for these operation executives typically only revolve around topics such as power consumption, utilization, and resources &#8211; which affect the bottom line.</p>
<p><strong>Security and compliance should be a topic of focus early on (during the selection and procurement process) </strong>– Steve Gunderson from Transitional Data Center Services and Jim Weber from Neustar walked through a template and evaluation process that included looking at security and availability features as well as available audits.  One participant from a manufacturing company stated that “I don’t handle credit card information, but the fact that the data center has gone through <a href="http://www.brightline.com/pci">PCI</a>, in my mind puts them at a higher level.”</p>
<p><strong>The different compliance and certification acronyms can be confusing </strong>– I believe I was able to provide insight with this topic.  At a minimum, the participants walked away understanding that “<a href="http://www.brightline.com/soc">SSAE 16</a> certified” was technically incorrect and could be an indication of misleading marketing.  We also discussed <a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/summary/">HIPAA</a>, <a href="http://csrc.nist.gov/groups/SMA/fisma/index.html">FISMA</a>, and how a data center plays a role when its tenants (or the tenants’ customers) are the ones mandated to comply.</p>
<p>In summary, we auditors, just like those in security, can get so ingrained in the details of <a href="http://www.brightline.com/soc">SOC</a> reporting standards, <a href="http://www.brightline.com/pci">PCI</a> compliance requirements, <a href="http://www.brightline.com/fedramp">FedRAMP</a> authorizations, etc. that we often need reminding of the end-user’s perspective.  This conference brought a lot of insight to the auditor in me, and I hope the attendees took away some tangible recommendations and action points from the Colocation Tutorial.</p>
<p>On May 15<sup>th</sup>, I get another opportunity to speak – this time at the <a href="http://symposium.uptimeinstitute.com/">Uptime Institute</a> conference in Santa Clara, CA. Hope to see you there!</p>
<script type="text/javascript" src="https://cdn.socialtwist.com/2011080653625/script.js"></script><a class="st-taf" href="https://tellafriend.socialtwist.com:443" onclick="return false;" style="border:0;padding:0;margin:0;"><img alt="SocialTwist Tell-a-Friend" style="border:0;padding:0;margin:0;" src="https://images.socialtwist.com/2011080653625/button.png" onmouseout="STTAFFUNC.hideHoverMap(this)" onmouseover="STTAFFUNC.showHoverMap(this, '2011080653625', 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1369', 'Colocation+Strategies+%E2%80%93+Perspectives+from+Data+Center+World')" onclick="STTAFFUNC.cw(this, {id:'2011080653625', link: 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1369', title: 'Colocation+Strategies+%E2%80%93+Perspectives+from+Data+Center+World' });"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thepragmaticauditor.com/?feed=rss2&#038;p=1369</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BrightLine Celebrating 11 Years!</title>
		<link>http://www.thepragmaticauditor.com/?p=1357</link>
		<comments>http://www.thepragmaticauditor.com/?p=1357#comments</comments>
		<pubDate>Mon, 06 May 2013 13:34:22 +0000</pubDate>
		<dc:creator>avani.desai</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.thepragmaticauditor.com/?p=1357</guid>
		<description><![CDATA[BrightLine is excited to celebrate 11 years. We would not be where we are without our dedicated employees and loyal clients.  Thank you! &#160; &#160;]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter" title="BrightLine turns 11" src="http://www.brightline.com/App_Themes/Sas70/image/brightline-11-years-old.jpg" alt="" width="602" height="250" /></p>
<h3><strong>BrightLine is excited to celebrate 11 years.  We would not be where we are without our dedicated employees and loyal clients.  Thank you!</strong></h3>
<p>&nbsp;</p>
<p>&nbsp;</p>
<script type="text/javascript" src="https://cdn.socialtwist.com/2011080653625/script.js"></script><a class="st-taf" href="https://tellafriend.socialtwist.com:443" onclick="return false;" style="border:0;padding:0;margin:0;"><img alt="SocialTwist Tell-a-Friend" style="border:0;padding:0;margin:0;" src="https://images.socialtwist.com/2011080653625/button.png" onmouseout="STTAFFUNC.hideHoverMap(this)" onmouseover="STTAFFUNC.showHoverMap(this, '2011080653625', 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1357', 'BrightLine+Celebrating+11+Years%21')" onclick="STTAFFUNC.cw(this, {id:'2011080653625', link: 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1357', title: 'BrightLine+Celebrating+11+Years%21' });"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thepragmaticauditor.com/?feed=rss2&#038;p=1357</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BrightLine a Sponsor at The Payroll Group’s 2013 Annual Conference in Austin, Texas</title>
		<link>http://www.thepragmaticauditor.com/?p=1327</link>
		<comments>http://www.thepragmaticauditor.com/?p=1327#comments</comments>
		<pubDate>Thu, 02 May 2013 15:09:01 +0000</pubDate>
		<dc:creator>avani.desai</dc:creator>
				<category><![CDATA[SOC 1]]></category>
		<category><![CDATA[SOC 2]]></category>
		<category><![CDATA[SOC Reports]]></category>
		<category><![CDATA[SSAE 16 / ISAE 3402]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[Payroll]]></category>
		<category><![CDATA[payroll organizations]]></category>
		<category><![CDATA[payroll providers]]></category>
		<category><![CDATA[solutions]]></category>
		<category><![CDATA[The Payroll Group]]></category>

		<guid isPermaLink="false">http://www.thepragmaticauditor.com/?p=1327</guid>
		<description><![CDATA[&#160; via BusinesWire TAMPA, FL— May 2, 2013- BrightLine CPAs &#38; Associates, Inc., a leading provider of attestation and compliance services, is pleased to announce their sponsorship of The Payroll Group’s (TPG) 2013 Annual Conference.  The conference will take place from May 8th through May 11th in Austin, Texas. The conference is designed to help independent [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter" title="TPG Austin" src="https://www.brightline.com/App_Themes/Sas70/image/tpg-conference-2013.png" alt="" width="600" /></p>
<p>&nbsp;<br />
via <a href="http://www.businesswire.com/news/home/20130502005002/en">BusinesWire</a></p>
<p><strong>TAMPA, FL</strong>— May 2, 2013- <a href="http://www.brightline.com/">BrightLine CPAs &amp; Associates</a>, Inc., a leading provider of attestation and compliance services, is pleased to announce their sponsorship of The Payroll Group’s (TPG) 2013 Annual Conference.  The conference will take place from May 8th through May 11th in Austin, Texas.</p>
<p>The conference is designed to help independent payroll service providers from across the country to reduce overhead costs, share business best practices, and discuss challenges and success stories.  This year’s conference will also highlight the utilization of state of the art technology in providing payroll services.</p>
<p>“BrightLine is honored to sponsor the TPG Annual Conference as we have seen the requests from payroll service providers for <a href="http://www.brightline.com/soc">SOC  1</a> examinations and other related compliance services increase in recent years,” said Greg Miller, BrightLine’s attending Principal.  “This will be an ideal venue for us to share the market trends and compliance solutions with payroll providers.”</p>
<p>&nbsp;</p>
<script type="text/javascript" src="https://cdn.socialtwist.com/2011080653625/script.js"></script><a class="st-taf" href="https://tellafriend.socialtwist.com:443" onclick="return false;" style="border:0;padding:0;margin:0;"><img alt="SocialTwist Tell-a-Friend" style="border:0;padding:0;margin:0;" src="https://images.socialtwist.com/2011080653625/button.png" onmouseout="STTAFFUNC.hideHoverMap(this)" onmouseover="STTAFFUNC.showHoverMap(this, '2011080653625', 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1327', 'BrightLine+a+Sponsor+at+The+Payroll+Group%E2%80%99s+2013+Annual+Conference+in+Austin%2C+Texas')" onclick="STTAFFUNC.cw(this, {id:'2011080653625', link: 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1327', title: 'BrightLine+a+Sponsor+at+The+Payroll+Group%E2%80%99s+2013+Annual+Conference+in+Austin%2C+Texas' });"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thepragmaticauditor.com/?feed=rss2&#038;p=1327</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BrightLine Joins Top Data Center Industry Experts To Discuss “Colocation Strategies Tutorial” at AFCOM Data Center World 2013</title>
		<link>http://www.thepragmaticauditor.com/?p=1313</link>
		<comments>http://www.thepragmaticauditor.com/?p=1313#comments</comments>
		<pubDate>Tue, 23 Apr 2013 18:17:17 +0000</pubDate>
		<dc:creator>avani.desai</dc:creator>
				<category><![CDATA[SOC 1]]></category>
		<category><![CDATA[SOC 2]]></category>
		<category><![CDATA[SOC Reports]]></category>
		<category><![CDATA[SSAE 16 / ISAE 3402]]></category>
		<category><![CDATA[AFCOM]]></category>
		<category><![CDATA[assurance]]></category>
		<category><![CDATA[Colocation]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[RagingWire]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Spring Data Center World]]></category>

		<guid isPermaLink="false">http://www.thepragmaticauditor.com/?p=1313</guid>
		<description><![CDATA[Via BusinessWire TAMPA, FL — April 23, 2013 — BrightLine CPAs &#38; Associates, Inc., a leading provider of compliance and attestation reporting services, will be part of the Colocation Strategies Tutorial Session at the AFCOM Spring Data Center World 2013 conference.  The conference will be held on April 29th, 2013, at The Mandalay Bay Resort [...]]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter" title="Data Center World" src="http://www.brightline.com/App_Themes/Sas70/image/data-center-world-afcom-colocation-tutorial-session.png" alt="" width="614" height="228" /></p>
<p>Via <a href="http://www.businesswire.com/news/home/20130423005276/en">BusinessWire</a></p>
<p>TAMPA, FL — April 23, 2013 — BrightLine CPAs &amp; Associates, Inc., a leading provider of compliance and attestation reporting services, will be part of the Colocation Strategies Tutorial Session at the AFCOM Spring Data Center World 2013 conference.  The conference will be held on April 29th, 2013, at The Mandalay Bay Resort and Casino in Las Vegas.</p>
<p>Doug Barbin, a BrightLine Principal, will join a panel of industry experts to discuss best practices for selecting a colocation provider.  He will be joined by leaders from other companies, including RagingWire Data Centers, Schneider Electric, Transitional Data Services, Dominion Virginia Power, Neustar and Equinix.  Mr. Barbin will focus specifically on the various assurance and compliance alternatives available to data center and colocation providers, such as the <a href="http://www.brightline.com/soc">SOC examinations</a>, <a href="http://www.brightline.com/pci">PCI validation</a>, <a href="http://www.brightline.com/iso">ISO certification</a>, and <a href="http://www.brightline.com/fedramp">FedRAMP</a> security assessment.</p>
<p>“Our goal in leading the Colocation Strategies Tutorial at AFCOM Data Center World is to educate enterprise IT and data center leaders so they can make informed decisions as buyers of data center colocation,” said Jim Leach, vice president of marketing at RagingWire.  “We are delighted to have Doug share his expertise on the critical topics of security and compliance.”</p>
<p>For more information about the Data Center World tutorials, please visit:</p>
<p><a href="http://www.datacenterworld.com/spring2013/tutorials/">http://www.datacenterworld.com/spring2013/tutorials/</a></p>
<p>&nbsp;</p>
<script type="text/javascript" src="https://cdn.socialtwist.com/2011080653625/script.js"></script><a class="st-taf" href="https://tellafriend.socialtwist.com:443" onclick="return false;" style="border:0;padding:0;margin:0;"><img alt="SocialTwist Tell-a-Friend" style="border:0;padding:0;margin:0;" src="https://images.socialtwist.com/2011080653625/button.png" onmouseout="STTAFFUNC.hideHoverMap(this)" onmouseover="STTAFFUNC.showHoverMap(this, '2011080653625', 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1313', 'BrightLine+Joins+Top+Data+Center+Industry+Experts+To+Discuss+%E2%80%9CColocation+Strategies+Tutorial%E2%80%9D+at+AFCOM+Data+Center+World+2013')" onclick="STTAFFUNC.cw(this, {id:'2011080653625', link: 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1313', title: 'BrightLine+Joins+Top+Data+Center+Industry+Experts+To+Discuss+%E2%80%9CColocation+Strategies+Tutorial%E2%80%9D+at+AFCOM+Data+Center+World+2013' });"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thepragmaticauditor.com/?feed=rss2&#038;p=1313</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Part II – PCI Cloud Computing Supplement:  Technical Considerations</title>
		<link>http://www.thepragmaticauditor.com/?p=1275</link>
		<comments>http://www.thepragmaticauditor.com/?p=1275#comments</comments>
		<pubDate>Thu, 11 Apr 2013 14:09:57 +0000</pubDate>
		<dc:creator>Douglas Barbin</dc:creator>
				<category><![CDATA[Cloud Audit]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Payment Card Industry (PCI) Data Security]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[cloud supplement]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[guidelines]]></category>
		<category><![CDATA[hypervisors]]></category>
		<category><![CDATA[technical considerations]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://www.thepragmaticauditor.com/?p=1275</guid>
		<description><![CDATA[By Eric Sampson and Doug Barbin In a previous article, we provided a summary of the key components of the PCI DSS Cloud Computing Guidelines (“cloud supplement”).  That article focused on roles, responsibilities, agreements, and audit considerations.  This article speaks more to the technical considerations. Segmentation challenges Cloud hosted environments often present new layers of [...]]]></description>
			<content:encoded><![CDATA[<p><em><img class="alignnone aligncenter" title="PCI Technical Considerations" src="http://www.brightline.com/App_Themes/Sas70/image/pci-cloud-computing-supplement-part2.jpg" alt="" width="614" height="228" />By Eric Sampson and Doug Barbin</em></p>
<p><span style="text-decoration: underline;"> </span></p>
<p>In a previous article, we provided a summary of the key components of the PCI DSS Cloud Computing Guidelines (“cloud supplement”).  That article focused on roles, responsibilities, agreements, and audit considerations.  This article speaks more to the technical considerations.</p>
<p><span style="text-decoration: underline;"> </span></p>
<p><span style="text-decoration: underline;">Segmentation challenges</span></p>
<p><span style="text-decoration: underline;"> </span></p>
<p>Cloud hosted environments often present new layers of responsibility for common shared layers, such as hypervisors and virtual infrastructure layers, which can present a single point of entry (or attack) for all systems above or below those shared layers.  The security applied to these layers is therefore critical not only to the security of the individual environments they support, but also to ensure that segmentation is enforced between different tenants’ environments.</p>
<p>Regardless of whether a hosted environment can achieve PCI DSS compliance, risks and threats persist, especially for shared cloud environments.  The need for adequate segmentation of client environments in a public or shared cloud is underscored by the principle that the other client environments running on the same infrastructure are to be considered untrusted networks.  The client has no way of confirming whether other client environments are securely configured or patched appropriately to protect against attack, or that they are not already compromised or designed with malicious intent.  This is particularly relevant where a cloud provider offers IaaS and PaaS services, as the individual tenants have greater control and management of their environments.</p>
<p><span style="text-decoration: underline;"> </span></p>
<p><span style="text-decoration: underline;">Virtualization Considerations</span></p>
<p>Virtualization requirements apply generally to cloud hosted environments.  The SSC had previously published the <em>PCI DSS Virtualization Guidelines</em> to discuss security considerations for virtual technologies.  In a complementary manner, the Cloud Guidelines reiterates some virtualization guidance and provides additional security considerations for cloud hosted environments.  Of note regarding technical considerations are the following:</p>
<ul>
<li>VM-to-VM traffic does not pass through traditional network-based security controls, such as a firewall, router, or network IDS/IPS.  Rather, traffic can pass through virtual network routes.  The use of additional host-based security controls to monitor and control traffic, such as host-based firewalls and host-based IDS/IPS applications may be necessary.</li>
<li>Dormant virtual machines must be secured when dormant and not actively used for any period of time.  Security vulnerabilities can be introduced when dormant host is activated.  In the same vein, if a virtual machine can be removed and replaced, a malicious user can make modifications offline and introduce a malware infected virtual machine.</li>
<li>In cloud hosted environments, audit logs are available both at the virtual host and at the virtual machine operating system.  Cloud providers and tenants should discuss roles and responsibilities to ensure all audit logs are reviewed appropriately and in a timely manner.  Creating an environment where virtual host and virtual machine audit logs can be correlated into meaningful events is recommended.</li>
<li>Where the hypervisor has introspection capabilities, or the ability to control and monitor individual VM activity from outside the VMs, presents security challenges.  For instance, the introspection function allows files of VMs to be access within the privileged state of the hypervisor without an audit trail being generated by the VM.  This can present a greater concern for tenants of public, community, or hybrid cloud hosted environments than for tenants of private cloud services.  Tenants should be aware that any personnel with access to the introspection function on the hypervisor could potentially have access to data on any VM managed by the hypervisor.  Therefore, the introspection function should be carefully managed, controlled, and monitored to ensure that role-based access and segregation of duties is maintained.  For example, the hypervisor administration and hypervisor monitoring and auditing functions should be separated.</li>
</ul>
<p>As noted in the previous article, many of the above issues apply equally in the world of <a href="https://www.brightline.com/soc1">SOC 1</a>, <a href="https://www.brightline.com/soc2">SOC 2</a>, <a href="https://www.brightline.com/iso27001">ISO 27001 certification</a>, and <a href="https://www.brightline.com/fedramp">FedRAMP</a>.</p>
<p>Please feel free to contact BrightLine if you have any additional questions.  BrightLine specializes in PCI validation for cloud providers.  We are also the only firm in the world that is a licensed CPA firm, PCI QSA, ISO 27001 certification body, and FedRAMP 3PAO.</p>
<p><em>Eric Sampson is a QSA at BrightLine who leads assessments for some of the largest SaaS providers in the US.  Doug Barbin is a Principal at BrightLine and the firm-wide practice leader for PCI.</em></p>
<p>&nbsp;</p>
<script type="text/javascript" src="https://cdn.socialtwist.com/2011080653625/script.js"></script><a class="st-taf" href="https://tellafriend.socialtwist.com:443" onclick="return false;" style="border:0;padding:0;margin:0;"><img alt="SocialTwist Tell-a-Friend" style="border:0;padding:0;margin:0;" src="https://images.socialtwist.com/2011080653625/button.png" onmouseout="STTAFFUNC.hideHoverMap(this)" onmouseover="STTAFFUNC.showHoverMap(this, '2011080653625', 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1275', 'Part+II+%E2%80%93+PCI+Cloud+Computing+Supplement%3A++Technical+Considerations')" onclick="STTAFFUNC.cw(this, {id:'2011080653625', link: 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1275', title: 'Part+II+%E2%80%93+PCI+Cloud+Computing+Supplement%3A++Technical+Considerations' });"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thepragmaticauditor.com/?feed=rss2&#038;p=1275</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Part I – PCI Cloud Computing Supplement:  Know Your CSP!</title>
		<link>http://www.thepragmaticauditor.com/?p=1262</link>
		<comments>http://www.thepragmaticauditor.com/?p=1262#comments</comments>
		<pubDate>Thu, 04 Apr 2013 14:00:26 +0000</pubDate>
		<dc:creator>Douglas Barbin</dc:creator>
				<category><![CDATA[Cloud Audit]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Payment Card Industry (PCI) Data Security]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[Data Center]]></category>
		<category><![CDATA[FedRAMP]]></category>
		<category><![CDATA[IAAS]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[PaaS]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[QSA]]></category>
		<category><![CDATA[ROC]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SOC]]></category>

		<guid isPermaLink="false">http://www.thepragmaticauditor.com/?p=1262</guid>
		<description><![CDATA[By Eric Sampson and Doug Barbin The writing is on the wall.  For many businesses, cloud providers are becoming a key component of IT and business strategies, service delivery capability and scalability, innovation, and delivering new service models and solutions to market.  For merchants and service providers that store, process, or transmit cardholder data, the [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" title="PCI Part 1" src="https://www.brightline.com/App_Themes/Sas70/image/PCI%20blog%20posting%20mind%20the%20gap.png" alt="" width="294" height="221" /><em>By Eric Sampson and Doug Barbin</em></p>
<p><em></em> The writing is on the wall.  For many businesses, cloud providers are becoming a key component of IT and business strategies, service delivery capability and scalability, innovation, and delivering new service models and solutions to market.  For merchants and service providers that store, process, or transmit cardholder data, the <a href="http://www.brightline.com/pci"></a><a href="http://brightline.com/?pmc=BL-002">PCI DSS</a> provides the requirements necessary to ensure a secure and compliant cardholder data environment.  Until recently, guidance was limited to the interpretation of existing PCI standards, which never fully accounted for today’s evolving cloud computing models.  The release of the PCI DSS Cloud Computing Guidelines (“cloud supplement”), attempts to align core PCI goals with a better understanding of cloud provider and cloud customer (“tenant”) responsibilities to maintain a compliant cloud-hosted cardholder data.  BrightLine had the privilege of participating in this group.  The document is, by default, supplementary and as with all PCI supplements does not supersede, replace, or extend the PCI DSS requirements.  In fact, the cloud supplement states they are provided especially to “[present] recommendations for starting discussions about cloud services” in giving cloud providers and tenants a point of discussion for approaching their individual roles and responsibilities in meeting the PCI DSS requirements.”  In the cloud supplement, the SSC describes the following important areas, to name a few, for understanding provider and client relationships:</p>
<ul>
<li>Cloud provider deployment and service models</li>
<li>How roles and responsibilities may differ among tenants and cloud provider environments including segmentation and scoping considerations</li>
<li>PCI DSS compliance challenges</li>
<li>Contractual needs</li>
<li>Technical security considerations</li>
</ul>
<p><strong><span style="text-decoration: underline;">Understanding the Models</span></strong> Generally speaking, cloud provider service delivery models can be categorized into one or more of the following three areas: Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS).  Cloud provider responsibilities over security and operational controls and meeting PCI DSS requirements tend to increase from an IaaS model (most client responsibility) to a SaaS model (least client responsibility).  In addition, cloud providers can deploy hosted environments differently.  Tenants need to understand the cloud deployment model being utilized or proposed for their cloud hosted environment.  Cloud deployment models include private, community, public, and hybrid cloud (a combination of private, community, and/or public).  Tenents need to understand the level of oversight or visibility they will have into the security functions that are outside their control.  If these security responsibilities are not properly assigned, communicated, and understood, insecure configurations or vulnerabilities could go unnoticed and unaddressed, resulting in potential exploit and data loss or other compromise.  Cloud providers can help their tenants understand how the service models being offered affect their tenants in terms of roles and responsibilities.</p>
<p><strong><span style="text-decoration: underline;">Written agreements</span> </strong> <span style="text-decoration: underline;"> </span> Once cloud provider and tenants roles and responsibilities for operation, management, and reporting are understood for each requirement, a formal agreement with clear policies and procedures should be defined.  Contractual agreements are especially critical where control responsibility is outsourced to ensure the required security measures are being met and maintained by the cloud provider for the duration of the agreement.</p>
<p><strong><span style="text-decoration: underline;">Mind the Gap</span></strong> Be mindful of when a CSP claims “PCI compliance” for their cloud environment.  It is not uncommon for a provider to sell data center, managed, and cloud services only to have the PCI ROC/AOC cover the data center component.  This is why it is critical that a tenant and their QSA be able to understand the scope of what was and was not covered to be able to determine if additional procedures are required.  It is also important to note that many of the above issues apply equally in the world of <a href="https://www.brightline.com/soc1">SOC 1</a>, <a href="https://www.brightline.com/soc2">SOC 2</a>, <a href="https://www.brightline.com/iso27001">ISO 27001 certification</a>, and <a href="https://www.brightline.com/fedramp">FedRAMP</a>.</p>
<p>In the next article we will discuss some of the technical considerations presented within the supplement.</p>
<p><em>Eric Sampson is a QSA at BrightLine who leads assessments for some of the largest SaaS providers in the US.  Doug Barbin is a Principal at BrightLine and the firm wide practice leader for PCI.</em></p>
<script type="text/javascript" src="https://cdn.socialtwist.com/2011080653625/script.js"></script><a class="st-taf" href="https://tellafriend.socialtwist.com:443" onclick="return false;" style="border:0;padding:0;margin:0;"><img alt="SocialTwist Tell-a-Friend" style="border:0;padding:0;margin:0;" src="https://images.socialtwist.com/2011080653625/button.png" onmouseout="STTAFFUNC.hideHoverMap(this)" onmouseover="STTAFFUNC.showHoverMap(this, '2011080653625', 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1262', 'Part+I+%E2%80%93+PCI+Cloud+Computing+Supplement%3A++Know+Your+CSP%21')" onclick="STTAFFUNC.cw(this, {id:'2011080653625', link: 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1262', title: 'Part+I+%E2%80%93+PCI+Cloud+Computing+Supplement%3A++Know+Your+CSP%21' });"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thepragmaticauditor.com/?feed=rss2&#038;p=1262</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISO 27001:2013 – Understanding the New Standard</title>
		<link>http://www.thepragmaticauditor.com/?p=1270</link>
		<comments>http://www.thepragmaticauditor.com/?p=1270#comments</comments>
		<pubDate>Tue, 02 Apr 2013 19:54:44 +0000</pubDate>
		<dc:creator>Ryan Mackie</dc:creator>
				<category><![CDATA[Compliance and Certification]]></category>
		<category><![CDATA[ISO 27001 / 27002]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[isms]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[new standard]]></category>

		<guid isPermaLink="false">http://www.thepragmaticauditor.com/?p=1270</guid>
		<description><![CDATA[Part 1: Scoping and the approach of implementing the ISMS Organizations currently implementing or planning to implement a management system based on ISO 27001 will have a tough decision to make in the near future: Should management implement the information security management system (ISMS) based on ISO 27001:2005 or should ISMS implementation be delayed until [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><em><img class="alignnone" title="ISO 27001 Part 1" src="http://www.brightline.com/App_Themes/Sas70/image/iso-27001-understanding-the-new-standard-part1.png" alt="" width="614" height="228" /></em></p>
<p><em><em>Part 1: Scoping and the approach of implementing the ISMS</em><br />
</em></p>
<p>Organizations currently implementing or planning to implement a management system based on <a href="https://www.brightline.com/iso27001">ISO 27001</a> will have a tough decision to make in the near future: Should management implement the information security management system (ISMS) based on ISO 27001:2005 or should ISMS implementation be delayed until the issuance of the new standard, ISO 27001:2013?  The decision of selecting either ISO27001 standard will have major implications as to how your organization approaches and designs your ISMS.</p>
<p>Organizations currently certified should not expect much difficulty in transitioning from the 2005 version to the 2013 version.  Organizations that are not currently certified will be impacted by the revised 27001 standard, which is expected to be released later in 2013.</p>
<p><strong>Background</strong></p>
<p>The draft version of the updated 27001 standard was recently released for review.  The draft version format of the updated 27001 standard was redesigned to better align with other ISO standards, such as ISO 9001 and ISO 20000.  Moreover, the draft version received slight modifications in both the management system requirements and the controls included in Annex A.  These modifications better interconnect software-based infrastructures (i.e. cloud computing) that have predominantly emerged within the last few years.</p>
<p>The intent and focus of the standard hasn’t changed in the 27001:2013 draft.  The standard remains focused on information security and an organization’s approach to design, plan, implement, and monitor a management system to effectively manage information security risk.  However, the foundation for designing and planning the management system has shifted to better align with the practical matters of today’s organizational environment.  This will come as a positive shift for several organizations as the scope moves away from assessing the risk approach, which organizations have historically struggled with during the implementation of their management system.</p>
<p><strong>Scoping Your Information Security Management System Under ISO 27001:2013</strong></p>
<p>By adopting the draft version of the standard, organizations will now have the ability to base the scope of their ISMS on the issues and objectives most meaningful to the organization’s risk environment.  The draft version takes into consideration the dependencies between the organization and third parties.  This is a critical component for organizations that have third party relationships (specifically data centers) that provide a key system or service to the organization.  Likewise, by adopting the draft version it is assumed that the organization will have a greater acceptance and understanding of scope limitations pertaining to third party relationships and dependencies.</p>
<p>See below for a comparison of the 2005 and 2013 versions of the standard:</p>
<p><strong> </strong></p>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td width="319" valign="top">27001:2005   Establishing the ISMS</td>
<td width="319" valign="top">ISO   27001:2013 Context of the Organization</td>
</tr>
<tr>
<td width="319" valign="top">Define   the scope and boundaries of the ISMS in terms of the following:&nbsp;</p>
<ul>
<li>characteristics of the business;</li>
<li>the organization;</li>
<li>its location;</li>
<li>assets and technology; and</li>
<li>details of and justification for any exclusions from   the scope.</li>
</ul>
</td>
<td width="319" valign="top">Determine   external and internal issues that are relevant to its purpose and that affect   the ability to achieve the intended outcome of its ISMS.&nbsp;</p>
<p>Determine   interested parties that are relevant to the ISMS and their requirements   relevant to information security.</p>
<p>Determine   the boundaries and applicability of the ISMS to establish its scope and   consider the following:</p>
<ul>
<li>the previously determined external and internal issues;</li>
<li>the previously noted requirements of interested   parties; and</li>
<li>interfaces and dependencies between activities   performed by the organization, and those that are performed by other   organizations.</li>
</ul>
</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>The draft version’s approach for defining the scope provides more directed guidance regarding necessary considerations which should ultimately formulate a more grounded scope.  This could potentially lead to a better defined implementation process for the foundations of their ISMS.  Organizations in the process of planning their ISMS or those that expect to undertake the project during the latter part of the year may have the opportunity to reassess their approach to implementation, should difficulties arise in defining the scope and/or potential scope creep.</p>
<p><strong>What to do Today?</strong></p>
<p>Organizations currently in the process of implementing an ISMS using the 27001:2005 standard may find it in their best interest to obtain and review the draft 27001:2013 standard so that the appropriate decision for the organization can be made.  In addition, please do not hesitate to <a href="https://www.brightline.com/iso27001#contactus/sendemail">contact BrightLine</a> to schedule a call to discuss the ISO 27001 certification process and upcoming changes.  We are happy to provide your organization with a free consultation.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<script type="text/javascript" src="https://cdn.socialtwist.com/2011080653625/script.js"></script><a class="st-taf" href="https://tellafriend.socialtwist.com:443" onclick="return false;" style="border:0;padding:0;margin:0;"><img alt="SocialTwist Tell-a-Friend" style="border:0;padding:0;margin:0;" src="https://images.socialtwist.com/2011080653625/button.png" onmouseout="STTAFFUNC.hideHoverMap(this)" onmouseover="STTAFFUNC.showHoverMap(this, '2011080653625', 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1270', 'ISO+27001%3A2013+%E2%80%93+Understanding+the+New+Standard')" onclick="STTAFFUNC.cw(this, {id:'2011080653625', link: 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1270', title: 'ISO+27001%3A2013+%E2%80%93+Understanding+the+New+Standard' });"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thepragmaticauditor.com/?feed=rss2&#038;p=1270</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BrightLine Principal, Doug Barbin, To Speak During the Knowledge Congress Webcast Series About PCI-DSS For The Cloud</title>
		<link>http://www.thepragmaticauditor.com/?p=1278</link>
		<comments>http://www.thepragmaticauditor.com/?p=1278#comments</comments>
		<pubDate>Wed, 27 Mar 2013 16:23:12 +0000</pubDate>
		<dc:creator>avani.desai</dc:creator>
				<category><![CDATA[Cloud Audit]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Payment Card Industry (PCI) Data Security]]></category>
		<category><![CDATA[attestation]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[cloud services]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[credit card]]></category>

		<guid isPermaLink="false">http://www.thepragmaticauditor.com/?p=1278</guid>
		<description><![CDATA[Via Business Wire PCI &#8211; DSS in the Cloud: Practical Guide for Cloud Computing Security and Compliance Tampa, FL- BrightLine CPAs &#38; Associates Principal, Doug Barbin, will be part of a two-hour live webcast on Thursday, April 4, 2013 from 12:00-2:00pm EST.  The live webcast will discuss the importance of Payment Card Industry Data Security [...]]]></description>
			<content:encoded><![CDATA[<p>Via <a href="http://www.businesswire.com/news/home/20130327005303/en">Business Wire</a></p>
<p><em>PCI &#8211; DSS in the Cloud: Practical Guide for Cloud Computing Security and Compliance </em></p>
<p>Tampa, FL- <a href="https://www.brightline.com/">BrightLine CPAs &amp; Associates</a> Principal, Doug Barbin, will be part of a two-hour live webcast on Thursday, April 4, 2013 from 12:00-2:00pm EST.  The live webcast will discuss the importance of <a href="https://www.brightline.com/pci?pmc=PR-001">Payment Card Industry Data Security Standard (PCI-DSS)</a> compliance.  While the PCI-DSS remains to be a challenge for many organizations, PCI-DSS compliance in a cloud computing environment can be even more daunting. It is therefore vital for financial institutions, merchants, and service providers to be informed of the latest and most significant issues with respect to PCI-DSS to help ensure cloud computing security and compliance within the organization, while at the same time minimizing the risk of any potential pitfalls.</p>
<p>Barbin will be part of key panel of experts discussing the fundamentals of PCI-DSS, cloud provider responsibilities, virtualization infrastructure, audit and assessments, strategic initiatives, and legal and regulatory issues.  Unlike some events that often feature technology or service providers, Barbin will be the only QSA along with attorneys who specialize in cloud service agreements and breach litigation.</p>
<p>BrightLine is offering complimentary passes to this event to its clients and prospective clients.  If you would like to claim CLE/CPE hours, a nominal fee of $49 is charged.  Interested parties who would like to listen to the live webcast can click here to <a href="https://gkc.memberclicks.net/index.php?option=com_mc&amp;view=mc&amp;mcid=form_134515">register</a>.</p>
<p><strong>ABOUT BRIGHTLINE </strong></p>
<p><strong> </strong></p>
<p><strong><a href="https://www.brightline.com/">BrightLine CPAs &amp; Associates</a></strong> is a leading provider of attestation and compliance services. BrightLine is the only company in the world that is a CPA firm, a globally licensed PCI Qualified Security Assessor, an <a href="https://www.brightline.com/iso27001">ISO Certification Body</a> and a <a href="https://www.brightline.com/fedramp">FedRAMP 3PAO</a>. Renowned for expertise tempered by practical experience, BrightLine’s professionals provide superior client service balanced by steadfast independence. BrightLine’s approach builds successful, long-term relationships and allows clients to achieve multiple compliance objectives using a single third party assessor.</p>
<p><strong> </strong></p>
<p>&nbsp;</p>
<script type="text/javascript" src="https://cdn.socialtwist.com/2011080653625/script.js"></script><a class="st-taf" href="https://tellafriend.socialtwist.com:443" onclick="return false;" style="border:0;padding:0;margin:0;"><img alt="SocialTwist Tell-a-Friend" style="border:0;padding:0;margin:0;" src="https://images.socialtwist.com/2011080653625/button.png" onmouseout="STTAFFUNC.hideHoverMap(this)" onmouseover="STTAFFUNC.showHoverMap(this, '2011080653625', 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1278', 'BrightLine+Principal%2C+Doug+Barbin%2C+To+Speak+During+the+Knowledge+Congress+Webcast+Series+About+PCI-DSS+For+The+Cloud')" onclick="STTAFFUNC.cw(this, {id:'2011080653625', link: 'http%3A%2F%2Fwww.thepragmaticauditor.com%2F%3Fp%3D1278', title: 'BrightLine+Principal%2C+Doug+Barbin%2C+To+Speak+During+the+Knowledge+Congress+Webcast+Series+About+PCI-DSS+For+The+Cloud' });"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thepragmaticauditor.com/?feed=rss2&#038;p=1278</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
