<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic July 2022 Meeting Minutes in Cleveland Chapter Discussion Forum</title>
    <link>https://community.isc2.org/t5/Cleveland-Chapter-Discussion/July-2022-Meeting-Minutes/m-p/52262#M15</link>
    <description>&lt;P&gt;Start: 17:35&lt;/P&gt;&lt;P&gt;Attendees: 32, 3 first time&lt;/P&gt;&lt;P&gt;Sponsor: Dell&lt;/P&gt;&lt;P&gt;Location: Improving, Independence, OH&lt;/P&gt;&lt;P&gt;Officers in attendance&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rob Netgen&lt;/LI&gt;&lt;LI&gt;Chris Hartley&lt;/LI&gt;&lt;LI&gt;Troy Sheley&lt;/LI&gt;&lt;LI&gt;Ted Kozenko&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Information Security Summit Announcement&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Call for volunteers&lt;/LI&gt;&lt;LI&gt;Announcement of registration&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Job openings&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Westfield: CISO, Sr. Security Architect, "regular" Security Architect&lt;/LI&gt;&lt;LI&gt;Federal Reserve CLE: Security Analyst&lt;/LI&gt;&lt;LI&gt;Cuyahoga County: Network, CCIE, HelpDesk, and Intern positions&lt;/LI&gt;&lt;LI&gt;Home Depot: Security Engineer &amp;amp; Security Analyst&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Security Friends&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;PNC Warns against phishing scam&lt;/LI&gt;&lt;LI&gt;Experts uncover firmware root kit UEFI - CosmicStrand&lt;/LI&gt;&lt;LI&gt;Entire Canadian town of St. Mary's ransomware Lockbit&lt;/LI&gt;&lt;LI&gt;Digital security firm Entrust breached&lt;/LI&gt;&lt;LI&gt;NIST updates healthcare cybersecurity guidance&lt;/LI&gt;&lt;LI&gt;T-Mobile agrees to $350MM settlement + $150MM to update infosec&lt;/LI&gt;&lt;LI&gt;Hackers can bring ships &amp;amp; planes to a halt&lt;/LI&gt;&lt;LI&gt;CISA announces Linux vulnerability&lt;/LI&gt;&lt;LI&gt;Phishing scams in QR codes&lt;/LI&gt;&lt;LI&gt;Houston area reportedly dealing with cyberattacks&lt;/LI&gt;&lt;LI&gt;Cyberattack on Port of Los Angeles doubled since pandemic - 40MM count&lt;/LI&gt;&lt;LI&gt;Hardcoded password in Confluence leaked on Twitter&lt;/LI&gt;&lt;LI&gt;Cisco fixes bug that lets attackers execute commands as root&lt;/LI&gt;&lt;LI&gt;US seizes stolen funds from North Korean hackers&lt;/LI&gt;&lt;LI&gt;Hackers distribute password hack tools for PLCs&lt;/LI&gt;&lt;LI&gt;Malicious GPS tracker vulnerability&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Topic 1: PCI DSS 4.0 Summary of Changes&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Chip Wolford @ Protiviti&lt;/LI&gt;&lt;LI&gt;PCI Council to meet next month in Toronto&lt;/LI&gt;&lt;LI&gt;2,000 PCI assessors globally&lt;/LI&gt;&lt;LI&gt;4.0 released Q1 2022&lt;/LI&gt;&lt;LI&gt;No one using v4.0 as v3.2.1 retires Q1 2024&lt;/LI&gt;&lt;LI&gt;April 01, 2024 official first date&lt;/LI&gt;&lt;LI&gt;Noncompliance of merchants can face fines&lt;/LI&gt;&lt;LI&gt;Real risk in not necessarily noncompliance, but the banks issuing punitive damage fines&lt;/LI&gt;&lt;LI&gt;Changes&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;New customized approach&lt;/LI&gt;&lt;LI&gt;Defined a "significant change"&lt;/LI&gt;&lt;LI&gt;Frequency of many controls determined&lt;/LI&gt;&lt;LI&gt;Defined roles and responsibilities&lt;/LI&gt;&lt;LI&gt;Scope confirmation is a requirement&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;Not changed&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;12 high level standards&lt;/LI&gt;&lt;LI&gt;Approach to scoping and handling encrypted data&lt;/LI&gt;&lt;LI&gt;Ability to use compensating controls&lt;/LI&gt;&lt;LI&gt;Not encryptions of internal data transmission&lt;/LI&gt;&lt;LI&gt;DLP not being a required control&lt;/LI&gt;&lt;LI&gt;Password requirement to align with NIST 800-63 for app and sys accounts&lt;/LI&gt;&lt;LI&gt;3rd party provider not be PCI compliant, but have controls in place&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;Defined vs customized approach = traditional approach vs defined&lt;/LI&gt;&lt;LI&gt;Extensive proofs and documentation for customized approach, to make it difficult&lt;/LI&gt;&lt;LI&gt;Periodic frequency can be done but needs to be justified through a risk analysis and formally documented&lt;/LI&gt;&lt;LI&gt;Scope confirmation as the organization level with a verification by the QSA&lt;/LI&gt;&lt;LI&gt;There is more focus on remote personnel to ensure card data&lt;/LI&gt;&lt;LI&gt;Disk level encryption for removeable media only, not for other card data&lt;/LI&gt;&lt;LI&gt;Include social engineering training&lt;/LI&gt;&lt;LI&gt;Use layer 7 web application firewalls or vulnerability analysis annually&lt;/LI&gt;&lt;LI&gt;SIEM is required&lt;/LI&gt;&lt;LI&gt;Quarterly monitoring if critical security control failures&lt;/LI&gt;&lt;LI&gt;Increased security for the payment page&lt;/LI&gt;&lt;LI&gt;Application vs system accounts have formalized management and password&lt;/LI&gt;&lt;LI&gt;User accounts reviewed every 6 months for access&lt;/LI&gt;&lt;LI&gt;Updated to include MFA&lt;/LI&gt;&lt;LI&gt;SAQs levels remain the same&lt;/LI&gt;&lt;LI&gt;New SAQ requirements in place by 3/31/2024&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;End 19:30&lt;/P&gt;</description>
    <pubDate>Mon, 01 Aug 2022 22:56:27 GMT</pubDate>
    <dc:creator>TedKozenko</dc:creator>
    <dc:date>2022-08-01T22:56:27Z</dc:date>
    <item>
      <title>July 2022 Meeting Minutes</title>
      <link>https://community.isc2.org/t5/Cleveland-Chapter-Discussion/July-2022-Meeting-Minutes/m-p/52262#M15</link>
      <description>&lt;P&gt;Start: 17:35&lt;/P&gt;&lt;P&gt;Attendees: 32, 3 first time&lt;/P&gt;&lt;P&gt;Sponsor: Dell&lt;/P&gt;&lt;P&gt;Location: Improving, Independence, OH&lt;/P&gt;&lt;P&gt;Officers in attendance&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rob Netgen&lt;/LI&gt;&lt;LI&gt;Chris Hartley&lt;/LI&gt;&lt;LI&gt;Troy Sheley&lt;/LI&gt;&lt;LI&gt;Ted Kozenko&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Information Security Summit Announcement&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Call for volunteers&lt;/LI&gt;&lt;LI&gt;Announcement of registration&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Job openings&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Westfield: CISO, Sr. Security Architect, "regular" Security Architect&lt;/LI&gt;&lt;LI&gt;Federal Reserve CLE: Security Analyst&lt;/LI&gt;&lt;LI&gt;Cuyahoga County: Network, CCIE, HelpDesk, and Intern positions&lt;/LI&gt;&lt;LI&gt;Home Depot: Security Engineer &amp;amp; Security Analyst&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Security Friends&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;PNC Warns against phishing scam&lt;/LI&gt;&lt;LI&gt;Experts uncover firmware root kit UEFI - CosmicStrand&lt;/LI&gt;&lt;LI&gt;Entire Canadian town of St. Mary's ransomware Lockbit&lt;/LI&gt;&lt;LI&gt;Digital security firm Entrust breached&lt;/LI&gt;&lt;LI&gt;NIST updates healthcare cybersecurity guidance&lt;/LI&gt;&lt;LI&gt;T-Mobile agrees to $350MM settlement + $150MM to update infosec&lt;/LI&gt;&lt;LI&gt;Hackers can bring ships &amp;amp; planes to a halt&lt;/LI&gt;&lt;LI&gt;CISA announces Linux vulnerability&lt;/LI&gt;&lt;LI&gt;Phishing scams in QR codes&lt;/LI&gt;&lt;LI&gt;Houston area reportedly dealing with cyberattacks&lt;/LI&gt;&lt;LI&gt;Cyberattack on Port of Los Angeles doubled since pandemic - 40MM count&lt;/LI&gt;&lt;LI&gt;Hardcoded password in Confluence leaked on Twitter&lt;/LI&gt;&lt;LI&gt;Cisco fixes bug that lets attackers execute commands as root&lt;/LI&gt;&lt;LI&gt;US seizes stolen funds from North Korean hackers&lt;/LI&gt;&lt;LI&gt;Hackers distribute password hack tools for PLCs&lt;/LI&gt;&lt;LI&gt;Malicious GPS tracker vulnerability&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Topic 1: PCI DSS 4.0 Summary of Changes&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Chip Wolford @ Protiviti&lt;/LI&gt;&lt;LI&gt;PCI Council to meet next month in Toronto&lt;/LI&gt;&lt;LI&gt;2,000 PCI assessors globally&lt;/LI&gt;&lt;LI&gt;4.0 released Q1 2022&lt;/LI&gt;&lt;LI&gt;No one using v4.0 as v3.2.1 retires Q1 2024&lt;/LI&gt;&lt;LI&gt;April 01, 2024 official first date&lt;/LI&gt;&lt;LI&gt;Noncompliance of merchants can face fines&lt;/LI&gt;&lt;LI&gt;Real risk in not necessarily noncompliance, but the banks issuing punitive damage fines&lt;/LI&gt;&lt;LI&gt;Changes&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;New customized approach&lt;/LI&gt;&lt;LI&gt;Defined a "significant change"&lt;/LI&gt;&lt;LI&gt;Frequency of many controls determined&lt;/LI&gt;&lt;LI&gt;Defined roles and responsibilities&lt;/LI&gt;&lt;LI&gt;Scope confirmation is a requirement&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;Not changed&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;12 high level standards&lt;/LI&gt;&lt;LI&gt;Approach to scoping and handling encrypted data&lt;/LI&gt;&lt;LI&gt;Ability to use compensating controls&lt;/LI&gt;&lt;LI&gt;Not encryptions of internal data transmission&lt;/LI&gt;&lt;LI&gt;DLP not being a required control&lt;/LI&gt;&lt;LI&gt;Password requirement to align with NIST 800-63 for app and sys accounts&lt;/LI&gt;&lt;LI&gt;3rd party provider not be PCI compliant, but have controls in place&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;Defined vs customized approach = traditional approach vs defined&lt;/LI&gt;&lt;LI&gt;Extensive proofs and documentation for customized approach, to make it difficult&lt;/LI&gt;&lt;LI&gt;Periodic frequency can be done but needs to be justified through a risk analysis and formally documented&lt;/LI&gt;&lt;LI&gt;Scope confirmation as the organization level with a verification by the QSA&lt;/LI&gt;&lt;LI&gt;There is more focus on remote personnel to ensure card data&lt;/LI&gt;&lt;LI&gt;Disk level encryption for removeable media only, not for other card data&lt;/LI&gt;&lt;LI&gt;Include social engineering training&lt;/LI&gt;&lt;LI&gt;Use layer 7 web application firewalls or vulnerability analysis annually&lt;/LI&gt;&lt;LI&gt;SIEM is required&lt;/LI&gt;&lt;LI&gt;Quarterly monitoring if critical security control failures&lt;/LI&gt;&lt;LI&gt;Increased security for the payment page&lt;/LI&gt;&lt;LI&gt;Application vs system accounts have formalized management and password&lt;/LI&gt;&lt;LI&gt;User accounts reviewed every 6 months for access&lt;/LI&gt;&lt;LI&gt;Updated to include MFA&lt;/LI&gt;&lt;LI&gt;SAQs levels remain the same&lt;/LI&gt;&lt;LI&gt;New SAQ requirements in place by 3/31/2024&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;End 19:30&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2022 22:56:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cleveland-Chapter-Discussion/July-2022-Meeting-Minutes/m-p/52262#M15</guid>
      <dc:creator>TedKozenko</dc:creator>
      <dc:date>2022-08-01T22:56:27Z</dc:date>
    </item>
  </channel>
</rss>

