<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Payment card Security updates &amp;amp; news in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Payment-card-Security-updates-amp-news/m-p/2002#M203</link>
    <description>&lt;P&gt;Anybody else wrestling with the deprecation of SHA1? &amp;nbsp; We just successfully completed an application change that allows the matching hash algorithm to be client-specific, via configuration, as a key step toward conversion - so that we could convert one client at a time. &amp;nbsp;Lot’s of clever ideas brought together by the team to minimize disruption on a massive update of these key matching fields.&lt;/P&gt;</description>
    <pubDate>Sun, 29 Oct 2017 15:58:21 GMT</pubDate>
    <dc:creator>MBiamonte77</dc:creator>
    <dc:date>2017-10-29T15:58:21Z</dc:date>
    <item>
      <title>Payment card Security updates &amp; news</title>
      <link>https://community.isc2.org/t5/Industry-News/Payment-card-Security-updates-amp-news/m-p/1984#M201</link>
      <description>&lt;P&gt;Find all answers to security requirements from Payment Card industry , new updates , releases &amp;amp; changes from Payment Card Industry&amp;nbsp; .&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PCI Security Standards.jpg" style="width: 999px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/989iCBFA26B4359AA24A/image-size/large?v=v2&amp;amp;px=999" role="button" title="PCI Security Standards.jpg" alt="PCI Security Standards.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 16:09:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Payment-card-Security-updates-amp-news/m-p/1984#M201</guid>
      <dc:creator>Mdevaraj</dc:creator>
      <dc:date>2017-10-29T16:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: Payment card Security updates &amp; news</title>
      <link>https://community.isc2.org/t5/Industry-News/Payment-card-Security-updates-amp-news/m-p/2002#M203</link>
      <description>&lt;P&gt;Anybody else wrestling with the deprecation of SHA1? &amp;nbsp; We just successfully completed an application change that allows the matching hash algorithm to be client-specific, via configuration, as a key step toward conversion - so that we could convert one client at a time. &amp;nbsp;Lot’s of clever ideas brought together by the team to minimize disruption on a massive update of these key matching fields.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 15:58:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Payment-card-Security-updates-amp-news/m-p/2002#M203</guid>
      <dc:creator>MBiamonte77</dc:creator>
      <dc:date>2017-10-29T15:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Payment card Security updates &amp; news</title>
      <link>https://community.isc2.org/t5/Industry-News/Payment-card-Security-updates-amp-news/m-p/2152#M218</link>
      <description>&lt;P&gt;Sounds Good , most of the trusted browser deprecated the use of SHA-1 support .&amp;nbsp;Test your SSL using the below to understand the Grade of your SSL , supported cipher suites .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ssllabs.com/ssltest/index.html" target="_blank"&gt;https://www.ssllabs.com/ssltest/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 19:24:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Payment-card-Security-updates-amp-news/m-p/2152#M218</guid>
      <dc:creator>Mdevaraj</dc:creator>
      <dc:date>2017-10-29T19:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: Payment card Security updates &amp; news</title>
      <link>https://community.isc2.org/t5/Industry-News/Payment-card-Security-updates-amp-news/m-p/2157#M219</link>
      <description>&lt;P&gt;Do share one the best ideas that you feel was really great , one which really simplified the journey of migration from X to Y .&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 19:26:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Payment-card-Security-updates-amp-news/m-p/2157#M219</guid>
      <dc:creator>Mdevaraj</dc:creator>
      <dc:date>2017-10-29T19:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Payment card Security updates &amp; news</title>
      <link>https://community.isc2.org/t5/Industry-News/Payment-card-Security-updates-amp-news/m-p/2993#M299</link>
      <description>&lt;P&gt;Two key ideas minimized disruption. &amp;nbsp; The core application functions that hash card numbers were modified to take a new parameter - which hash algorithm to use. &amp;nbsp;(We had some older clients using a hard coded SHA1, and some newer clients using a hard coded 256 - on a “Version 2” core&amp;nbsp;code base). &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With each client’s new parameter set to the existing value (SHA1 or SHA256), the code change was launched (2 lines of code: 300+ test cases) but ... no data was changed. &amp;nbsp;We did this so that we could “flip the switch” (to 512) one client at a time. &amp;nbsp;It took a couple of hours of down time (2 am - 4am) to validate the code changes, but - at least - no data updates were needed now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The actual conversion of each client (one at a time) took less than a minute of down time, accomplished by precomputing a completely new table, and doing a table rename along with the publish of the parameter change.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2017 14:16:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Payment-card-Security-updates-amp-news/m-p/2993#M299</guid>
      <dc:creator>MBiamonte77</dc:creator>
      <dc:date>2017-10-31T14:16:19Z</dc:date>
    </item>
  </channel>
</rss>

