<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PCI-DSS 12.3.3 in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/PCI-DSS-12-3-3/m-p/74976#M7288</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1342468679" target="_blank" rel="noopener"&gt;@Gerardojr83&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Given there is a multitude of tools for Quantum Safe, here are some suggestions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ibm.com/quantum/blog/crypto-agility" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.ibm.com/quantum/blog/crypto-agility&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://owasp.org/blog/2023/10/03/CycloneDX-Cryptography-CBOM" target="_blank" rel="nofollow noopener noreferrer"&gt;https://owasp.org/blog/2023/10/03/CycloneDX-Cryptography-CBOM&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://owasp.org/www-project-cyclonedx/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://owasp.org/www-project-cyclonedx/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are many others available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These generally allow you to create a Cryptographic Bill of Materials or CBOM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other tools such as Kali, Nessus etc, but obvious get permission before you use such tools on organisations networks etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Tue, 05 Nov 2024 20:33:43 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2024-11-05T20:33:43Z</dc:date>
    <item>
      <title>PCI-DSS 12.3.3</title>
      <link>https://community.isc2.org/t5/Industry-News/PCI-DSS-12-3-3/m-p/74938#M7287</link>
      <description>&lt;P&gt;I'm having trouble finding a good solution that would be needed for one of the new PCI 4.0 controls:&lt;/P&gt;&lt;P&gt;12.3.3 Cryptographic cipher suites and protocols in use&lt;BR /&gt;are documented and reviewed.&lt;/P&gt;&lt;P&gt;What is a good tool to scan for cryptographic ciphers and protocols within an environment? I believe NMAP (Zenmap for Windows) could work but the test scans I've performed do not give accurate results as I can see vulnerability scanning tools pick up other ciphers and protocols that NMAP does not. '&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help or advice is much appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 21:10:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/PCI-DSS-12-3-3/m-p/74938#M7287</guid>
      <dc:creator>Gerardojr83</dc:creator>
      <dc:date>2024-11-04T21:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: PCI-DSS 12.3.3</title>
      <link>https://community.isc2.org/t5/Industry-News/PCI-DSS-12-3-3/m-p/74976#M7288</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1342468679" target="_blank" rel="noopener"&gt;@Gerardojr83&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Given there is a multitude of tools for Quantum Safe, here are some suggestions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ibm.com/quantum/blog/crypto-agility" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.ibm.com/quantum/blog/crypto-agility&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://owasp.org/blog/2023/10/03/CycloneDX-Cryptography-CBOM" target="_blank" rel="nofollow noopener noreferrer"&gt;https://owasp.org/blog/2023/10/03/CycloneDX-Cryptography-CBOM&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://owasp.org/www-project-cyclonedx/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://owasp.org/www-project-cyclonedx/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are many others available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These generally allow you to create a Cryptographic Bill of Materials or CBOM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other tools such as Kali, Nessus etc, but obvious get permission before you use such tools on organisations networks etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 05 Nov 2024 20:33:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/PCI-DSS-12-3-3/m-p/74976#M7288</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2024-11-05T20:33:43Z</dc:date>
    </item>
  </channel>
</rss>

