Blog

search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Scanners 101: What, Why, and How to Comply

Learn the fundamentals of vulnerability scanning, especially for PCI compliance requirements.

Configure and Maintain Your Firewall
Data Security

Learn why your firewall may make you vulnerable and how SecurityMetrics Managed Firewall can help.

PCI Requirement 8: Combatting Weak Passwords and Usernames
PCI

In order to comply with PCI Requirement 8, you need to practice proper password and username management.

SAQ D: What's Required for Service Providers
PCI Audit

If you are a service provider who stores credit card data, PCI SAQ D likely applies to you.

How Does Network Segmentation Affect PCI Scope?
PCI

Segmentation is important for preventing breaches and hacks, as well as a method to reduce PCI scope.

Kaseya VSA Software SecurityMetrics Response
Forensics

We are strongly encouraging all SecurityMetrics clients that use Kaseya VSA software in their environment to follow the recommended guidance provided by CISA and the FBI provided below.

What is the HIPAA Privacy Rule?
HIPAA

The HIPAA Privacy Rule is crucial for protecting PHI and ensuring patient privacy. Learn about HIPAA PHI compliance with our free guide.

What is Formjacking?
Ecommerce Security

Formjacking is a type of cyber attack where hackers inject malicious JavaScript code into a webpage form–most often a payment page form.

SAQ A: What to Know, and What to Do
SMB

Learn what’s required to fill out SAQ A.

Incident Response: 10 Things to Do if You Have a Data Breach
Forensics

Learn how to effectively respond to security breaches and prevent future attacks.

PCI Compliance in the Cloud
PCI

Learn how PCI compliance in the cloud affects your organization. "The cloud" brings up an idea of something mysterious and far away, but in reality, “the cloud” is a third-party-managed physical server.

Role Based Access Control for HIPAA Security
HIPAA

Healthcare providers are responsible to make sure those with access to ePHI require that access to adequately do their jobs.

5 Steps to Making a Risk Assessment
Risk Assessment

Making a risk Assessment, or Risk Analysis, is the first step in the Security Rule compliance.

Firewalls 101: 5 Things You Should Know
Data Security

What are firewalls and how do they help protect your business?

5 Tips to Boost Your Business's Physical Security
Data Security

Many businesses don’t often realize how physical security can help protect their card data.

Network Diagrams: Key to Compliance and Security
Data Discovery

If you were to ask network architects and engineers about their favorite part of the job, I doubt any of them will respond with “creating and maintaining network diagrams.”

PCI 4.0 Summary of Changes
PCI Trends

PCI 4.0 summary of changes including new requirements that have been added to the standard.

Scoping for PCI Compliance: What You Need To Know
PCI Audit

Scoping is determining what systems are covered or need to be assessed or included as part of your PCI compliance.

Auditor Tips: Requirement 7: Restrict Access
PCI Audit

Cardholder data and card systems should only be accessible to those that need that information to do their jobs. Once you’ve implemented access privileges, make sure to document it.

How to Test Your Incident Response Plan
Forensics

How to test your incident response plan and conduct tabletop exercises.

Auditor Tips: Requirement 6: System Updating And Software Development
PCI Audit

System administrators have the responsibility to ensure that all system components (e.g., servers, firewalls, routers, workstations) and software are updated with critical security patches within 30 days of public release.

BlogEngine.NET Directory Traversal + Remote Code execution
Data Security

A remote code execution (RCE) vulnerability, CVE-2019-10719, was discovered in BlogEngine 3.3.7 and earlier.

PCI Assessment FAQs
PCI Audit

To address some of the most common questions we receive about PCI assessments, we sat down with Lee Pierce, a PCI assessment expert with over 15 years in the industry.