Showing posts with label practice. Show all posts
Showing posts with label practice. Show all posts

Friday, March 19, 2010

Compliance: PCI in a very small nutshell

Disclosure
I am certified as a Payment Card Industry (PCI) Qualified Security Assesor (QSA). I am frequently paid to perform PCI audits, to advise people on how to fill out their Self Assessment Questionnaire (SAQ), and how to identify and remedy gaps in security that would prevent them from complying.


Previously, I’ve written about identifying risks and handling them. I’ve asserted, indeed my fundamental thesis in this blog, is that risk management is something everyone does; and that if done mindfully and consciously we live happier and better lives personally and professionally. That never means there aren’t complications and challenges to face, and today I’m writing about one of them.

It should come as no surprise that if everyone evaluates their own risks, different people come up with different risks and ideas about how to manage them.

Wednesday, March 3, 2010

Risk management example: my tire

I was going continue the governance series today by writing about policies, but I had the idea to use my last few days to show how theory turns into practice. In particular, how I think about and do risk management in day-to-day life. I’m sure you do the same thing, but call it by a different name. “Thinking things through,” perhaps. The really cool thing about it is that it takes longer to describe than to actually do – and if it’s that reflexive for some things, it can become reflexive for everything.