Contextual Security
  • About Us
    • Our Team
    • Careers
  • Services
    • BASE (Base Assessment of Security Elements)
    • Penetration Testing
    • PCI Compliance
    • Cybersecurity Maturity Model Certification (CMMC)
    • HIPAA Risk Assessment
    • General Data Protection Regulation
    • CIS Top 20
    • SecurityXtension
    • Rogue Access Point (AP)
    • HITRUST
    • Types of Pen Testing
  • Specialty Industries
    • Retail
    • Healthcare
    • Power
    • Finance
  • Blog
  • Contact Us
  • (844)-526-6732
  • Let’s Chat
Select Page

PCI DSS 3.2.1 to 4.0 Control Changes – Requirement 2

by Joshua Jones | Feb 16, 2023 | Compliance, cybersecurity, PCI DSS 4.0

Today, let’s look at changes made to Requirement 2 for PCI DSS 4.0. Requirement 2 Changes In Requirement 2, we will find our first PCI DSS new control for 4.0: In 3.2.1, roles were not necessary to be defined in 2.x controls.  While role definition...

PCI DSS 3.2.1 to 4.0 Control Changes

by Joshua Jones | Oct 25, 2022 | Compliance, cybersecurity, PCI DSS 4.0

Now that you are looking at your timeline, you may be wondering how you can get from where you are now, a sage of PCI DSS 3.2.1, to where you will need to be by 2024. The PCI DSS 4.0 Summary of Changes Using the PCI DSS Summary of Changes document, you can...

Don’t Deploy Vulnerabilities

by Slade Griffin | Sep 6, 2022 | cybersecurity, penetration testing, Uncategorized

We are constantly updating and evolving our deliverables in an effort to provide more context around our security services. With that in mind we have been tracking some metrics since 2020 that allow us to see why organizations remain vulnerable to compromise.  One of...

BloodHound Basics

by Andrew Nash | Aug 3, 2022 | cybersecurity, penetration testing, Uncategorized

“Hacking” isn’t magic, but sometimes it is presented that way. Much of penetration testing and “hacking” is learning the tools of the trade and how they work “under the hood.” In this series we hope to provide a high-level overview of common...

Exploiting the JMX Console (A slightly different path to compromise)

by Terence Martin | Jul 19, 2022 | cybersecurity, penetration testing

On a recent engagement, the client I was assessing had a relatively strong security posture. None of the old standby attacks were working. The client had disabled LLMNR and WPAD based on a previous security assessment, and all the client’s Windows machines were...

The Need for Incident Response Playbooks

by Kevin Thomas | Jun 17, 2022 | cybersecurity, incident response

The most recent Cost of a Data Breach Report (Ponemon 2021) found that “Lost Business Cost” represented the largest percentage (38%, or $1.59M) of the $4.2M average cost of a data breach. One of the key contributors to the “Lost Business Cost”, along with the cost of...
« Older Entries

Recent Posts

  • PCI DSS 3.2.1 to 4.0 Control Changes – Requirement 2
  • PCI DSS 3.2.1 to 4.0 Control Changes
  • Don’t Deploy Vulnerabilities
  • BloodHound Basics
  • Exploiting the JMX Console (A slightly different path to compromise)

Recent Comments

    Archives

    • February 2023
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • March 2022
    • December 2021
    • November 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020
    • September 2020
    • August 2020
    • July 2020
    • April 2020
    • March 2020
    • February 2020

    Categories

    • Compliance
    • cybersecurity
    • incident response
    • PCI DSS 4.0
    • penetration testing
    • Uncategorized
    • whitelisting

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    PCI DSS 3.2.1 to 4.0 Control Changes – Requirement 2

    by Joshua Jones | Feb 16, 2023 | Compliance, cybersecurity, PCI DSS 4.0

    Today, let’s look at changes made to Requirement 2 for PCI DSS 4.0. Requirement 2 Changes In Requirement 2, we will find our first PCI DSS new control for 4.0: In 3.2.1, roles were not necessary to be defined in 2.x controls.  While role definition...

    PCI DSS 3.2.1 to 4.0 Control Changes

    by Joshua Jones | Oct 25, 2022 | Compliance, cybersecurity, PCI DSS 4.0

    Now that you are looking at your timeline, you may be wondering how you can get from where you are now, a sage of PCI DSS 3.2.1, to where you will need to be by 2024. The PCI DSS 4.0 Summary of Changes Using the PCI DSS Summary of Changes document, you can...

    Don’t Deploy Vulnerabilities

    by Slade Griffin | Sep 6, 2022 | cybersecurity, penetration testing, Uncategorized

    We are constantly updating and evolving our deliverables in an effort to provide more context around our security services. With that in mind we have been tracking some metrics since 2020 that allow us to see why organizations remain vulnerable to compromise.  One of...

    « Older Entries

    Contextual Security
    5100 Poplar Avenue, 27th Floor
    Memphis, TN 38137
    844-526-6732
    [email protected]

    Let’s have a chat. We will call you right back!

    3 + 6 =

    Solid security begins with knowing. Excels by doing.

    • Home
    • Services
    • Industries
    • SecurityXtension
    • Resources
    • Contact Us
    • (844) 526-6732

    copyright 2020 | Contextual Security

    • Follow
    • Follow