Educause Security Discussion mailing list archives

Re: Consultant recommendations for PCI DSS compliance work?


From: "Hudson, Edward" <ewhudson () CSUCHICO EDU>
Date: Wed, 20 Jan 2010 11:01:35 -0800

I would echo Nathaniel re Fishnet and add Solutionary. I have a direct contact for both if anyone needs it please feel 
free to contact me off list

Ed Hudson, CISM
Information Security Office
California State University, Chico
www.csuchico.edu/ires/security<http://www.csuchico.edu/ires/security>
Office: (530) 898-6307
Cell: 707-799-3250
ewhudson () csuchico edu


From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of HALL, 
NATHANIEL D.
Sent: Wednesday, January 20, 2010 10:39 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Consultant recommendations for PCI DSS compliance work?

I have used Fishnet Security for many years for several different services.  They have a group dedicated to PCI 
compliance services and they are on the low end of the cost scale.  They were great during out PCI analysis.

--
Nathaniel Hall, GSEC GCFW GCIA GCIH GCFA
Network Security System Administrator
OTC Computer Networking

Office: (417) 447-7535

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Greg 
Francis
Sent: Wednesday, January 20, 2010 11:22 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Consultant recommendations for PCI DSS compliance work?


Hello,

In evaluating PCI DSS compliance, I've found that there are a number of different possible solutions as well as 
conflicting answers on what can be compliant. While I'm confident that our internal IT staff could build up sufficient 
expertise to ultimately address the compliance requirements, I think we need to look to outside guidance from those 
that have expertise with PCI DSS compliance.

Can anyone recommend a vendor that they have worked with to assist them on PCI DSS compliance? I'm not looking for a 
general security consultant; I need the PCI expertise specific to the IT side but with a very strong knowledge of the 
entire set of requirements for PCI DSS compliance.

Thanks,
Greg

Greg Francis
Director, Central Computing and Network Support Services
Gonzaga University
francis () gonzaga edu<mailto:francis () gonzaga edu>


Current thread: