Triaxiom Security
Partner with us to meet your Information Security needs.
  • About Us
  • Services
    • Penetration Testing
    • Compliance Audit
    • Strategic Consulting
  • Blog
    • Penetration Test
    • PCI Compliance
    • Best Practice
  • Contact Us
pci qsa onsite assessment
5 Jun 2019

Top 10 Ways to Prepare for a PCI QSA Onsite Assessment

Your company is required to have a full Payment Card Industry (PCI) Qualified Security Assessor (QSA) Onsite Assessment that will produce a Report on Compliance (RoC) for you to provide to your acquirer. Maybe you’re a Level 1 merchant, maybe you’ve been classified as a high risk merchant due to transaction size, maybe you’ve had […]

Penetration Testing Statement of Work
3 Jun 2019

What to Look For in a Penetration Testing Statement of Work?

A Statement of Work or “SOW” is a key document for your penetration testing project. If you are at the stage of executing an SOW, it should mean that you have completed your vetting process and will be locking in your penetration testing vendor. Today, we discuss some of the key elements that you should […]

pci qsa onsite assessment
30 May 2019

Am I Required to Have a PCI QSA Onsite Assessment?

For such a short question, you may be reading this because you are struggling to find a clear answer. Many organizations may be confused about what their requirements from a PCI perspective are, and with that confusion, may not even know who they need to ask to clear it up. The question of whether you […]

SAQ Summary
27 May 2019

Which SAQ is Right For Your Organization?

For most organizations that accept credit cards for payment, compliance with PCI DSS is a necessary evil to keep your bank happy and ensure that money keeps coming in the door. And for compliance purposes, your company is likely being required to complete an SAQ, as only a relatively small percentage of large merchants (or […]

after a penetration test
24 May 2019

What to Expect After a Penetration Test (Part 2 of 2)

In this two-part blog series, we are looking at what you can expect after a penetration test. More specifically, what basic steps should you follow once you receive the report to start fixing the vulnerabilities uncovered. In the previous installment, we took a look at understanding the penetration testing report and coming up with an […]

after a penetration test
22 May 2019

What to Expect After a Penetration Test (Part 1 of 2)

So you have finally taken the plunge and had your first penetration test completed. Or maybe this is a yearly requirement, but for some reason you still aren’t getting the results you expected. Maybe you are running into hurdles securing your environment. For many, having a penetration test completed is an eye-opening experience that will […]

saq d - service provider
20 May 2019

PCI Compliance – Completing an SAQ D – Service Provider

This is the final installment in our series reviewing each of the Self-Assessment Questionnaires (SAQs) available for organizations required to comply with the PCI DSS. This final blog is going to cover another sub-type of the SAQ D, the SAQ D – Service Provider. This SAQ is unique in that, if you’re a service provider, […]

Password Security
17 May 2019

Password Security: Everything You Need to Know

After performing penetration tests for a myriad of companies over the last decade, there is one thing that stands out above all others…. People suck at making passwords. At first I thought “how hard can it be?” But after working with company after company, and trying to improve their password security, I have realized that […]

data breach
15 May 2019

Key Takeaways from the 2019 Verizon Data Breach Investigation Report

Each year, Verizon provides a Data Breach Investigation Report (DBIR) which looks at the trends from the past year’s data breaches. Verizon builds this report using 73 data sources, with a combined total of 41,686 security incidents. By looking at the trends, we can see what’s happening in the information security landscape and try to […]

saq-p2pe
13 May 2019

PCI Compliance – Completing an SAQ P2PE

This is the last merchant self-assessment questionnaire to cover in our series going through the organizational requirements to use each of the SAQs. We’ve talked a lot about why it’s so important to try and reduce scope and use the right SAQ for the payment channels utilized by your organization. The SAQ P2PE, in particular, […]

«‹ 21 22 23 24›»

Looking for something specific?

Recent Posts

  • web application penetration testingWeb Application Penetration Testing – A Beginner’s Guide
  • external penetration testWhat is an External Penetration Test?
  • why should you prepare for a penetration testWhy Should You Prepare for a Penetration Test?

Categories

Most Discussed

API Penetration Test Best Practice Checklist Cloud Common Vulnerabilities comparison COMPLIANCE configuration review Core Values Cost Current Events Education External Penetration Test firewall HIPAA improvement Incident Response Internal Penetration Test methodology Onsite Assessment Passphrase Passwords Password Security PCI PCI DSS PCI QSA penetration test Physical Penetration Test Problems QSA Quick Tips Regulation Remediation Report Risk ROC SAQ Security Awareness Small Business SMB Social Engineering vetting vulnerability Web Application Penetration Test wireless
Back to top
Triaxiom Security
© 2025 Triaxiom Security, a division of Strata Information Group, Inc. All rights reserved.
Privacy Policy