Triaxiom Security
Partner with us to meet your Information Security needs.
  • About Us
  • Services
    • Penetration Testing
    • Compliance Audit
    • Strategic Consulting
  • Blog
    • Penetration Test
    • PCI Compliance
    • Best Practice
  • Contact Us
saq c-vt
2 May 2019

PCI Compliance – Completing an SAQ C-VT

We’re back again to discuss another SAQ in our series covering the different SAQs that an organization can complete to meet PCI DSS requirements. This decision is an important one, as your applicable SAQ will increase or decrease the number of requirements that you need to address (which equates to cost) as well as the […]

Supply Chain Information Security Risks
29 Apr 2019

Supply Chain Information Security Risks

The 2013 Target data breach is one of the most infamous attacks in the past decade. Attackers gained access to the point-of-sale (POS) terminals and stole the credit card information for up to 40 million customers during the peak of the 2013 holiday season. This attack cost Target over $300 million dollars in actual expenses, […]

SAQ C
26 Apr 2019

PCI Compliance – Completing an SAQ C

We come back to our series covering the different SAQs that an organization can complete to meet PCI DSS requirements. This decision is an important one, as your applicable SAQ will increase or decrease the number of requirements that you need to address (which equates to cost) as well as the scope of systems that […]

North Carolina Penetration Test
24 Apr 2019

North Carolina Penetration Testing Requirements

In 2018, the last two states (Alabama and South Dakota) passed data breach laws. This means that as of January 2019, all 50 states now have a data breach notification laws requiring businesses to report data breaches affecting their organization. Similarly, a number of states (like New York did for financial companies) are beginning to […]

saq b-ip
22 Apr 2019

PCI Compliance – Completing an SAQ B-IP

As we continue discussing the different SAQs that organizations complete, we’re going to cover another very specific merchant SAQ today. Merchants that use (point-of-interaction) POI terminals connected directly to the Internet and their payment processor can complete an SAQ B-IP, as of PCI DSS version 3.0 (February 2014). We’ll cover which merchants can use this […]

First Time Penetration Testing Tips
19 Apr 2019

Five Tips For Your First Penetration Test

The first time getting any type of penetration test as an organization can be intimidating. You’re not sure about the process, you’re not familiar with the company doing the testing, and you may not even be sure on what success looks like. Today, we’ll explore 5 tips for your first penetration test to help you […]

DMZ
17 Apr 2019

What is a DMZ and Why is it Important?

In today’s blog, we are going to explore the concept of a Demilitarized Zone (DMZ) in computer networking. Specifically, what is a DMZ and what does it protect your organization from? Second, we will explore what makes a DMZ so important and why so many compliance regulations require one. With that, let’s jump right into […]

saq a-ep
15 Apr 2019

PCI Compliance – Completing an SAQ A-EP

As we continue to discuss the different types of Self-Assessment Questionnaires (SAQs) within PCI, we’re continuing with some of the smaller SAQs from a requirements and scope perspective. SAQ A-EP is interesting and a little different from the SAQs we’ve discussed previously because it is a subset or special case of SAQ A. It’s also […]

Get into penetration testing
12 Apr 2019

How to Get Into Penetration Testing

One of the most common questions I get asked when people find out that I am a penetration tester is, “How did you get into this field?” More accurately, they are asking how they can get into penetration testing themselves. As a managing partner of a penetration testing firm and a penetration tester myself, this […]

review of information security certifications
10 Apr 2019

A Review of Information Security Certifications

If you are in IT and looking to try to get into information security, the first place to start is by obtaining industry certifications. As I currently have my OSCP, CISSP, C|EH, GSEC, GCIH, PCIP and am working towards my CISA, I figured I was as good as any to review the certifications out there […]

«‹ 23 24 25 26›»

Looking for something specific?

Recent Posts

  • aws s3 sse-c deprecationAWS S3 SSE-C Today, Gone Tomorrow
  • Screenshot 2026-01-16 at 11.13.27 AMAWS CodeBreach: A Close Call For All
  • hidden-dangers-in-cloudCommon Security Dangers Lurking in Cloud Environments

Categories

Most Discussed

API Penetration Test AWS Best Practice Checklist Cloud Cloud Security Cloud Security Assessment Common Vulnerabilities comparison COMPLIANCE configuration review Core Values Cost Current Events Education External Penetration Test firewall HIPAA improvement Incident Response Internal Penetration Test methodology Passphrase Passwords Password Security PCI PCI DSS PCI QSA penetration test Physical Penetration Test Problems QSA Quick Tips Regulation Remediation Report Risk Security Awareness Small Business SMB Social Engineering vetting vulnerability Web Application Penetration Test wireless
Back to top
Triaxiom Security
© 2025 Triaxiom Security, a division of Strata Information Group, Inc. All rights reserved.
Privacy Policy