Andrew Jamieson

speaker
102 appearances 2 recordings 1 series first heard Apr 2025 last heard 1 Apr

Andrew Jamieson’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
1 · Apr OctJan 26AprJulnow

Recordings per month over the last 12 months — 1 in all, peaking in Apr 2026 with 1.

Appearances

newest first · ▶ plays the moment
Happy to be here.
We do.
So we have a number of requirements when it comes to access to things and primarily it comes down to requirements 841, 842 and 843 in PCI DSS specifically we're talking about here.
841 is about what we call non-console access into the cardholder data environment for people who have administrative access.
842 is non-console access for everybody, not admin, but everybody else.
And 843 is access from outside the entity's network into the entity's network.
With those requirements, when it comes to 8.4.2, which is all non-console access, so non-admin access, you're already in your network and you're going from that point in the network into the cardholder data environment, you can use passkeys or what we call phishing-resistant authentication in that context
to authenticate yourself to get into that particular area of the network, into the CDE.
Now, if you're not using phishing-resistant authentication, we require you to use MFA for that.
But in the context of 842, non-admin access, you can use phishing-resistant authentication in the place of MFA.
For the other requirements, 841 and 843,
We recommend the use of phishing resistant authentication for all the reasons that Megan was talking about.
It's a fantastic technology.
It prevents people from having their secrets stolen in terms of password archives or those things being brute forced in stuffing attacks, all the stuff that goes on because you don't have a secret stored in the backend system you're authenticating to.
But when it comes to 841, when we're talking about administrative access, when it comes to 843, when we're talking about remote access into the network, then in those contexts, we require that although you can use, and we do recommend the use of phishing resistant, you need to have another factor.
And Megan did mention that often...
you will have another factor in the context of these kind of systems you'll be using you know a password or a biometric or something like that and so that might work in to use that along with the passkey or the phishing resistant auth to act as multi-factor authentication
However, there are some instances where you would not, and we're actually releasing some FAQs to further provide some information on these systems.
Yeah, so I think it's an interesting, exciting time that we're living in at the moment because we spent so long up until this point
relying on and using knowledge-based factors for authentication.
Showing 61–80 of 102 · page 4 of 6 ← Previous Next →