# PCI DSS

Published articles for PCI DSS.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## AWS Security Reference Architecture: A deep dive into PCI DSS compliance

DevFeed: [AWS Security Reference Architecture: A deep dive into PCI DSS compliance](<https://devfeed.tech/articles/aws-security-reference-architecture-a-deep-dive-into-pci-dss-compliance-20819.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/security/aws-security-reference-architecture-a-deep-dive-into-pci-dss-compliance/>)

Author: Avik Mukherjee

Published: 2026-09-14T17:46:56Z

Content type: article

Language: en

Sources: [AWS Security Blog](<https://devfeed.tech/sources/aws-security-blog.md>)

Topics: [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Network Segmentation](<https://devfeed.tech/topics/network-segmentation.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [amazon-web-services](<https://devfeed.tech/tags/amazon-web-services.md>), [announcements](<https://devfeed.tech/tags/announcements.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [foundational-100](<https://devfeed.tech/tags/foundational-100.md>), [logging](<https://devfeed.tech/tags/logging.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [security-blog](<https://devfeed.tech/tags/security-blog.md>), [security-identity-compliance](<https://devfeed.tech/tags/security-identity-compliance.md>)

### AI overview

AWS announces the AWS Security Reference Architecture (AWS SRA) PCI DSS Deep Dive, a guide that extends the core AWS SRA with prescriptive architecture-level guidance for organizations handling cardholder data on AWS. It explains how AWS SRA patterns address PCI DSS concerns including account scoping, network segmentation, encryption, logging, and access control.

### Source excerpt

Amazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data Security Standard (DSS) Deep Dive. This new guide extends the core AWS SRA to provide prescriptive, architecture-level guidance for organizations that store, process, or transmit cardholder data on AWS. Organizations subject to [...]

## How Ninth Wave built AI-powered open finance onboarding on Amazon Bedrock

DevFeed: [How Ninth Wave built AI-powered open finance onboarding on Amazon Bedrock](<https://devfeed.tech/articles/how-ninth-wave-built-ai-powered-open-finance-onboarding-on-amazon-bedrock-21548.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/machine-learning/how-ninth-wave-built-ai-powered-open-finance-onboarding-on-amazon-bedrock/>)

Author: Shawn Kelly

Published: 2026-09-14T15:58:57Z

Content type: article

Language: en

Sources: [Artificial Intelligence](<https://devfeed.tech/sources/artificial-intelligence.md>)

Topics: [Amazon Bedrock AgentCore](<https://devfeed.tech/topics/amazon-bedrock-agentcore.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [API](<https://devfeed.tech/topics/api.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Security](<https://devfeed.tech/topics/security.md>), [Finance](<https://devfeed.tech/topics/finance.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [advanced-300](<https://devfeed.tech/tags/advanced-300.md>), [ai](<https://devfeed.tech/tags/ai.md>), [amazon-bedrock](<https://devfeed.tech/tags/amazon-bedrock.md>), [amazon-bedrock-agentcore](<https://devfeed.tech/tags/amazon-bedrock-agentcore.md>), [apis](<https://devfeed.tech/tags/apis.md>), [customer-solutions](<https://devfeed.tech/tags/customer-solutions.md>), [fintech](<https://devfeed.tech/tags/fintech.md>), [onboarding](<https://devfeed.tech/tags/onboarding.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

The article describes how Ninth Wave built Compass, a multi-agent AI onboarding assistant powered by Amazon Bedrock AgentCore. Compass helps financial institutions validate bank APIs, map fields to Financial Data Exchange standards, and score production readiness while supporting secure, compliant open finance connectivity.

### Source excerpt

Learn how Ninth Wave built Compass, a multi-agent AI onboarding assistant on Amazon Bedrock AgentCore that validates bank APIs against Financial Data Exchange (FDX) standards, scores compliance, and compresses open finance onboarding from weeks to minutes while meeting SOC 2 and PCI DSS requirements.

## Scaling Kubernetes governance: A platform engineer's guide to Kyverno and CEL

DevFeed: [Scaling Kubernetes governance: A platform engineer's guide to Kyverno and CEL](<https://devfeed.tech/articles/scaling-kubernetes-governance-a-platform-engineer-s-guide-to-kyverno-and-cel-12220.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/scaling-kubernetes-governance-a-platform-engineers-guide-to-kyverno-and-cel>)

Author: Koray Oksay

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Security](<https://devfeed.tech/topics/security.md>), [developer velocity](<https://devfeed.tech/topics/developer-velocity.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [opa](<https://devfeed.tech/topics/opa.md>), [rego](<https://devfeed.tech/topics/rego.md>)

Tags: [common-expression-language](<https://devfeed.tech/tags/common-expression-language.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [developer-velocity](<https://devfeed.tech/tags/developer-velocity.md>), [governance](<https://devfeed.tech/tags/governance.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [integration](<https://devfeed.tech/tags/integration.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [platform](<https://devfeed.tech/tags/platform.md>), [policy](<https://devfeed.tech/tags/policy.md>), [security](<https://devfeed.tech/tags/security.md>), [security-policies](<https://devfeed.tech/tags/security-policies.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

A guide to using Kyverno and its Common Expression Language support for Kubernetes governance. It explains how platform engineering teams can enforce policies, automate resource changes, generate resources, verify image signatures, and maintain security and compliance while preserving developer velocity.

### Source excerpt

Kyverno with CEL support provides Policy-as-Code for Kubernetes governance. Enforce security, automate guardrails, and boost developer velocity for platform engineering teams.

## Announcing the CIS Benchmark for CockroachDB v25.x

DevFeed: [Announcing the CIS Benchmark for CockroachDB v25.x](<https://devfeed.tech/articles/announcing-the-cis-benchmark-for-cockroachdb-v25-x-23757.md>)

Original publisher: [Read original article](<https://cockroachlabs.com/blog/cis-benchmark-cockroachdb-security>)

Author: Adam Brennick,Ayog Mohanty

Published: 2026-07-14T00:00:00Z

Content type: release

Language: en

Sources: [Cockroach Labs](<https://devfeed.tech/sources/cockroach-labs.md>)

Topics: [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [CockroachDB](<https://devfeed.tech/topics/cockroachdb.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cockroach Labs](<https://devfeed.tech/topics/cockroach-labs.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Database](<https://devfeed.tech/topics/database.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [cockroach-labs](<https://devfeed.tech/tags/cockroach-labs.md>), [cockroachdb](<https://devfeed.tech/tags/cockroachdb.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [published](<https://devfeed.tech/tags/published.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [standard](<https://devfeed.tech/tags/standard.md>)

### AI overview

The Center for Internet Security has published the CIS CockroachDB v25.x Benchmark, providing a consensus-driven security configuration guide for self-hosted CockroachDB deployments. The article explains how the benchmark can support standardized security practices, audits, compliance reviews, and production configuration validation.

### Source excerpt

We're proud to announce that the Center for Internet Security (CIS) has published the CIS CockroachDB v25.x Benchmark.

## Hosted vs Self-Hosted Payment Gateway: Which Is Right for Your SaaS?

DevFeed: [Hosted vs Self-Hosted Payment Gateway: Which Is Right for Your SaaS?](<https://devfeed.tech/articles/hosted-vs-self-hosted-payment-gateway-which-is-right-for-your-saas-9901.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/hosted-vs-self-hosted-payment-gateway/>)

Author: Ayush Agarwal

Published: 2026-06-08T00:00:00Z

Content type: tutorial

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Shared Responsibility Model](<https://devfeed.tech/topics/shared-responsibility-model.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [gateway](<https://devfeed.tech/tags/gateway.md>), [payment-gateway](<https://devfeed.tech/tags/payment-gateway.md>), [payments](<https://devfeed.tech/tags/payments.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [saas](<https://devfeed.tech/tags/saas.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>)

### AI overview

This guide compares hosted and self-hosted payment gateways for SaaS products. Hosted gateways keep card-data collection on the provider's infrastructure, reducing PCI DSS scope and integration work, while self-hosted gateways provide more control over checkout and customer experience but require greater compliance effort. Client-side tokenization can keep raw card data out of the backend.

### Source excerpt

Hosted vs self-hosted payment gateway compared. PCI scope, control, integration speed, and which model fits SMB SaaS, enterprise, and global product-led companies.

## Embedded Payments for SaaS Platforms: A 2026 Implementation Guide

DevFeed: [Embedded Payments for SaaS Platforms: A 2026 Implementation Guide](<https://devfeed.tech/articles/embedded-payments-for-saas-platforms-a-2026-implementation-guide-9845.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/embedded-payments-saas-platforms/>)

Author: Ayush Agarwal

Published: 2026-04-29T00:00:00Z

Content type: tutorial

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Software as a service](<https://devfeed.tech/topics/saas.md>), [API](<https://devfeed.tech/topics/api.md>), [tokenization](<https://devfeed.tech/topics/tokenization.md>), [ui](<https://devfeed.tech/topics/ui.md>), [Mobile](<https://devfeed.tech/topics/mobile.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [api](<https://devfeed.tech/tags/api.md>), [app](<https://devfeed.tech/tags/app.md>), [architectures](<https://devfeed.tech/tags/architectures.md>), [checkout](<https://devfeed.tech/tags/checkout.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [conversion](<https://devfeed.tech/tags/conversion.md>), [guide](<https://devfeed.tech/tags/guide.md>), [integration](<https://devfeed.tech/tags/integration.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [patterns](<https://devfeed.tech/tags/patterns.md>), [payment](<https://devfeed.tech/tags/payment.md>), [payments](<https://devfeed.tech/tags/payments.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [platform](<https://devfeed.tech/tags/platform.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [revenue](<https://devfeed.tech/tags/revenue.md>), [saas](<https://devfeed.tech/tags/saas.md>), [subscription](<https://devfeed.tech/tags/subscription.md>)

### AI overview

A 2026 guide to implementing embedded payments in SaaS platforms. It compares inline checkout, modal overlays, and raw card APIs, with attention to PCI compliance, regulatory obligations, fraud, settlement risk, support, and implementation patterns.

### Source excerpt

How modern SaaS platforms add embedded payments without becoming a payments company. Architectures, compliance, revenue share, and implementation patterns.

## PCI DSS Compliance: What Digital Businesses Need to Know

DevFeed: [PCI DSS Compliance: What Digital Businesses Need to Know](<https://devfeed.tech/articles/pci-dss-compliance-what-digital-businesses-need-to-know-10274.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/pci-dss-compliance-digital-business/>)

Author: Ayush Agarwal

Published: 2026-04-15T00:00:00Z

Content type: tutorial

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Network Segmentation](<https://devfeed.tech/topics/network-segmentation.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [tokenization](<https://devfeed.tech/topics/tokenization.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [digital-products](<https://devfeed.tech/tags/digital-products.md>), [firewalls](<https://devfeed.tech/tags/firewalls.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [saas](<https://devfeed.tech/tags/saas.md>), [scope](<https://devfeed.tech/tags/scope.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>), [tls](<https://devfeed.tech/tags/tls.md>), [tokenization](<https://devfeed.tech/tags/tokenization.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This guide explains how PCI DSS applies to digital businesses that accept card payments, including SaaS companies and sellers of digital products. It outlines the standard's 12 requirements and discusses controls for networks, account data, vulnerabilities, access, monitoring, and information security. It also covers card-not-present transactions, recurring billing, and tokenization.

### Source excerpt

PCI DSS compliance explained for digital businesses. Understand the 12 requirements, compliance levels, and how to reduce your scope when selling digital products online.

## Scaling Payments in the Age of Real-Time Fraud: Building a Resilient Foundation for Fintech

DevFeed: [Scaling Payments in the Age of Real-Time Fraud: Building a Resilient Foundation for Fintech](<https://devfeed.tech/articles/scaling-payments-in-the-age-of-real-time-fraud-building-a-resilient-foundation-for-fintech-23814.md>)

Original publisher: [Read original article](<https://cockroachlabs.com/blog/scaling-payments-real-time-fraud-fintech>)

Author: Becca Weng

Published: 2026-02-25T00:00:00Z

Content type: article

Language: en

Sources: [Cockroach Labs](<https://devfeed.tech/sources/cockroach-labs.md>)

Topics: [systems](<https://devfeed.tech/topics/systems.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [consistency](<https://devfeed.tech/topics/consistency.md>), [Low Latency](<https://devfeed.tech/topics/low-latency.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [fintech](<https://devfeed.tech/tags/fintech.md>), [high-availability](<https://devfeed.tech/tags/high-availability.md>), [latency](<https://devfeed.tech/tags/latency.md>), [outages](<https://devfeed.tech/tags/outages.md>), [payments](<https://devfeed.tech/tags/payments.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

This article explains why fintech payment systems require resilient architectures that preserve atomic data updates, maintain low latency during demand spikes, support global regulatory and data-residency requirements, and provide high availability and security. It also introduces real-time fraud detection as an added source of complexity.

### Source excerpt

Fintech is one of the most competitive and highly regulated industries in the world. Whether you're a payment processor, digital-first bank, trading platform, or wallet provider, your infrastructure is directly tied to customer trust. In this environment, outages aren't just technical incidents; a single missed transaction, delayed authorization, or moment of downtime can erode customer confidence instantly.

## Forrester TEI study: Chainguard Containers delivered 233% return on investment

DevFeed: [Forrester TEI study: Chainguard Containers delivered 233% return on investment](<https://devfeed.tech/articles/forrester-tei-study-chainguard-containers-delivered-233-return-on-investment-13051.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/forrester-tei-study-chainguard-containers-delivered-233-return-on-investment>)

Published: 2026-02-18T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-forrester](<https://devfeed.tech/tags/chainguard-forrester.md>), [chainguard-roi](<https://devfeed.tech/tags/chainguard-roi.md>), [chainguard-value](<https://devfeed.tech/tags/chainguard-value.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [forrester-tei](<https://devfeed.tech/tags/forrester-tei.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

A Forrester Consulting Total Economic Impact study commissioned by Chainguard reports that customers using Chainguard Containers achieved a 233% return on investment over three years, with $2.5 million in benefits and payback in less than six months. The article attributes these results to reduced vulnerabilities, simpler maintenance, and lower compliance overhead, supported by minimal zero-CVE container images and automated remediation.

### Source excerpt

Explore the latest Forrester Consulting Total Economic Impact™ (TEI) study, commissioned by Chainguard.

## Ensuring Compliance and Governance in Kubernetes for Banking Workloads

DevFeed: [Ensuring Compliance and Governance in Kubernetes for Banking Workloads](<https://devfeed.tech/articles/ensuring-compliance-and-governance-in-kubernetes-for-banking-workloads-17642.md>)

Original publisher: [Read original article](<https://www.urolime.com/blogs/ensuring-compliance-and-governance-in-kubernetes-for-banking-workloads/>)

Author: Urolime Technologies

Published: 2025-11-04T12:50:33Z

Content type: article

Language: en

Sources: [Kubernetes Archives - Urolime Blogs](<https://devfeed.tech/sources/kubernetes-archives-urolime-blogs.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Scalability](<https://devfeed.tech/topics/scalability.md>), [Availability](<https://devfeed.tech/topics/availability.md>)

Tags: [banking](<https://devfeed.tech/tags/banking.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [gdpr](<https://devfeed.tech/tags/gdpr.md>), [governance](<https://devfeed.tech/tags/governance.md>), [kubernete](<https://devfeed.tech/tags/kubernete.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [orchestration](<https://devfeed.tech/tags/orchestration.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

This article examines how Kubernetes can support compliance and governance for banking workloads. It describes benefits such as scalability, high availability, and fault tolerance, while identifying governance and security challenges involving complex configurations, dynamic workloads, regulatory requirements, and audit visibility. It highlights Kubernetes consulting services and zero-trust network policies as relevant practices.

### Source excerpt

In the fast-paced banking era, data security and compliance is not a choice, but a necessity. Here Kubernetes has emerged as an adaptable platform to govern the containerized workloads. Its scalable, fault-tolerant application orchestration feature has proven it to be the ideal choice for the industry. In this blog we will analyze on how Kubernetes [...]

## Simplify Continuous Compliance: How to Stay Audit-Ready and Ship Software Faster

DevFeed: [Simplify Continuous Compliance: How to Stay Audit-Ready and Ship Software Faster](<https://devfeed.tech/articles/simplify-continuous-compliance-how-to-stay-audit-ready-and-ship-software-faster-13233.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/simplify-continuous-compliance-how-to-stay-audit-ready-and-ship-software-faster>)

Published: 2025-10-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cves](<https://devfeed.tech/tags/cves.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [stateramp](<https://devfeed.tech/tags/stateramp.md>)

### AI overview

This article explains how organizations can treat software compliance as a continuous practice rather than a periodic audit exercise. It describes how open-source components, CVE remediation, provenance, SBOM coverage, and audit evidence affect platform engineering, application security, development velocity, and regulated-market access, while presenting Chainguard as a solution provider.

### Source excerpt

Turn compliance into a growth driver with Chainguard. Eliminate CVEs, stay audit-ready, and meet FedRAMP, SOC 2, and ISO 27001 with secure images.

## How Snyk Learn Helps You Meet PCI DSS v4.0 Developer Training Requirements

DevFeed: [How Snyk Learn Helps You Meet PCI DSS v4.0 Developer Training Requirements](<https://devfeed.tech/articles/how-snyk-learn-helps-you-meet-pci-dss-v4-0-developer-training-requirements-7954.md>)

Original publisher: [Read original article](<https://snyk.io/blog/how-snyk-learn-helps-you-meet-pci-dss-v4-0-developer-training-requirements/>)

Author: Michael Biocchi; Celia Jenkins

Published: 2025-09-23T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk-learn](<https://devfeed.tech/topics/snyk-learn.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [pci-dss-v4-0](<https://devfeed.tech/tags/pci-dss-v4-0.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [reviews](<https://devfeed.tech/tags/reviews.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-learn](<https://devfeed.tech/tags/snyk-learn.md>), [testing](<https://devfeed.tech/tags/testing.md>), [training](<https://devfeed.tech/tags/training.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains how Snyk Learn supports PCI DSS v4.0.1 developer training requirements. It describes relevant, just-in-time security lessons linked to coding mistakes, along with training on secure coding, security testing, code reviews, and software vulnerabilities.

### Source excerpt

Discover how Snyk Learn helps organizations meet PCI DSS v4.0 developer training requirements by providing relevant, just-in-time, interactive, and trackable security education for developers.

## HIPAA and PCI Compliance at ClickHouse

DevFeed: [HIPAA and PCI Compliance at ClickHouse](<https://devfeed.tech/articles/hipaa-and-pci-compliance-at-clickhouse-5151.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/clickhouse-self-service-hipaa-pci-compliance>)

Author: Leticia Webb

Published: 2025-08-05T14:06:20Z

Content type: news

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data](<https://devfeed.tech/tags/data.md>), [healthcare](<https://devfeed.tech/tags/healthcare.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

ClickHouse announces the general availability of self-service HIPAA and PCI deployments in ClickHouse Cloud. The article explains safeguards for protected health information and payment card data, including compliance with HIPAA requirements and PCI DSS Level 1 Service Provider standards.

### Source excerpt

HIPAA and PCI self-service deployments are now generally available in ClickHouse Cloud

## The Difference Between Postgres Logging and PGAudit

DevFeed: [The Difference Between Postgres Logging and PGAudit](<https://devfeed.tech/articles/the-difference-between-postgres-logging-and-pgaudit-5734.md>)

Original publisher: [Read original article](<https://neon.com/blog/postgres-logging-vs-pgaudit>)

Author: Monica Steinke

Published: 2025-05-28T20:26:29Z

Content type: article

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [Logging](<https://devfeed.tech/topics/logging.md>), [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Databases](<https://devfeed.tech/topics/databases.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [config](<https://devfeed.tech/tags/config.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [iso](<https://devfeed.tech/tags/iso.md>), [logging](<https://devfeed.tech/tags/logging.md>), [logs](<https://devfeed.tech/tags/logs.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [postgres](<https://devfeed.tech/tags/postgres.md>), [process](<https://devfeed.tech/tags/process.md>), [server](<https://devfeed.tech/tags/server.md>)

### AI overview

The article compares PostgreSQL's built-in logging with PGAudit. PostgreSQL logging supports operational monitoring and troubleshooting, while PGAudit is designed for compliance auditing with detailed records of database access and changes. It describes PGAudit's session and object auditing modes and the information recorded in audit log entries.

### Source excerpt

Postgres has some excellent internal logging capabilities. With a simple logging_collector = on and a couple of other config flags, you can get an incredibly detailed picture of your Postgres operations, from individual SQL statements to connection attempts, error messages, and l...

## Overcoming AppSec Challenges in FinServ: How CIBC Balances Speed, Security, and Compliance

DevFeed: [Overcoming AppSec Challenges in FinServ: How CIBC Balances Speed, Security, and Compliance](<https://devfeed.tech/articles/overcoming-appsec-challenges-in-finserv-how-cibc-balances-speed-security-and-compliance-8042.md>)

Original publisher: [Read original article](<https://snyk.io/blog/overcoming-appsec-challenges-in-finserv-how-cibc-balances-speed-security-and/>)

Author: Snyk Team

Published: 2025-03-20T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [automation](<https://devfeed.tech/tags/automation.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [community](<https://devfeed.tech/tags/community.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [customer](<https://devfeed.tech/tags/customer.md>), [customer-featured](<https://devfeed.tech/tags/customer-featured.md>), [data-privacy](<https://devfeed.tech/tags/data-privacy.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [finserv](<https://devfeed.tech/tags/finserv.md>), [interest](<https://devfeed.tech/tags/interest.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This article distills a fireside-chat discussion about application security challenges in financial services, featuring Snyk's Field CTO and CIBC's Senior Director of Security Service Management. It covers the tension between rapid innovation and strict compliance, risks from cybercrime, data privacy, cloud infrastructure, third-party services, legacy systems, and modern applications, and the role of automation, continuous security testing, monitoring, DevSecOps, AI-driven tools, and human oversight in vulnerability management.

### Source excerpt

Join Snyk's Field CTO, Steven Schmidt, and Mihai Saveschi, Senior Director of Security Service Management at CIBC, for an exclusive fireside chat on the evolving landscape of application security in financial services.

## Chainguard Images are the Gold Standard for PCI DSS v4.0

DevFeed: [Chainguard Images are the Gold Standard for PCI DSS v4.0](<https://devfeed.tech/articles/chainguard-images-are-the-gold-standard-for-pci-dss-v4-0-12954.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-images-are-the-gold-standard-for-pci-dss-v4-0>)

Published: 2025-02-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-sboms](<https://devfeed.tech/tags/chainguard-sboms.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-image-compliance](<https://devfeed.tech/tags/container-image-compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [financial](<https://devfeed.tech/tags/financial.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [pci-dss-v4-0](<https://devfeed.tech/tags/pci-dss-v4-0.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [stig](<https://devfeed.tech/tags/stig.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article explains how Chainguard Images can support selected PCI DSS v4.0 container-security controls. It focuses on asset and vulnerability management, hardened images, FIPS cryptography, build-time SBOMs, software supply chain inventory, and continuously updated containers.

### Source excerpt

Chainguard Images are designed to make container image compliance for PCI DSS v4.0 easy for any company involved in card transactions.

## Mastering the "compliance end run" with Chainguard Images

DevFeed: [Mastering the "compliance end run" with Chainguard Images](<https://devfeed.tech/articles/mastering-the-compliance-end-run-with-chainguard-images-13148.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mastering-the-compliance-end-run-with-chainguard-images>)

Published: 2024-07-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-rev-5](<https://devfeed.tech/tags/fedramp-rev-5.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [secure-container-images](<https://devfeed.tech/tags/secure-container-images.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article explains how the "compliance end run" shifts responsibility for software compliance to customers who run a vendor's stack in their own environments. It highlights the resulting vulnerability-management obligations under PCI DSS v4 and FedRAMP Rev 5, and presents Chainguard Images as a minimal, secure starting point for reducing vulnerabilities and meeting stringent compliance requirements.

### Source excerpt

Learn how to use Chainguard Images to streamline compliance and avoid the "compliance end run" that slows down sales and creates friction with customers.

## STIG hardening container images

DevFeed: [STIG hardening container images](<https://devfeed.tech/articles/stig-hardening-container-images-13239.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/stig-hardening-container-images>)

Published: 2024-06-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [hardened-image](<https://devfeed.tech/tags/hardened-image.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [security-technical-implementation-guide](<https://devfeed.tech/tags/security-technical-implementation-guide.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stig-hardening](<https://devfeed.tech/tags/stig-hardening.md>)

### AI overview

The article discusses hardening container images against STIG requirements, including how to distinguish controls that apply to containers from those that apply to the host operating system or Docker service. It also notes that false positives can occur in container security scans.

### Source excerpt

Dive into the world of STIG hardening for container images. Explore expert insights, practical tips, and Chainguard solutions to fortify your container security.

## Achieve PCI DSS v4.0 compliance with Chainguard Images

DevFeed: [Achieve PCI DSS v4.0 compliance with Chainguard Images](<https://devfeed.tech/articles/achieve-pci-dss-v4-0-compliance-with-chainguard-images-12863.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/achieve-pci-dss-v4-0-compliance-with-chainguard-images>)

Published: 2024-05-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [container images](<https://devfeed.tech/topics/container-images.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container](<https://devfeed.tech/tags/container.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [pci-dss-v4-0](<https://devfeed.tech/tags/pci-dss-v4-0.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This article explains how Chainguard Images can support PCI DSS v4.0 compliance for payment applications. It outlines updated vulnerability-management requirements, including recurring vulnerability scans, risk-based classification, coverage of third-party software, and remediation planning.

### Source excerpt

Navigating PCI DSS v4.0 compliance? Chainguard Images simplifies the process with secure, compliant container images for your payment applications.

## How Data Protection Requirements Discourage Excessive Customer Data Hoarding

DevFeed: [How Data Protection Requirements Discourage Excessive Customer Data Hoarding](<https://devfeed.tech/articles/worth-reading-data-protection-for-dummies-10994.md>)

Original publisher: [Read original article](<https://blog.ipspace.net/2024/04/worth-reading-data-protection-dummies/>)

Published: 2024-04-20T04:35:00Z

Content type: opinion

Language: en

Sources: [ipSpace.net blog](<https://devfeed.tech/sources/ipspace-net-blog.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [customer](<https://devfeed.tech/tags/customer.md>), [data](<https://devfeed.tech/tags/data.md>), [data-protection](<https://devfeed.tech/tags/data-protection.md>), [gdpr](<https://devfeed.tech/tags/gdpr.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [worth-reading](<https://devfeed.tech/tags/worth-reading.md>)

### AI overview

The article argues that data protection requirements such as PCI-DSS and GDPR primarily discourage companies from retaining excessive customer data by making data hoarding expensive, rather than directly making companies more secure.

### Source excerpt

Another lovely must-read rant from the cranky security professional. TL&DR: Data protection requirements like PCI-DSS aren't there to make companies more secure but to make it too expensive for them to hoard excessive customer data (see also: GDPR).

## Into the deep: Exploring Chainguard Container Images

DevFeed: [Into the deep: Exploring Chainguard Container Images](<https://devfeed.tech/articles/into-the-deep-exploring-chainguard-container-images-13104.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/into-the-deep-exploring-chainguard-container-images>)

Published: 2023-11-29T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [soc2](<https://devfeed.tech/topics/soc2.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [soc2](<https://devfeed.tech/tags/soc2.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard Images provide value beyond low CVE counts by supporting software supply chain security. The article discusses rapid CVE remediation through Wolfi, enterprise remediation SLAs, compliance requirements, and the use of trusted minimal base images to reduce supply chain attack risk.

### Source excerpt

Learn how Chainguard Images go beyond reducing CVE count in your software supply chain, with hardened container images, SBOMs, and more.

## My Career Pivot: From IT recruiter to information security

DevFeed: [My Career Pivot: From IT recruiter to information security](<https://devfeed.tech/articles/my-career-pivot-from-it-recruiter-to-information-security-32387.md>)

Original publisher: [Read original article](<https://medium.com/@SkyscannerEng/my-career-pivot-from-it-recruiter-to-information-security-cf955ca39d24?source=rss-401f3b3c958f------2>)

Author: Skyscanner Engineering

Published: 2022-06-24T08:08:19Z

Content type: article

Language: en

Sources: [Stories by Skyscanner Engineering on Medium](<https://devfeed.tech/sources/stories-by-skyscanner-engineering-on-medium.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [career](<https://devfeed.tech/tags/career.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [female-engineers](<https://devfeed.tech/tags/female-engineers.md>), [information-security](<https://devfeed.tech/tags/information-security.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [women-in-tech](<https://devfeed.tech/tags/women-in-tech.md>)

### AI overview

This profile follows Maria Sepulveda's career transition from customer service and IT recruitment into information security. As a Senior Security Engineer at Skyscanner, she discusses her role, career development, and responsibility for leading the recertification of the company's PCI DSS compliance.

### Source excerpt

Senior Security Engineer Maria Sepulveda As we celebrate International Women in Engineering Day this week, we're profiling female-identifying engineers across our business. Maria Sepulveda is a Senior Security Engineer at Skyscanner. An expert within information security, Maria led the recertification of Skyscanner's PCI DSS (Payment Card Industry data Security Standard) compliance. Maria took an unconventional path to information security, starting her career in customer service and IT recruitment. Here, she discusses her journey, imposter syndrome and what her role looks like today. Maria, as a Senior Security Engineer, what does your role involve? Well, I only recently joined Skyscanner so a typical day for me today might look different to a typical day in a couple of months time! Having said that, I have already been given responsibility to lead the recertification of our PCI-DSS compliance. It's great that I can be trusted so early on in my Skyscanner journey. My day typically starts with following up on tasks that are due in the coming week. During the day I meet with people and various teams to understand what they do. I'll also attend internal events, often to better understand the Skyscanner culture and the way things work here -- as well as to make connections. Focus Time in the afternoon allows me to re-read my notes and absorb information I obtained during the day. The day might end with a recap of the day with my team, allowing me to ask questions I haven't already asked or just generally talk about how the day went. What was your career journey to this point? I took an unconventional path into information security. Originally from Australia, I worked in customer service roles and IT recruitment. I arrived in London and found a job working at an in-house recruitment team for an online betting company. I knew that I wanted to move into a more tech-focussed role but still interfacing with the business. My colleague who was recruiting for the security team

## What Is PCI Compliance?

DevFeed: [What Is PCI Compliance?](<https://devfeed.tech/articles/what-is-pci-compliance-29963.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/what-is-pci/>)

Author: info@goteleport.com (Allan MacGregor)

Published: 2022-05-26T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Transactions](<https://devfeed.tech/topics/transactions.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [e-commerce](<https://devfeed.tech/tags/e-commerce.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [payment](<https://devfeed.tech/tags/payment.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

This article explains PCI compliance and the PCI DSS requirements for organizations that accept, transmit, or store cardholder data. It describes the standard's purpose, security practices, breach response, certification, and how requirements vary by transaction volume.

### Source excerpt

In this blog post we'll look at the PCI compliance standards and how to use PCI standards to ensure your business is compliant.

## Implementing Square's Payment Form in Reaction Commerce

DevFeed: [Implementing Square's Payment Form in Reaction Commerce](<https://devfeed.tech/articles/implementing-square-s-payment-form-in-reaction-commerce-15688.md>)

Original publisher: [Read original article](<https://developer.squareup.com/blog/implementing-sqpaymentform-in-reaction-commerce>)

Author: Richard Moot

Published: 2018-01-12T00:59:44Z

Content type: tutorial

Language: en

Sources: [Square Corner Blog RSS Feed](<https://devfeed.tech/sources/square-corner-blog-rss-feed.md>)

Topics: [Meteor](<https://devfeed.tech/topics/meteor.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Web Development](<https://devfeed.tech/topics/web-development.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apis](<https://devfeed.tech/tags/apis.md>), [checkout](<https://devfeed.tech/tags/checkout.md>), [ecommerce](<https://devfeed.tech/tags/ecommerce.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [implementation](<https://devfeed.tech/tags/implementation.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [library](<https://devfeed.tech/tags/library.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [payment](<https://devfeed.tech/tags/payment.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This tutorial explains how to implement Square's SqPaymentForm JavaScript library in Reaction Commerce. The hosted form captures payment information in an iframe and returns a nonce token that can be used with Square's APIs, while the article addresses Meteor's handling of external scripts.

### Source excerpt

Get Square's payment form implemented in your Reaction Commerce App