Skip to main content
Tibor Laczko

Tibor Laczko

Senior Consultant and Qualified Security Assessor (QSA) at URM Consulting, specializing in PCI DSS compliance.

Sep 10, 2026

6:22
There's no way they're too admin intensive to do them on the fly.
6:29
yeah you have to develop the control then they need to develop the control they need to explain to you what their control is and then the qsa needs to derive the testing procedure as they see fit to validate the control that the organization put in place so it's not documented in standard there's no testing procedures written for it so this is not something again when you know you're not like day four in the assessment and there's something that's not there, it's like, oh, you know what, let's just do a customized validation.
7:02
Yeah, no, it's not going to work.
7:04
Plus, I think, yeah, and I don't know about you, but like I've run into this a couple of times, well, even ahead of the assessment.
7:11
But then when you explain to the client how much extra effort is required to do a customized validation, they sort of like shy away from it.

9 MINS LATER

16:35
So that's also probably why it's not used as often because most organizations probably aren't risk mature enough to be able to do
16:41
these kinds of things.
16:43
Although this is one of those things, I think it's important for us to point out that both composite controls and customized validation controls needs to be revisited every year.
4:17
Yeah.
4:17
Now you need to do your targeted risk analysis.
4:19
However, I don't know.
4:20
It's-- So in previous versions, it was, like, the overall risk management of an organization, and it, and now it's very focused on the targeted risk analysis or the customized approach validation.
4:34
So I think it did kind of like th- the council went away from, okay, so we're not looking at the enterprise as a whole.
4:42
Uh, we're looking at certain controls, which, to be honest with you, if the question is whether it improved security, I think it's kind of went-

9 MINS LATER

13:54
Um-
13:54
Yeah.
23:29
So you kind of have to audit them essentially to the requirements
23:33
in question.
23:34
You need to pull them into your assessment or your client's assessment.
23:39
So when you, you can, you know, tell them that you need to become PCR compliant.
23:45
Well, you can, but I guess it depends on how big of a business it is that the service provider provides for you, but are they willing to go through it? But if not, I have a client right now.
23:58
Their hosting provider is not PCI compliant, but they're very happy to be involved in the assessment.
24:06
So they're made time aside through the gap analysis portion of the assessment or the engagement.

8 MINS LATER

32:41
Yeah, I
19:21
So it's understanding that you can split the responsibility across the environment to make it a shared responsibility.
19:28
Well, a responsibility matrix should be either the clients, the service provider, or shared.
19:35
My general advice to my clients always is, if it's your responsibility, you don't really have to say anything.
19:43
If you deem that it's your client's responsibility, explain why you believe it's your client's responsibility.
19:49
And if it's shared, especially then, be able to draw a line because this is how much I do, but anything on top of it is your responsibility.
20:01
This is what I see most often from responsibility matrices.
20:07
And especially, I mean, I'm not calling out any of, I wouldn't dare calling out any of the large cloud providers, but when one responsibility matrix is used for 225 products, it's difficult sometimes to understand.

14 MINS LATER

34:55
Speed is key when it comes to responding to incidents.
1:39
Yeah.
1:40
Uh, no servers, no physical devices.
1:42
So your provider runs the platform, you run the code on it.
1:46
But I think where when it comes to serverless, um, at least what I see, is sometimes they think no servers, no responsibility.
1:54
That doesn't mean that.
1:56
Like, um, the customer still needs to run their code.
1:58
They n- still need to, um...
4:20
Mm-hmm

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.