
Tibor Laczko
Senior Consultant and Qualified Security Assessor (QSA) at URM Consulting, specializing in PCI DSS compliance.
5
APPEARANCES
1
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
SEP 21
SEP 28
Sep 10, 2026
PCI DSS Compensating Controls vs. Customized Approach
6:29
7:04
7:11
16:35
16:43

Tibor LaczkoGUEST
yeah you have to develop the control then they need to develop the control they need to explain to you what their control is and then the qsa needs to derive the testing procedure as they see fit to validate the control that the organization put in place so it's not documented in standard there's no testing procedures written for it so this is not something again when you know you're not like day four in the assessment and there's something that's not there, it's like, oh, you know what, let's just do a customized validation.

Tibor LaczkoGUEST
Plus, I think, yeah, and I don't know about you, but like I've run into this a couple of times, well, even ahead of the assessment.

Tibor LaczkoGUEST
But then when you explain to the client how much extra effort is required to do a customized validation, they sort of like shy away from it.
9 MINS LATER

Alistair StewartGUEST
So that's also probably why it's not used as often because most organizations probably aren't risk mature enough to be able to do

Tibor LaczkoGUEST
Although this is one of those things, I think it's important for us to point out that both composite controls and customized validation controls needs to be revisited every year.
PCI DSS Periodic Activities
4:20
4:34
4:42

Tibor LaczkoGUEST
It's-- So in previous versions, it was, like, the overall risk management of an organization, and it, and now it's very focused on the targeted risk analysis or the customized approach validation.

Tibor LaczkoGUEST
So I think it did kind of like th- the council went away from, okay, so we're not looking at the enterprise as a whole.

Tibor LaczkoGUEST
Uh, we're looking at certain controls, which, to be honest with you, if the question is whether it improved security, I think it's kind of went-
9 MINS LATER
PCI DSS Scoping
23:39
23:45
23:58
24:06

Tibor LaczkoGUEST
So when you, you can, you know, tell them that you need to become PCR compliant.

Tibor LaczkoGUEST
Well, you can, but I guess it depends on how big of a business it is that the service provider provides for you, but are they willing to go through it? But if not, I have a client right now.

Tibor LaczkoGUEST
Their hosting provider is not PCI compliant, but they're very happy to be involved in the assessment.

Tibor LaczkoGUEST
So they're made time aside through the gap analysis portion of the assessment or the engagement.
8 MINS LATER
PCI DSS and Service Providers
19:21
19:28
19:35
19:43
19:49
20:07

Alistair StewartGUEST
So it's understanding that you can split the responsibility across the environment to make it a shared responsibility.

Tibor LaczkoGUEST
Well, a responsibility matrix should be either the clients, the service provider, or shared.

Tibor LaczkoGUEST
My general advice to my clients always is, if it's your responsibility, you don't really have to say anything.

Tibor LaczkoGUEST
If you deem that it's your client's responsibility, explain why you believe it's your client's responsibility.

Tibor LaczkoGUEST
And if it's shared, especially then, be able to draw a line because this is how much I do, but anything on top of it is your responsibility.

Tibor LaczkoGUEST
And especially, I mean, I'm not calling out any of, I wouldn't dare calling out any of the large cloud providers, but when one responsibility matrix is used for 225 products, it's difficult sometimes to understand.
14 MINS LATER
PCI DSS and Severless Architecture
1:46

Tibor LaczkoGUEST
But I think where when it comes to serverless, um, at least what I see, is sometimes they think no servers, no responsibility.