Lauren Holloway

Director of Data Security Standards, PCI Security Standards Council

Ms. Holloway is the Director, Data Security Standards for the PCI Security Standards Council where her roles include managing and guiding PCI DSS and all related collateral, and coordinating PCI SSC’s efforts with the Small Merchant Task Force. Prior to joining the Council in 2010, Ms. Holloway led and coordinated Visa’s efforts for PCI DSS and PA-DSS and related programs for several years. Ms. Holloway’s extensive information security and audit background includes managing information security at an internet payment gateway, consulting with a Big 4 audit firm, and conducting and managing internal audits for computer systems at a Fortune 500 company. Ms. Holloway holds the CISSP, CISM, and CISA designations.

Lauren Holloway's Events

Assessor Session

Date: Tuesday, September 10

Presented by: Marc Bayerkohler, Standards Trainer, PCI Security Standards Council; Lauren Holloway, Director of Data Security Standards, PCI Security Standards Council; Matt O’Connor, Director, AQM, PCI Security Standards Council and Travis Powell, Director, Training Programs, PCI Security Standards Council

Assessor Session (QSAs, ISAs, ASVs, PFIs, QPAs, CPSAs, SSF, P2PE, 3DS assessors only): As an active assessor in the PCI SSC programs, join us for a special session to hear industry best practices, recent case studies, Council updates, live Q&A and networking opportunities with your peers.

What Are the Implications of Infrastructure as Code and PCI DSS?

Date: Wednesday, September 11

Track Two

Presented by: Lauren Holloway, Director of Data Security Standards, PCI Security Standards Council and Peter O’Sullivan, Principal Information Security Consultant, Blackfoot Cybersecurity

Wondering how to handle Infrastructure as Code and cloud deployments for PCI DSS? This session considers how to meet PCI DSS requirements in environments defined by Infrastructure as Code from the Council’s perspective and an assessor’s viewpoint. Topics include integration, code repositories, scoping, significant changes, and assessment practicalities.