This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

2/3 -Fail- Credit Card Security Compliance - PCI

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

2/3 -Fail- Credit Card Security Compliance - PCI
- http://www.informationweek.com/news/securi…endly=this-page
April 20, 2011 - "The Payment Card Industry Data Security Standard - known as PCI DSS, or just PCI - is meant to safeguard cardholder data. Yet, 67% of PCI-regulated companies are still not in full compliance with the standard… According to the study**, 50% of security professionals view PCI as a burden, and 59% don't think it helps them improve security. Furthermore, comparing this study with the inaugural one conducted in 2009, the number of respondents who said they had sufficient resources to comply with PCI dropped from 40% to 38%. In addition, Ponemon also found that the number of organizations that had experienced a data breach in the past two years increased from 79% in 2009 to 85% in 2011. Companies reporting that they'd experienced between two and five data breaches in the past 24 months also jumped from 30% to 41%. Furthermore, 39% of all breaches, the study found, involved cardholder data. Companies that were not in compliance with PCI experienced more data breaches. For example, while 64% of PCI-compliant companies experienced no data breaches in the past two years, only 38% of non-compliant companies* didn't experience a data breach…"
* http://www.informationweek.com/news/smb/se…endly=this-page

** http://blog.imperva.com/2011/04/pcis-impac…quantified.html

:( :blink:
I find PCI rather annoying and generally useless. It involves a monthly audit to discover if your machine or network has vulnerabilities. If you keep up decent machine and network security anyway, they won't find any breaches. I do think they have a decent protocol for company policy development. Unfortunately, as to company policy, all you have to do is "say" that you have one, and you pass that portion of PCI.

"I find PCI rather annoying and generally useless…"

I understand that the perception from the inside might lead to that conclusion. However, unless you can provide a better standard or plan, and -sell- it to management so it becomes policy, resign yourself to the fact that nothing will change or get any better.

The numbers support the facts here:
- http://blog.imperva.com/2011/04/pcis-impac…quantified.html
"… #1: There is a dramatic difference with respect to number of breaches between compliant and non compliant organizations…
#4: Achieving effective compliance greatly depends on finding cost-effective solutions rather than spending more money…
#5: Business Unit Leaders are taking over PCI management…"

So, it's "Go with the flow", or present and implement a better one.

.