The Green Sheet Online Edition

November 11, 2011 • 11:11:02

PCI: Target or shield

Since 2006 and the formation of the PCI Security Standards Council (PCI SSC) by the major credit card brands, identity theft and data breaches have continued to escalate - from large-scale incidents, impacting more than 130 million credit and debit cards, to an alarming and recent focus on small businesses.

According to the Verizon 2011 Payment Card Industry Compliance Report, roughly 80 percent of businesses in 2010 were not 100 percent compliant with the Payment Card Industry (PCI) Data Security Standard (DSS), an evolving standard managed by the PCI SSC to increase controls around cardholder data in an effort to reduce fraud.

To make matters worse, retailers and politicians often view breaches as an opportunity to attack the PCI DSS. Meanwhile, industry leaders and the PCI SSC forge onward with promoting adherence to and updating the data security standard. This article will explore some of the most common attacks on the PCI DSS and how merchants and the ISOs and acquirers that serve them can better understand, embrace and deploy the standard within their organizations.

Caught in the crossfire

Most criticisms of the PCI DSS are overly broad, demonstrating a lack of understanding of the standard or review of even the most basic of its requirements. Others are very specific, which are more often than not currently being discussed by the PCI SSC or addressed in updates to the standard, such as the PCI DSS 2.0. Let's explore some of the most common criticisms.

PCI - An evolving standard

While the list of complaints may seem lengthy, the truth is the PCI DSS has forced the payments industry, financial institutions, businesses of all sizes and even consumers to pay more attention to information technology (IT) infrastructure and personal data security, and notable progress has been made toward improved security.

Terms of agreement

There is a statement both sides can agree upon: PCI compliance has largely been adopted as a point-in-time event. To be truly effective in preventing hacks and breaches, merchants and the ISOs and acquirers that serve them must maintain a continually vigilant security posture through the use of layered security, internal policies, continual review of all transaction equipment and payment terminals, and guidance from PCI-compliance and security solutions vendors.

The following correspondence from a PCI-compliance provider to its customers, demonstrates the importance of consistent application of and adherence to the PCI DSS:

Today, consumers are much more conscious of identity theft and protecting personal information than in the past. The PCI DSS provides a prescriptive baseline that improves security posture while providing a firm security foundation to build on. Meeting PCI compliance standards through constant and vigilant monitoring of business practices through the lens of the security standard is good for business.

By protecting against cardholder fraud, merchants are providing a valuable service and obligation to customers, as well as protecting one of their most important assets: their business reputations. End of Story

Steve Robb is Vice President of Products & Services for Atlanta-based ControlScan Inc., a provider of PCI compliance and security solutions that fit the specific needs of small- to medium-sized merchants. He can be reached at srobb@controlscan.com.

Whether you want to upgrade your POS offerings, find a payment gateway partner, bone up on fintech regs or PCI requirements, find an upcoming trade show, read about faster payments, or discover the latest innovations in merchant acquiring, The Green Sheet is the resource for you. Since 1983, we've helped empower and connect payments professionals, starting with the merchant level salespeople who bring tailored payment acceptance and digital commerce tools, along with a host of other business services to merchants across the globe. The Green Sheet Inc. is also a proud affiliate of Bankcard Life, a premier community that provides industry-leading training and resources for payment professionals.

Notice to readers: These are archived articles. Contact information, links and other details may be out of date. We regret any inconvenience.

skyscraper ad