We have read complaints on other blogs about the PCI standards, claiming they are a burden for merchants and software developers.However, when taking into account the documented link between credit card fraud—which PCI DSS was developed to fight against—and terrorism, perhaps complaints about security standards will fall silent.
Kimberly Kiefer Peretti, Senior Counsel in the [...]
It seems like everyone (including this author) today has an opinion on the value of the PCI DSS and the card brand programs. In March, 2009 Congress held hearings on the standard and there are a number of companies that make a living from the program.No matter people’s view of the PCI DSS, my own [...]
PCI DSS is Payment Card Industry Data Security Standard, a collaborative effort to achieve a common set of security standards for use by entities that process, store, or transport payment card data. This applies to: all merchants that “store, process, or transmit cardholder data” and all payment channels including brick-and-mortar, mail, telephone, and e-commerce.
PCI [...]
Over the past few weeks and months I’ve been helping to develop a PCI DSS System for a client. It’s been quite a feat as there are quite a few integrity checks, tripwire monitors to set up and automate – as well as having the services that are running audited for secure protocols – and [...]
‘PCI compliance‘ IS A TERM that gets bantered about by software companies, credit card companies, financial firms, banks and more.
So what is it? Basically it is a set of standards which have been agreed upon by the 4 largest Credit Card companies – ie, Visa, MasterCard, Discover and American Express. to guarantee the security [...]
Today I participated in a very interesting pci panel at ISSA Denver RMISC 2009 conference in Denver.Practically,even our pre-panel discussion was very interesting:we intended to hit such subjects as checklist mentality vs risk mentality, prescriptive compliance versus outcome-based compliance, PCI for various sizes of organizations and even PCI compliance in virtualized environments.
At start,it was [...]