|
Comments
|
Today's Top SOA Links
Cloud Computing Viewpoint Will You Comply or Just Check the Box?
There are a couple interesting PCI developments coming over the next rc year
By: Peter Silva
Oct. 22, 2009 06:45 PM
Some of both, apparently. A recent Ponemon Institute PCI-DSS Compliance survey revealed that 71% of companies actually admitted that data security is not a top priority and 55% say they are only protecting credit card data and not other sensitive information like bank account info, social security numbers and drivers license data.
Additional statistics show that a miniscule 28% of smaller companies (501-1000 employees) are PCI-DSS compliant and around 70% of large companies (>75,000 employees) say they meet the Regulations. The one that jumps out for me is the small merchant stat. I understand that cost is a large factor for smaller companies to be PCI compliant but just imagine how many companies and industries that fall into the 501-1000 employee category.
And that doesn’t count all the even smaller ‘Family Owned’ restaurants, auto repair shops or any other service where you say, ‘I like them because they are local or family owned.’ Unfortunately, those friendly establishments might not be a BFF with your sensitive data. I’m not saying to avoid your favorite Chinese take-out but also be aware that the numbers are against you.
There are a couple interesting PCI developments coming over the next These are those standalone ‘Pay for your parking’ machines, gas station terminals, ticket kiosks, vending machines and any other terminal where a PIN might be entered. First, July 1, 2009, was the deadline for Triple-DES to be mandated for all debit transaction processing. And next July, all fuel pumps (and like terminals) will need to have encrypted PIN entry pad, be able to encrypt the PIN itself and process using TDES. I imagine there will be another mad dash next spring for merchants to get in compliance. The other PCI piece is come summer 2010, PCI will be making some regulatory changes to update PCI standards including 3rd party audits (Level II), tokens, end-to-end encryption and potentially Virtualization Security. Some of these changes should help in protecting our data. And if you think skirting regulations might be a money saver, take a look at this article where the FTC has recently fined ChoicePoint for not adhering to the agreement made in 2006 for the huge 2005 data breach. They just got whacked with another $275,000 for removing a database security monitoring tool. As I finish up the 18th entry of 26 Short Topics I’ve noticed Regulatory ps UPDATE - Added 10.22.09: ChoicePoint would like to clarify the characterization of the FTC situation and I'm happy to include this for accuracy:
"Your piece titled "Will you Comply or Just Check the Box" touches on recent ChoicePoint/FTC news and the company would like to request a clarification. 1. In regards to your report that a "fine" was levied by the FTC a. While the Commission has authority to seek a civil penalty, http://ftc.gov/ogc/brfovrvw. release and has since revised its press release to correct this point. The payment was made pursuant to the courts equitable authority to address compliance with its orders. The payment is not punitive in nature and neither the Order nor the FTC press release (as modified) characterizes the payment as a fine or a penalty. Thank you so much for you time and attention. We would very much appreciate your correction of the record." - Not a problem, thanks for the update and appreciate the clarification. ps
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
|
SYS-CON Featured Whitepapers
Most Read This Week |
|||||||||||||||||||||||||||