Merchants Struggle to Comply With PCI Security In Economy
The heads of seven business organizations sent PCI Security Standards Council General Manager Bob Russo a cry for help earlier this month, saying the recession is making it "increasingly difficult" for merchants to meet the requirements of the Payment Card Industry's Data Security Standard (PCI DSS).
In an interview Wednesday, Russo said he understands what merchants are going through and that everyone will have a chance to offer input for the next version of the standard, set for release in September 2010. [Related: PCI Debate Ignores Planned Improvement Cycle]
[ LISTEN to what Russo had to say in this audio clip]
In the letter, leaders of the National Association of Convenience Stores, National Retail Federation, National Restaurant Association, American Hotel and Lodging Association, National Council of Chain Restaurants, Merchant Advisory Group and the International Franchise Association cited the trouble merchants are having:
"The vast majority of our members take data security seriously and have spent in excess of $1 billion on PCI DSS compliance as part of their security programs. However, it is becoming increasingly difficult for our members to comply with the program's requirements in a cost-effective and timely manner; especially in this difficult economic climate."
To alleviate the stress without compromising the security needed to protect cardholder data, the organizations proposed the following:
1. Incorporate a formal review and comment phase on revisions to the PCI DSS by participating membership before they are issued. This will result in more informed revisions and will increase merchants' understanding of and ability to effectively implement the revised standards. We suggest that the PCI SSC adopt a similar process for writing standards in an open environment as is used by Accredited Standards Committee X9 (ASC X9). As ASC X9 also maintains data security standards, we recommend the PCI SSC partner with them in an effort to create a single standard that could be used by all.
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
On Twitter now
pci dss
Powered by Twitter
jfruh
Apple syncing patent can't come soon enough
pasmith
New Twitter features borrow from 3rd party clients
Esther Schindler
Open Source Changes the Software Acquisition Process
mikelgan
How to set up continuous podcast play on the new iTunes
David Strom
Five important Windows 7 mobility features
sjvn
Guard your Wi-Fi for your own sake
Sandra Henry-Stocker
Grepping on Whole Words
Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325
Join the conversation here
Quick, practical advice for IT pros. Made fresh daily.
Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.












