Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Visa slaps payment processors over breaches, defends PCI rules

March 23, 2009 12:00 PM ET

Computerworld - Two payment processors that recently disclosed data breaches have been dropped from Visa Inc.'s list of companies that comply with the PCI data security rules. But analysts said the move may be more about Visa protecting itself than about improving the security of payment card data.

Visa said on March 13 that it was dropping Heartland Payment Systems Inc. and RBS WorldPay Inc. from its PCI-compliant list. The company added that it would "consider" restoring Heartland and RBS WorldPay if they are recertified as compliant by third-party assessors.

Gartner Inc. analyst Avivah Litan said that, strictly speaking, Visa's actions mean merchants can't use either payment processor if they themselves want to remain compliant with the PCI rules, which are known as the Payment Card Industry Data Security Standard (PCI DSS).

It's highly unlikely, though, that Visa intends for the sanctions to be interpreted in such a restrictive way, Litan said. Instead, she contended, they appear to be designed primarily to give Visa legal protection and prevent Heartland and RBS WorldPay from using PCI DSS as a shield against breach-related lawsuits.

"This is all about Visa protecting Visa," agreed David Taylor, founder of PCI Knowledge Base, a Web site that offers advice on PCI-related issues.

Taylor acknowledged that the two breaches have created a "difficult situation" for Visa, which has taken the lead among credit card companies in trying to enforce the PCI rules. But Visa officials seem anxious to avoid getting into debates about the standard's effectiveness, he said.

In a speech at the Global Security Summit, which Visa held in Washington last week, Ellen Richey, Visa's chief enterprise risk officer, insisted that PCI is "an effective security tool when implemented properly."

The breach at Heartland wouldn't have happened, Richey said, if the payment processor had been vigilant about maintaining its PCI compliance. "No compromised entity has yet been found to be in compliance with PCI DSS at the time of a breach," she said.

However, Heartland has said that its PCI compliance was validated by an auditor last April, only a month before the breach is thought to have begun.

Similarly, RBS WorldPay, which was certified as compliant last June, said last week that it has made "no material system changes that would have negatively altered the certification."

This version of this article originally appeared in Computerworld's print edition.

Read more about security in Computerworld's Security Knowledge Center.



Jump to comments

Visa

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs