PCI security rules may require reinforcements
Critics carp that the standard isn't protecting credit and debit card data. And chief proponent Visa is working on new technologies that would go beyond PCI's current controls.
Computerworld - The PCI standard, long touted as one of the private sector's strongest attempts to regulate itself on IT security, is increasingly being slammed by critics who claim that the rules aren't doing enough to protect credit and debit card data.
And amid all the complaints, Visa Inc. — the standard's biggest proponent — is working one-on-one with banks and retailers to test new security measures that go beyond the controls currently mandated by PCI.
What it all adds up to is a new sense of uncertainty about the future of the specification, which is formally known as the Payment Card Industry Data Security Standard, or PCI DSS. Created by Visa and other credit card companies, the PCI rules will have been in effect for four years as of June 30. But with breaches of card data continuing and questions about the standard's effectiveness on the rise, PCI DSS is showing signs of coming apart at the seams.
Criticism of the standard isn't new. But since the recent disclosures of breaches by payment processors Heartland Payment Systems Inc. and RBS WorldPay Inc., PCI DSS has been hit with some of its most forceful denunciations thus far.
For instance, at a March 31 hearing held in the U.S. House of Representatives, Rep. Yvette Clarke (D-N.Y.) said that PCI DSS simply isn't sufficient for protecting cardholder data. The security rules aren't "worthless," said Clarke, who chairs a subcommittee that focuses on cybersecurity among other topics. But, she added, "I do want to dispel the myth once and for all that PCI compliance is enough to keep a company secure."
As an example, Clarke pointed to the data breach disclosed early last year by Hannaford Bros. Co. The grocery store chain was certified as PCI-compliant by a third-party assessor in February 2008 — one day after it was informed of the system intrusions that had begun two months earlier.
Similarly, RBS WorldPay and Heartland both received PCI certifications last year prior to the breaches that they disclosed in December and January, respectively. Visa dropped the two companies from its list of PCI-compliant service providers last month and is requiring them to be recertified, although it has said merchants can continue to do business with them in the meantime.
Michael Jones, CIO at arts and crafts retailer Michaels Stores Inc., said at the House hearing that the PCI rules appear to have been developed "from the perspective of the card companies, rather than from that of those who are expected to follow them." As a result, he contended, the requirements don't necessarily help to protect data.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts