Are the PCI-DSS Standards Working?

 





The major credit card companies have been strong-arming companies, that process credit cards, into compliance for over 3 years now, but is it working?  The obvious answer may seem to be yes.  Droves of companies report annual compliance and have auditors verify that with on-site audits.  This has effectively made these companies safer then, right?

 

Well not necessarily.  While the PCI-DSS Board, the organization that provides the PCI standards, will attest to the fact that their requirements do improve a company’s overall IT safety; they too rely on the certified PCI auditors to report a company’s compliance with these standards.  Therein lies the problem.

 

A company’s compliance is dependant on what the PCI auditor, certified by PCI-DSS mind you, reports back to the PCI-DSS Board.  In many cases they, like many auditors, perform an audit based off of questionnaires and individual interviews with IT personnel.

 

A compliance officer, at a major fast food restaurant chain, said that they use canned audit responses each year, and at their PCI level, that those answers are almost never questioned. This type of attitude seems to be the trend.

 

“I just tell them [PCI auditors] whatever they want to hear.” said Maryann Douglass, in charge of PCI compliance for Macys, Inc. “I’m sure everyone else fibs to auditors too. Around here, I jokingly call that the real Magic of Macys.” Douglass continued.

 

With some companies not taking the credit regulations as serious as the PCI-DSS board would like, is this a place where the Federal Government should step in?  Many say no, but even if that happened would that help.  It’s still too early to tell.

 

With attacks on companies still on the rise, the question may not be whether or not the PCI-DSS standards are working, but rather is it happening at all.


Downloaded 1 times

Find More References Like This

Signup for Thought Leader

Get the latest IT management thought leadership delivered to your mailbox.

Mailchimp Signup (Short)
Cioindex No Spam Guarantee Shield

Our 100% “NO SPAM” Guarantee

We respect your privacy. We will not share, sell, or otherwise distribute your information to any third party. Period. You have full control over your data and can opt out of communications whenever you choose.