According to a recent report from vendor SecurityMetrics, about seven out of 10 merchants have unencrypted credit...
By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.
card data storage, a practice strictly prohibited by the PCI DSS. PCI DSS compliance isn't new, so why does this still happen? What are the most common areas where merchants inappropriately store card data?
Ask the Expert!
Got a vexing problem for Mike Chapple or any of our other experts? Ask your enterprise-specific questions today! (All questions are anonymous.)
The study you mention is truly mind-boggling. It found that 71% of participating merchants are storing unencrypted payment card information, in clear violation of the Payment Card Industry Data Security Standard (PCI DSS). Not only does this represent a breach of PCI DSS, but it also puts the merchant holding the information at significant risk of causing a breach of personal information that may lead to financial loss and/or identity theft.
I believe that the organizations storing this information could fall into the following four categories:
- Those that are blissfully unaware of their obligations under PCI DSS. There's not much excuse for ignorance anymore. I would expect that only the smallest or newest merchants do not understand that PCI DSS dictates the ways in which the handling and storing of credit card data should occur.
- Those that are unaware that their payment application is storing unencrypted cardholder information. My guess is that this is the largest category. Many merchants probably believe that they purchased "secure" software that is handling cardholder data appropriately, while in reality the software may be storing unencrypted cardholder information, unbeknownst to the merchant. Merchants should ensure that they are running software that appears on the list of Validated Payment Applications and that they are running a software version that is certified compliant. It's important to remember that many of the same vendors that now produce applications compliant with Payment Application Data Security Standard once produced versions that were not compliant. Monitoring the compliance status of your particular application version and applying patches and updates should be critical components of your PCI DSS compliance program.
- Those that have legacy databases containing cardholder information. Some organizations may have upgraded to PA DSS-validated applications, but still have legacy databases that contain unencrypted information from older systems or business processes. These databases should be sought out and either destroyed or secured.
- Those that are storing unencrypted information willfully. Hopefully, this is a small category, but there are undoubtedly merchants out there that know they are storing data in violation of PCI DSS and simply aren't doing anything about it.
If you're not certain that you've successfully removed all unencrypted card information from your systems, take the time to conduct a thorough audit. It's better to invest time and resources now to discover areas where you might need to change your practices, than discover later that you've either failed an assessment or been the victim of a major breach.
Dig Deeper on PCI Data Security Standard
Related Q&A from Mike Chapple
A proposed cyberattack information database in the U.K. aims to improve cyberinsurance. Expert Mike Chapple explains what collecting data breach ...continue reading
The proposed CFTC regulations on cybersecurity testing are set to finalize in 2016. Expert Mike Chapple discusses the effects these regulations have ...continue reading
Whether Apple is a HIPAA covered entity was called into question when it advertised for a health regulations lawyer. Expert Mike Chapple discusses ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.