Home > Ask the Security Experts > Security Management Questions & Answers > Should PCI DSS auditors be subjective?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Should PCI DSS auditors be subjective?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 16 July 2007
How subjective is a PCI audit? Does the scope of a PCI audit make it more difficult for an auditor to be subjective?

>
EXPERT RESPONSE
Every audit, in some way shape or form is subjective. The reality is it needs to be. If you are looking simply for an automaton to go through a checklist and give you a clean bill of health, you are missing the point of the audit.

Most people fail to realize that audits can and should be a productive experience that not only helps an organization learn what it needs to do better, but also provides some perspective on best practices and other techniques that can improve the information security posture of an organization. The auditor sees far more than you do, so this person should be treated as a resource.

I would encourage my auditor to use his or her subjective opinion of my environment to help me improve my security. And given the wide-ranging nature of different technology environments, it's not possible to define regulations tightly enough to remove subjectivity.

If we are talking about PCI DSS specifically, let's take its first requirement -- "Install and maintain a firewall configuration to protect data." How is that anything but subjective? The auditor will ultimately be the one who defines what an acceptable firewall configuration should be. PCI DSS's third requirement -- "Protect stored data," is similarly nebulous. As you dig into the details of each requirement, there are more specifics detailing what each requirement means, but there is wiggle room -- there always is.

So the bottom line is that an audit, even a PCI DSS audit, is going to be partially subjective. Keep that in mind as you gather you data and go through your audit.

For more information:

  • In this tip by contributor John Kindervag, learn the five biggest misunderstandings about PCI DSS.
  • Learn how PCI DSS compensating controls can help corporations build a strong security program that appeases both examiners and security pros.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Security Management
    Is it against HIPAA regulations to permanently store sensitive information?
    Two-tier distributed systems vs. three-tier distributed systems
    How to prevent software piracy
    How do ISO 17799 and SAS 70 differ?
    Has FFIEC made any VoIP-specific mandates?
    What is the best way to administer exams to students via computer?
    Should computer exams be transmitted as PDF files or Word files?
    Is it against HIPAA regulations to display client names?
    Getting started on a career in penetration testing
    Are there security management products that can track compliance objectives?

    PCI Data Security Standard
    PCI Requirement 6.6 has merchants gearing up
    PCI compliance extends to car washes, quick lubes
    PCI council to launch assessor quality assurance program
    The 'security standards dilemma': Network segmentation and PCI Compliance
    NSS Labs to focus research on PCI technologies
    PCI Confusion
    Trio indicted in restaurant data security breach
    PCI portal aims compliance guidance at smaller merchants
    PCI compliance and Web applications: Code review or firewalls?
    How to test the security of personal details submitted to a website

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    PCI DSS (Payment Card Industry Data Security Standard )  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts