Home > Ask the Security Experts > Security Management Questions & Answers > How are the PCI DSS deadline extensions affecting corporations' desire to become compliant?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How are the PCI DSS deadline extensions affecting corporations' desire to become compliant?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 31 January 2008
How are the PCI DSS deadline extensions affecting corporations' desire to become compliant? Why do you think banks and credit card companies are issuing these extensions?

>
EXPERT RESPONSE
Most of the extensions issued by banks have been kept relatively hush-hush. Obviously they don't want retailers to think they can put off doing the right stuff to get compliant. To specifically answer the first part of your question, there are basically two types of companies out there: those that are trying to do the right thing for their customers by getting compliant, and those that aren't as interested because they don't think a breach will happen to them. Thus they do the bare minimum at all times, such as putting off fixing things until the auditor shows up and forces the issue. I'm not sure why any self-respecting security professional would work in an environment like this.

I'm actually OK with the former companies (that are doing their best) getting reasonable extensions and then being held accountable to make the agreed-upon progress. Getting PCI DSS compliant is a reasonably long and fairly hard struggle for a corporation that hasn't done much relative to security.

The other type of company should be drawn and quartered (and fined) and made to understand how important it is to safeguard customer data. But that is likely a losing battle.

In terms of why the banks would offer these extensions, it's a basic risk management decision. They assess the track record of the retailer and try to figure out how exposed they are to fraud. Then they decide if it's a good idea to issue the extension versus saying no and risking that the retailer will take its business elsewhere. Remember, merchant banking is a competitive business, and some banks will relax general risk standards if they think it's a good business decision.

More information:


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Security Management
What value do research firms provide to enterprises that subscribe to their services?
What certificate offers the best ROI for an IT project manager?
What role does information security play in enterprise fraud-prevention activities?
What is the difference between an SAS 70 data center and a Tier III data center?
What does the future of the endpoint encryption market look like?
Are independent researchers out for fame?
Would you recommend SANS Institute security training?
What vendors would you recommend for software write-blockers?
What can be done to keep students from becoming cybercriminals?
Is there a published standard or guideline for system hardening?

PCI Data Security Standard
WEP to WPA: Wireless encryption in the wake of PCI DSS 1.2
PCI is about eliminating data, not securing it, former QSA says.
Security of customer data, IP sustains security budgets
PCI version 1.2 clarifications: How to get an early start on compliance audits
Version 1.2 of Payment Card Industry (PCI) Data Security Standard answers questions, raises others
Security visualization helps make log files work
The Little Black Book of Computer Security, 2nd Edition
Data breach discovery, disclosure outpaces 2007
PCI groups to focus on wireless, pre-authorization changes
PCI DSS 1.2 clarifies wireless, antivirus use

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
PCI DSS (Payment Card Industry Data Security Standard )  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
Targeted Security Channel Tips for Resellers, Integrators and Consultants
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts