Email Alerts
-
Should there be PCI security requirements for bank account data?
Gartner analyst wonders why no PCI-like standard exists for bank account information, which online criminals are targeting. Article | 18 May 2010
-
PCI compliance encryption includes hardening key management systems
As companies deploy encryption to protect cardholder data, French security giant, Thales Group is making the case for hardware security modules (HSMs) to protect the underlying key management systems at the heart of all encryption systems. According ... Interview | 03 May 2010
-
PCI security compliance experts share ways to get compliance 'done right'
Don't whine about having to achieve PCI compliance and don't think of PCI as an end-goal, said two experts at SOURCE Boston 2010. Article | 26 Apr 2010
-
PCI Council readying end-to-end encryption guidance
The PCI Security Standards Council is studying a number of emerging technologies and plans to issue a guidance document on end-to-end encryption when it releases the next version of the PCI Data Security Standards (PCI DSS), due out in October. Bob R... Interview | 06 Apr 2010
-
PCI tokenization push promising but premature, experts say
Merchants see value in the technology helping to reduce the scope of a PCI assessment, but a lack of standards and complexity issues are a cause for concern. Article | 04 Mar 2010
-
No major PCI DSS revision expected in 2010
The next revision of PCI DSS will contain clarifications, but no major revisions, according to Bob Russo, general manager of the PCI Security Standards Council. Article | 27 Jan 2010
-
PCI QSAs, certifications to get new scrutiny
The PCI Security Standards Council now has a team of five reviewing PCI assessments for inconsistencies and has increased funding for its QSA oversight program. Article | 26 Jan 2010
-
MasterCard reverses PCI compliance requirement
New rules do not require a QSA onsite assessment for Level 2 merchants. News | 22 Dec 2009
-
Chip and PIN adoption serves lesson for U.S. payment industry
As payment processors offer plans for end-to-end encryption, the UK is finding success with chip and pin deployments. The U.S. payment industry should take notice, expert says. Column | 29 Oct 2009
-
Heartland CIO is critical of First Data's credit card tokenization plan
First Data Corp. uses RSA software for tokenization, providing a possible threat vector for attackers, says Heartland CIO Steven Elefant. Article | 26 Oct 2009
Security Management Strategies for the CIO