Personal tools
You are here: Home WiKIDBlog problems-with-the-pci-security-standard

problems-with-the-pci-security-standard

by admin posted on Jan 21, 2009 03:46 PM last modified Apr 03, 2009 11:56 AM —

Mark Curphey has some thoughts about the problems with the PCI security standard and it looks like he is just getting started....

Mark Curphey has some thoughts about the problems with the PCI security standard and it looks like he is just getting started. I would like to also point out a comment left by an anonymous poster (probably because he or she makes a living doing PCI audits) in a previous post on PCI:

The problem with the Visa PCI standard is that Visa/MC have a vested interested in keeping the business flowing. The entity that is responsible for answering Visa is the issuing bank. The retailer is responisible to the issuing bank. The reports are filed with the issuing banks and shared with Visa. The problem with this structure is that all parties have a financial interest in keeping the business flowing. It takes a serious public violation, like card systems, for Visa/Issuing Banks to drop a vendor.

I recognize that there are problems with PCI, yet to me, it seems like it is the best of what is out there, especially when compared to something like HIPAA. While all the parties are interested in keeping the money flowing, they are also interested in avoiding excessive regulation and liability.

Document Actions