Skip to main content

The WiKID Blog

Viewing posts tagged Security and Economics

more-on-pci-security-random-pen-testing

In thinking a bit more about PCI security since my post on PCI visibility. I think what Visa and Mastercard need to do is to hire independent 3rd party penetration testers to pen test merchants and processors.

The PCI Three are making a big switch in September, when they will start fining acquiring banks non-compliant merchants. However, there are two problems with the auditing procedures: Auditors are paid by the companies they are auditing and audits are static snapshots. I'm not insinuating anything here about the ethics of PCI auditors, just pointing out the agency conflict and that a company might get compliant for an audit, then lapse out of compliance.

networkworld-on-pci-conflicts-of-interest

NetworkWorld has an article on the potential for conflicts of interest in the PCI world. In sum:

  • There are only 60 qualified security assessors (QSAs).
  • Many QSAs also sell products.

new-non-profit-educational-discounts-plus-pay-what

Today we announced a new pricing program for home users: pay what you want. This variable payment plan for home users is based on the recent bands that have tested this system (Radiohead and NIN). But the trigger was also the free for home use offer for SSL-Explorer>. I have, of course, seen a lot of free for home use enterprise software and we may yet go there. But I also believe that this should be an interesting experiment.

new-incentives-for-pci-compliance-from-visa

Visa's CEO hinted during a keynote speach that Visa may be looking at increasing incentives for PCI compliance.

Coghlan’s reference to incentives for compliance with the Payment Card Industry data-security standard follows a year that saw major hacker breaches of databases containing sensitive card information, including PINs for debit cards. “We need to do a better job with data security,” Coghlan said.

open-source-momentum-and-spending-during-the

Hat Tip: Slashdot, From ComputerWorld:

Recent Posts

Archive

2024
2022
2021
2019
2018
2017
2016
2015
2014
2013
2012
2011
2010
2009
2008

Categories

Tags

Authors

Feeds

RSS / Atom