Payment Card Industry (PCI) update - Network World

Skip Links

DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Small Business Networking

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library.  Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Audio

Six Minutes With ... Perry Wu, CEO of BitGravity. Listen now!

DEMO: Six minutes with...

Six Minutes With ... Scott Ryan, CEO of Asankya. Listen now!

DEMO: Six minutes with...

Additional Resources

RSS

FEATURED REPORTS

Executive Guide: Storage Heats Up HP

Get the latest on storage technologies that allow IT professionals to better cope with new IT demands. Learn how storage technologies can help you successfully tackle e-Discover, regulatory compliance, green data center initiatives and the data explosion. Get all the details now.

RSS

FEATURED WEBCASTS

Get Real-world Advice on how to Cost Effectively Consolidate your Data Center Novell

Discover the benefits of paravirtualization in this informative webcast today. This server virtualization-themed webcast not only explores how to improve virtualized server performance, but provides real-world user examples, explains how to optimize workloads and discusses the future of server virtualization. Focus on only the themes that interest you or watch all six consecutively for a full picture of how you can lower your costs significantly through consolidation and virtualization. Register below to learn more and be entered to win an Archos 605 Portable Media Player.

IT Buyer's Guides

View All Buyer's Guides

Free Newsletters

Sign up and receive the latest news, reviews and trends on your favorite technology topics

Save The Date!
What They Are Saying

So, the OpenOffice.org Community has announced the public beta release of OpenOffice.org 3.0, a new version...- Microsoft Subnet

Join the Discussion

Partner Content

Company Description

Emerson Network Power and its Liebert power and cooling technologies increase IT system flexibility and availability, while lowering the total cost of ownership.

Data Center Efficiency

Discover how to optimize your data center efficiency through virtualization, digital system controls and emerging monitoring capabilities.

Download this white paper

Maui Computing Center

Learn how Liebert technology ensures availability for U.S. DoD facility while providing the flexibility to add a new supercomputer.

Download this case study

Cutting Energy Costs

Reduce cooling system energy costs by 30 to 45 percent through five data center efficiency strategies.

Download this white paper

Payment Card Industry (PCI) update

PCI looking the wrong way, but rules will help everyone.
Small Business Tech By James E. Gaskin , Network World , 02/14/2008
James Gaskin
  • Social Web 
  • Email 
  • Feedback 
  • Close

Credit card losses to fraud adds up to about $3 Billion per year, depending on who you ask. So we can understand the concern on the part of financial service companies and the need for the Payment Card Industry Data Security Standard (PCI DSS, usually referred to as just PCI; official documents here).

But the huge credit card companies -- Visa, MasterCard, American Express, Discover, and JCB -- haven't done their job well and are forcing new rules on the wrong end of the transaction pipeline. That said, the rules are, for the most part, good security guidelines that businesses should be following anyway. Rarely do we see a bad idea lead to good results.

According to the book Geekonomics by David Rice, the PCI rules are a way for the financial giants to stave off government regulations. After losing more than a 100 million credit card records in 2006, one would think Congress would try to “help.”

The credit card industry swears it can self-regulate, and says it is in a better position than most to do so. After all, if your business is sloppy with credit card data, the card companies can cut you off and effectively put you out of business. They almost never, never do that, of course, because it's bad for business. But at least now they're forcing vendors making card transaction software to tighten up, says Computerworld.

PCI also forces any business taking credit cards, no matter how small, to become security experts. That t-shirt kiosk in the mall? Same security rules apply to it as to the Sears store down the way. Since t-shirt vendors rarely can judge the security of firewalls, operating systems, and transaction processing software, they're at the mercy of the security companies.

But many of the rules should be followed by every business. Scott Goessling of Blue Pay, a card processing service, created an understandable version of the PCI rules and gave me a copy. I don't see a copy on its Web site, but I bet if you send a note you'll get one via e-mail.

Jesper Jurcenoks, CTO of NetVigilance, a network vulnerability testing company, says 60% of businesses fail their PCI audit for one reason: they have no information security policy written down. So grab some paper and start from the basics, like “lock the door at night.” Then detail who can access data, define daily operational security procedures, and keep writing down policies.

1 | 2 |  Next >
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.
First Name
Last Name
E-mail
Zip Code