Network World
Tuesday, December 2, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Navigation

RE: PCI compliance mandate's power raises conflict-of-interest questions

The potential for conflict of interest with the same person selling security equipment who is conducting the audit is poor. The only way around this is independent certification of security products to determine whether they are compliant as per PCI standards. The ONLY company which is doing this right now to my knowledge is NSS Labs (out of Chicago). NSS has a long history of security testing and certification and, more importantly, appears to be the ONLY independent security testing and certification facility which is truly independent (i.e. is not owned by or affiliated with a company with a vested interest in selling security products or managed services). One of the vendors we use is already going through the NSS PCI certification process and it look pretty good - will certainly be of use to us in the future when it comes to selecting security products to maintain our PCI compliance.

Click to read the article this is in response to.

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: