Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Security deadline missed by one-third of Visa merchants

By Ellen Messmer , Network World , 10/25/2007
  • Share/Email
  • Comment
  • Print

Just over a third of large-volume Visa merchants failed to meet a Sept. 30 deadline to comply with the Payment Card Industry's 12-part Data Security Standard, Visa said yesterday, and those companies are facing fines of $25,000 per month

Visa said 65% of the largest U.S. merchants (those processing six million or more Visa transactions annually, known as Level I) have validated compliance with the PCI DSS 1.1., up from 36% in December. The standard is set by the Wakefield, Mass.-based PCI Security Standards Council, whose membership includes the card associations Visa, MasterCard, and American Express.

Visa also said validation for the PCI security standard among midsize merchants (those processing one million to six million Visa transactions annually) has reached 43% as of Sept. 30, up from 15% in December. This Level II group is expected by Visa to validate compliance by Dec. 31. Level I and Level II merchants constitute two-thirds of Visa’s transaction volumes, the company said.

Smaller merchants also are being encouraged to become compliant with PCI DSS, and a number say their banks and the card associations are contacting them with deadlines to achieve compliance, which may include a self-assessment audit or one performed by a PCI-qualified security assessor.

Visa in May announced requirements for U.S. acquiring banks to identify security risks among their smaller merchant customers and develop an educational program to raise awareness about PCI DSS. Since then, 100% of the merchant banks active with Visa have submitted plans, the company said.

The PCI Security Standards Council is updating DSS for new requirements likely to pertain for next year, although debate about it is ongoing. Plans are expected to be finalized in the coming months.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed