Industry analysis by expert Joanie Wexler, plus links to the day's wireless news headlines
Retailers apparently are mixed in how seriously they take the Payment Card Industry Data Security Standard, which contains some provisions for securing wireless data along with other mandates. While some retailers are conscientious, others have yet to be fazed by fines, increases in credit card company exchange rates and even immense out-of-court settlements following a breach.
So observes Steve Rowen, a partner at RSR Research in Boston, which focuses on the retail industry and tracks PCI compliance. Many retail organizations face a rip-and- replace undertaking to meet the wireless components of PCI DSS mandates, he notes. For example, retail locations with point-of-sale wireless applications require wireless data encryption using Wireless Protected Access (WPA) or higher, which can often mean replacing thousands of legacy handsets. PCI DSS, driven by credit card companies, also requires the use of wireless firewalls and wireless analyzers for rogue monitoring.
"But retailers would rather spend money on things that will help them make more money, not just protect the business," Rowen explains.
Who wouldn’t? Notoriously thin-margin retailers, though – particularly highly distributed ones – are among the verticals usually short on the manpower and budget dollars to tackle an infrastructure overhaul. It’s not uncommon, Rowen says, for retailers to adopt a “pay-the-ticket-and-go” attitude toward PCI. In other words, many opt to endure expensive wrist-slapping measures rather than investing time and money in an enterprise upgrade.
Current industry climes make it “easier for retailers to self regulate,” Rowen explains, because the PCI effort is driven by credit card companies – most notably, Visa – who say, “comply or we will do this to you.” The idea that financial institutions should tell retailers what to do with IT “seems silly,” he says. Meanwhile, in the absence of federal governance, states have slowly begun adopting legislation.
He described state regulation of retail compliance, though, as “the worst of all possible worlds,” because nationwide, distributed retailers that also conduct online commerce would have to implement multiple sets of rules in their infrastructures depending on geography. (Compare Network Auditing and Compliance products)
Still, Rowen is heartened by a number of recent industry efforts to help retailers out with not only being technically PCI compliant, in a “checkbox” fashion, but in truly securing customer data and protecting internal resources from wireless-initiated break-ins, which requires steps beyond the PCI basics.
Among the recent industry moves:
* Yesterday’s launch by AirTight Networks of a $2/day wireless LAN security software-as-a service (SaaS) offers full wireless vulnerability management without CPE investments.
* Mobile VPN provider Columbitech rolled out a premises-based centralized compliance management system in late March.
* Aruba Wireless offers centralized monitoring for unauthorized devices with no requirement for in-store hardware or software investments. Meanwhile, Aruba’s recent acquisition of Airwave, completed late last month, adds centralized signature-based intrusion prevention at each site with the installation of at least one Aruba sensor per approximately 20,000 square feet of space.
Joanie Wexler is an independent networking technology writer/editor in Silicon Valley.