Restaurant chain must show PCI conformity by Sept. 30 or face fines
endif; ?>Steak n Shake sprints toward Sept. 30 deadline for PCI compliance.
It’s now a sprint to the finish line for PCI compliance, says Sean Smith, director of strategic technology services at the Indianapolis-based chain of 500 restaurants. The kickoff to reach the goal of compliance with the PCI Data Security Standard 1.1 (PCI DSS) started a year ago, he says. The company’s merchant bank, Fifth Third Bank out of Cincinnati, informed Steak n Shake it was among those having to show PCI compliance by this Sept. 30, or risk penalties and higher rates.
“There’s the potential for $25,000 to $50,000 per month in fines,” says Smith, along with possible higher card-processing fees for the bank.
The 12-point PCI DSS was completed a year ago by the PCI Security Standards Council, the Wakefield, Mass., organization formed by Visa, MasterCard and Discover to come up with uniform baseline requirements for card security.
The payment-card security standard is a set of requirements that corporations processing credit and debit cards are supposed to follow to protect sensitive data.
Merchant banks, working in tandem with the card associations, expect the first wave of largest merchants and service providers to prove PCI compliance by the end of this month or the year.
Merchants can turn to any of 70 or so “qualified security assessors” certified by the PCI Security Standards Council to conduct the PCI-compliance assessment. They can also exercise the option to conduct a self-assessment if they have sufficient audit staff, their bank agrees and their top management is willing to sign off on the final report.
Steak n Shake, because it has an audit team of seven people and an IT department of 35, is able to carry out a self-assessment. But that doesn’t mean it’s been easy.
“Identifying the gaps and proposing remediation took three months,” Smith says. To bring the 500 restaurants up to the standard of the corporate headquarters has meant months of deploying technological controls, including host intrusion-prevention and event logging to security information management, adding back-up for where credit-card data resides, and other tasks, such as antivirus and patch management extended out to the restaurants.
Now that most of the technical work is done, it’s mostly a matter of getting the paperwork done with a week remaining for the deadline. “I think we’ll make it,” Smith says.
Although Sept. 30 deadline is the first hard-and-fast deadline for demonstrated PCI compliance demanded by the card associations and the banks, it’s likely the review will become an annual event for merchants and service providers, especially as more PCI requirements are anticipated to be issued by the council by the end of the year.




