30 Sep 2010
Security experts have used today's Payment Card Industry Data Security Standards (PCI DSS) compliance deadline to warn against complacency in the industry.
PCI DSS is an industry standard designed to protect consumer credit card data, but participating payment card brands set the deadlines for compliance.
All UK Level 1 merchants that process over six million transactions a year and accept Visa payments need to comply with the current v1.2 PCI guidelines by 30 September.
However, Alan Bentley, international senior vice president at endpoint security firm Lumension, suggested that the standard had left even the largest merchants confused.
"PCI compliance might have been around for some time, but merchants are still struggling to get their heads around the requirements," he said.
"Version 2.0 is just around the corner, meaning that merchants need to be concerned about their ability to prove compliance with v1.2, and with the steps they must take to get to the next stage of compliance."
The PCI Council, which oversees the development and management of the standard, is already working on v2.0 as part of the standards update lifecycle process which spans 36 months.
This process covers publication, feedback and implementation, and the retirement of the older version of the standard by the end of year two.
MasterCard, Visa and other participating payment card brands have rolling deadlines for PCI DSS compliance according to merchant size, which were set up with the standard's introduction three years ago.
Fines for data breaches arising from non-compliance can go up to $100,000 (£63,450) per month, and may result in having the ability to process credit card transactions frozen by the acquiring bank.
However, just nine per cent of UK Level 1 merchants have achieved v.1.2 PCI DSS compliance, according to figures issued by Visa earlier this year.
"All too often, organisations fall into the compliance trap and focus all their efforts on meeting the requirements of a new deadline without thinking about the bigger picture," said Bentley.
"This broken compliance strategy is costly and ineffective when it comes to security. Taking a myopic view of regulatory compliance creates a situation where merchants are constantly reinventing the wheel, wasting time and effort, and ultimately blowing security budgets."
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
APPLICANTS MUST BE A EU CITIZEN OR HAVE PERMANENT RESIDENCY...
C# Software Developer/Programmer/engineer; C#, Winforms...
Linux Administrator / Senior Linux Administrator / Debian...
C#, WPF, Silverlight, UI Development, Software Engineers...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Online retailers can't ignore PCI DSS
PCI DSS is something all online retailers simply cannot ignore ? if you?re in business online you need to be able to prove your systems are compliant if you are to avoid a weighty fine. The requirements, though, are steep - the documentation runs to over 70 pages - so many smaller businesses just don?t have the space to do it for themselves. Outsourcing the entire payments process to specialist payment service providers can sidestep the issue. As these companies have already adopted PCI DSS, their customers comply by default. It means they are safeguarded from future changes to the rules, and can also benefit from additional capabilities, such as online fraud detection.
Posted by: Michael Norton, MD PayPoint.net 01 Oct 2010