<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PCI: DSS Petition</title>
	<atom:link href="http://www.port7.co.uk/index.php/2007/06/26/pci-dss-petition/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.port7.co.uk/index.php/2007/06/26/pci-dss-petition/</link>
	<description>life and times of a geek home</description>
	<lastBuildDate>Tue, 16 Aug 2011 20:20:36 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: Tim Holman</title>
		<link>http://www.port7.co.uk/index.php/2007/06/26/pci-dss-petition/comment-page-1/#comment-26557</link>
		<dc:creator>Tim Holman</dc:creator>
		<pubDate>Mon, 21 Jul 2008 15:58:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.port7.co.uk/index.php/2007/06/26/pci-dss-petition/#comment-26557</guid>
		<description>The intent of the PCI Council is to provide an open global forum around card security with the overall aim of improving it.  They&#039;re not the ones who will be issuing fines or sending Visa a naughty list.
If it&#039;s monthly fines we&#039;re talking about, then it would be Visa who would be imposing these fines on acquiring banks.  The banks would then pass the fines onto non-compliant merchants.
In the US a slightly different strategy has evolved, in that acquiring banks are offering discount rates to PCI Compliant merchants.  However, if the merchant&#039;s particularly big then the merchant will just tell the acquiring bank they&#039;re going to switch, so again no real meat for PCI enforcement for large retailers.
It&#039;s always an interesting subject to talk about - wishy washy QSAs have always been buying time by blaming things on the PCI SSC, or waiting for clarifications on things they should already know about.  The PCI SSC don&#039;t really have the strength to enforce PCI DSS as they&#039;re not the ones who are supposed to.
As things stand, PCI Compliance is only ever relevant if you&#039;re compromised.  This is the one immutable risk that all businesses need to consider.  
Secondly, PCI Compliance MAY be relevant if fines are introduced.  Something still worth putting on the risk register on a 6-12 month timeline. 
Merchants that do nothing are highly susceptible to the former risk and it follows that it&#039;s completely sensible to start addressing major areas of security risk (which an ISO 27001 or PCI DSS gap analysis would identify).
Working on the basis that PCI Compliance is only relevant if compromised, it&#039;s important to take a risk based approach to PCI DSS and identify the systems, processes and policies that put a merchant at risk of compromise.  Each and every component of PCI DSS can be replaced by a compensating control.  If a particular control is too expensive (eg network segmentation), then perhaps stronger access control and security policies are the answer?  Point is, if you&#039;re hitting a financial hurdle then there&#039;s probably another answer (other than buying 3rd party products)...
We should have a chat sometime - I&#039;ll be up your way in a couple of weeks.  Not all QSAs are alike...  :)</description>
		<content:encoded><![CDATA[<p>The intent of the PCI Council is to provide an open global forum around card security with the overall aim of improving it.  They&#8217;re not the ones who will be issuing fines or sending Visa a naughty list.<br />
If it&#8217;s monthly fines we&#8217;re talking about, then it would be Visa who would be imposing these fines on acquiring banks.  The banks would then pass the fines onto non-compliant merchants.<br />
In the US a slightly different strategy has evolved, in that acquiring banks are offering discount rates to PCI Compliant merchants.  However, if the merchant&#8217;s particularly big then the merchant will just tell the acquiring bank they&#8217;re going to switch, so again no real meat for PCI enforcement for large retailers.<br />
It&#8217;s always an interesting subject to talk about &#8211; wishy washy QSAs have always been buying time by blaming things on the PCI SSC, or waiting for clarifications on things they should already know about.  The PCI SSC don&#8217;t really have the strength to enforce PCI DSS as they&#8217;re not the ones who are supposed to.<br />
As things stand, PCI Compliance is only ever relevant if you&#8217;re compromised.  This is the one immutable risk that all businesses need to consider.<br />
Secondly, PCI Compliance MAY be relevant if fines are introduced.  Something still worth putting on the risk register on a 6-12 month timeline.<br />
Merchants that do nothing are highly susceptible to the former risk and it follows that it&#8217;s completely sensible to start addressing major areas of security risk (which an ISO 27001 or PCI DSS gap analysis would identify).<br />
Working on the basis that PCI Compliance is only relevant if compromised, it&#8217;s important to take a risk based approach to PCI DSS and identify the systems, processes and policies that put a merchant at risk of compromise.  Each and every component of PCI DSS can be replaced by a compensating control.  If a particular control is too expensive (eg network segmentation), then perhaps stronger access control and security policies are the answer?  Point is, if you&#8217;re hitting a financial hurdle then there&#8217;s probably another answer (other than buying 3rd party products)&#8230;<br />
We should have a chat sometime &#8211; I&#8217;ll be up your way in a couple of weeks.  Not all QSAs are alike&#8230;  <img src='http://www.port7.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.port7.co.uk/index.php/2007/06/26/pci-dss-petition/comment-page-1/#comment-26551</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Wed, 16 Jul 2008 19:48:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.port7.co.uk/index.php/2007/06/26/pci-dss-petition/#comment-26551</guid>
		<description>Yes but I think they are going to continue to do so until we get a stronger message from the PCI Council here in the UK. At the moment it&#039;s difficult for companies to justify the budget needed for becoming PCI compliant.

They are going to ask what happens if we don&#039;t go through this and spend the money? A £5k fine per month? No thanks we will just pay the fine!</description>
		<content:encoded><![CDATA[<p>Yes but I think they are going to continue to do so until we get a stronger message from the PCI Council here in the UK. At the moment it&#8217;s difficult for companies to justify the budget needed for becoming PCI compliant.</p>
<p>They are going to ask what happens if we don&#8217;t go through this and spend the money? A £5k fine per month? No thanks we will just pay the fine!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Holman</title>
		<link>http://www.port7.co.uk/index.php/2007/06/26/pci-dss-petition/comment-page-1/#comment-26550</link>
		<dc:creator>Tim Holman</dc:creator>
		<pubDate>Wed, 16 Jul 2008 17:28:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.port7.co.uk/index.php/2007/06/26/pci-dss-petition/#comment-26550</guid>
		<description>Is your QSA still being wishy washy? :)</description>
		<content:encoded><![CDATA[<p>Is your QSA still being wishy washy? <img src='http://www.port7.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: port7 &#187; Blog Archive &#187; Sign my PCI: DSS Petition!</title>
		<link>http://www.port7.co.uk/index.php/2007/06/26/pci-dss-petition/comment-page-1/#comment-6869</link>
		<dc:creator>port7 &#187; Blog Archive &#187; Sign my PCI: DSS Petition!</dc:creator>
		<pubDate>Wed, 04 Jul 2007 09:39:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.port7.co.uk/index.php/2007/06/26/pci-dss-petition/#comment-6869</guid>
		<description>[...] metioned in a previous post I created a petition to the Prime Minister to make the PCI: DSS standards a legal requirement. This [...]</description>
		<content:encoded><![CDATA[<p>[...] metioned in a previous post I created a petition to the Prime Minister to make the PCI: DSS standards a legal requirement. This [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

