Most Popular Stories
- Lawsuits starting to mount against Goldman Sachs
- What to make of Goldman Sachs' move into derivatives clearing?
- Citigroup explores Volcker Rule options
- SEC seeks comments on fiduciary standard vs. suitability
- Goldman Sachs' hedges on AIG exposure debated
- Tabb Group: Buy-side continues to embrace algorithms
Events
Sponsored Links
Latest News
Free Newsletter
FierceComplianceIT is a leading source of news and information on compliance IT in financial services. Join 14,000+ CCOs, CFOs, and CIOs who get FierceComplianceIT via weekly email. Sign up today!
About | View Sample | Privacy
Popular Topics
Press Releases
We never sell or give away your contact information. Our reader's trust comes first.
Time to go beyond PCI?
![]()
The PCI DSS standard was released back in December 2004 and was quickly hailed as one of the most important private-industry data security standards ever developed. Over the past few years, however, amid a steady stream of news about breaches and thefts, the PCI DSS standards has been roundly criticized.
At a congressional hearing this month, one congresswoman said, "I do want to dispel the myth once and for all that PCI compliance is enough to keep a company secure." Many would agree. A case in point noted by Network World: The breach at Hannaford Brothers, where hackers installed malware on the grocery store chain's internal servers to seize card numbers as they were swiped by customers. Hannaford was certified a PCI DSS-compliant company as the scam was in progress. Heartland Payment Systems, before its scam broke in the news, was also certified compliant by Visa.
Visa defends the standard as a way to minimize theft if properly implemented, and you certainly can't blame PCI DSS entirely for recent thefts. For all we know, there would have been many more if not for the standard. Still, the general view is that the PCI DSS standard has become overly complex and has done little thus far to stop fraud, as fraud artists get sophisticated technologically.
While some think the future of the standard is up in the air, others are encouraged that there's a movement afoot to extend the standard in key areas.
ComputerWorld reports that amid all complaints, Visa, long the prime force behind the standard, "is working one-on-one with banks and retailers to test new security measures that go beyond the controls currently mandated by PCI." An important pilot program is underway. At Fifth Third for example, a test is underway that uses magnetic-stripe technology to create unique digital fingerprints for credit and debit cards. New card readers use magnetic stripe data to create a "DNA picture," which is matched against baseline information during authorization.
Another test at OfficeMax involves better authorization. The retailer asks for information on ZIP codes, phone numbers or area codes and matches the answer against previous answers.
These are potentially important developments but you have to ask if they'll do much to thwart the malware purveyors. In order to do that, individual companies will have to be vigilant about securing their networks. - Jim
Comments
Post new comment
Home
| Subscribe | Advertise | Mobile Edition | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2010 FierceMarkets. All rights reserved. |
![]() |



