Feeds

Experts fret over credit card compliance

PCI DSS fails to settle SMEs

Security for virtualized datacentres

Efforts by the credit card industry to boost merchant security are likely to flounder unless tighter regulations are accompanied by punishments against transgressors.

The Payment Card Industry Data Security Standard (PCI DSS) methodology aims to improve the security of cardholder data among banks, service providers and the merchant community. The industry self-regulation standard is more prescriptive and detailed than earlier regulatory regimes (such as Sarbannes-Oxley) but still leaves plenty of room for interpretation. Although voluntary, at least in theory, those subject to a breach who aren't able to show they've followed best practice by signing up to PCI DSS risk having their ability to process cards taken away.

Merchants and service providers need to validate compliance against an audit by a qualified assessor.

But there are major holes in the process of becoming compliant, and even greater challenges in staying compliant as networks are evolving, according to panelists discussing the issue at the NetEvents technology summit in Malta on Thursday. Hundreds of qualified assessors attempting are audit hundreds of thousands of merchants creating a potential gap in the system.

Neal Hartsell, VP of product marketing at IPS supplier TippingPoint, said that although the high profile credit card security beach at TJX has stole the headlines problems at small merchants also present a severe risk. For example the link between a scanning device through to the software application on the PC in a small store is often unencrypted, even though the data is encrypted is placed in an encrypted tunnel after it leaves the computer. A keystroke logging planted on such machines therefore presents a severe security risk.

The problem is that small shops don't know PCI DSS exists and, if they do, they don't take the process seriously enough. "SMEs are not able to make these kinds of decisions, which ought to be the responsibility of vendors," Hartsell said.

Bob Walder, chief scientist at testing and certification firm NSS Labs, said small merchants using self-assessment will be tempted to just tick boxes saying they had set up a firewall or secured their network. Part of the problems is that assessors act more like consultants than health inspectors. Nothing will happen unless you take away merchant accreditation.

Many merchants wonder why they should invest in PCI DSS compliance when it does little to help them sell more products, Walder added.

Hartsell criticised SOX compliancy as a "wasted effort" from a security perspective because it failed to outline tactics for achieving strategic directions. PCI DSS is better because it outlines best practice, such as using a firewall and a secure wireless LAN, but doesn't go far enough. "DSS and it tells me what I have to do, but it doesn’t actually tell me how I’m going to do it", said Walder, who added a product accreditation scheme was needed. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
Admins! Never mind POODLE, there're NEW OpenSSL bugs to splat
Four new patches for open-source crypto libraries
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.