ANTenna Blog -- Security
Credit Card Compliance Still Poorly Practiced
Posted by Keith Ferrell Wednesday, Sep 23, 2009, 10:46 AM ET
A new survey from Imperva and the Ponemon Institute finds that despite the rising number of data breaches, many companies still do not fully adhere to compliance standards. And many of those that are protecting credit card information are neglecting security when it comes to other, equally sensitive data. Smaller businesses may be having the most trouble with the standards.
The Payment Card Industry (PCI) Data Security Standard (DSS) spells out the security steps companies must take to protect confidential customer and financial information.
According to the Ponemon Institute/Imperva survey of 500 businesses, many of them haven't taken all the necessary steps.
This isnt new -- incomplete or partial PCI DSS compliance has long been a concern, both for the risk it creates,obviously, but also for what failures to meet the compliance standards says about business.
In the case of the Ponemon/Imperva survey, what it says is that:
79% of respondents have experienced a data breach involving credit card data, yet 71% still don't incorporate PCI DSS compliance into their overall strategic security initiatives.
55% protect credit card data -- but don't apply DSS-level compliance to protecting Social Security and other equally sensitive identity and financial data.
Scary stuff, but pretty clearly explained, at least by the survey's respondents:
60% of respondents blamed lack of PCI DSS compliance on lack of resources -- this stuff is scary, but this stuff is also costly, with fully compliant companies typically devoting 35% of their IT security budgets to compliance.
It's even worse on the small and midsized business front. According to the survey:
Only 28% of smaller business are fully PCI DSS compliant.
That sound about right to you? Where does your company's PCI DSS compliance practices -- and, for that matter, budget or level of security resource dedication -- fall on the scale.
More to the point, have you -- or a credit card processing vendor -- experienced a data breach after which you or the vendor remains non-compliant?
Recognizing that the burden -- it's a responsibility, sure, but it's also a burden -- of PCI DSS compliance is heavy on all companies, but disproportionately so on smaller businesses, Ponenon and Imperva make a couple of provocative recommendations:
A PCI DSS compliant logo to be posted on Web sites would, they argue, help offset the cost of compliance by making compliance a competitive advantage. This, of course, begs the questions of a) How long it would take to educate the public about the logo and its meaning, and b) whether the public would actually respond to such a log and restrict its shopping and purchasing habits to logo-emblazoned businesses.
(Won't even talk here about the prospect of phony logos emerging from the cybercrook sphere.)
More practically, I believe, they recommend that the PCI-DSS governing body modify the standards for smaller businesses in recognition of the larger challenges those businesses face in hitting the compliance standard.
Whether or not either recommendation is acted upon -- and how long it takes -- will be interesting to watch.
Security
Business & E-Business
| Company Size: 1-49
| Finance/Banking/Insurance
| Hospitality
| IT Management
| Retail
This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.
Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.
Important Note: This comment area is NOT intended for commercial messages or solicitations of business.
- Phone Systems Guide - What kind of phone system is right for your business
- Web Design Guide - What to look for in a Web designer
- Merchant Services Guide - Credit card processing and more
- Online Marketing Guide - Leverage the Net to market your business
- Alternative Financing Guide - How to find the cash your business needs
- View all guides
Explore ANTenna Blog
Most Recent Posts
- Twilight's Latest Hacking: Vampire Byte Scam Targets Stephanie Meyer Fans
- Quark Promote Enters Web-To-Print Market
- Yes, Virginia -- There IS A Google Phone
- Could Linux Fall Prey To Windows Malware?
- New Mini NAS Enclosure Targets Small-Biz Users
ANTenna Blog Topics
- Apple
- Backup
- bMighty
- Business & E-Business
- Business Continuity
- Cloud Computing
- Company Size: 1,100-1,500
- Company Size: 250-999
- Company Size: 50-249
- Company Size: 1-49
- Disaster Recovery
- Economics
- Education
- Entrepreneurs
- Finance/Accounting
- Finance/Banking/Insurance
- Government
- Green Business
- Hardware & Software
- Healthcare
- Hospitality
- How-To
- HR
- Imaging How-To
- International
- Internet/Web
- iPhone
- IT
- Linux
- Management
- Manufacturing/Mining
- Messaging
- Mobile
- Networking & Communications
- Non-Profit
- Open Source
- Operations
- Piracy
- Printers/Printing
- Professional/Creative Services
- Retail
- Unified Communications
- Sales/Marketing
- Start-Ups
- Security
- Server How-To
- Services
- Social Networking
- Software-as-a-Service
- Storage
- Strategy/Analysis/Biz Dev
- Technology/Telecom
- The rANT
- Transportation
- Travel
- Windows
- Web 2.0
- Women in Business
ANTenna Bloggers
ANTenna Blog Roll
- ANTenna Archive
- Ars Technica
- Business Know-How
- ChannelWeb Hot Topics
- ChannelWeb The Chart
- Datamation
- Duct Tape Marketing
- The Entrepreneurial Mind
- Freakonomics
- GigaOmNet
- Guy Kawasaki
- Inc.com
- IT Organization Management
- IT Manager's Journal
- IT Toolbox
- LifeHacker
- Mashable
- MonkeyBrains
- Network Computing Blog
- Scott Berkun
- Search Engine Land
- Search Engine Watch
- SmallBizResource
- SmallBizTechnology.com
- SmallBusinessHub
- Small Business Trends
- TechCrunch
- Technologizer
- Tech Republic
- The Secret Diary of Steve Jobs
- USA Today Small Biz Connection
- Valleywag
- Walt Mossberg Feed - All Things Digital
- Web Worker Daily
- WorkHappy.net
- WSJ's Business Technology
bMighty email newsletter!
Browse by Category
bMighty Tech
Term Of Day:
Boost your tech
vocabulary!
bMighty's SMB
TechEncyclopedia
defines more than
20,000 IT terms.
FREE Technology Services Locator!
Search our database of 200,000 solution- provider locations by business activity, technology, vertical market, and customer size. Find a technology partner NOW.
go



