18 December 2008

Risk and the Payment Card Industry Data Security Standard

Chris Hayes has posted an important reminder of the difference between the risk of non-compliance with the Payment Card Industry (PCI) Data Security Standard (DSS) and the risk of the defects themselves.

Read his Risk and PCI-DSS posting on Risktical Ramblings.

Cotton Traders survived a payment card data breach earlier this year and has gone on to implement tighter controls. It was not clear at the time of the breach whether they were PCI DSS compliant or not.

Partial screen capture of the Privacy and Security page on the Cotton Traders web site which mentions their PCI DSS compliance - taken from http://www.cottontraders.co.uk/ct/info_SecurityStatement.asp

Chris mentions non-compliance with PCI DSS. Not many merchants should seriously consider remaining out of compliance—micro, small and medium sized enterprises in particular may not survive the consequences of a security breach followed by the effects of being found to be non-compliant.

He also refers to the Common Vulnerability Scoring System (CVSS) in his posting. It is quite a complex standardised method for rating information technology (IT) vulnerabilities and you can read his thoughts on CVSS starting at Risk and CVSS (Post 1) which highlights the dangers of applying methodologies and metrics without a full understanding of them and what aspects are being included/excluded.

Posted on: 18 December 2008 at 12:59 hrs

Comments Comments (2) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Thanks for referencing the post and the blog itself!
1 Added by Chris Hayes Posted on 18 December 2008 at 14:14 hrs
I'm keen to distribute good information as widely as possible.
2 Added by Clerkendweller Posted on 19 December 2008 at 12:40 hrs
Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Risk and the Payment Card Industry Data Security Standard
http://www.clerkendweller.com/2008/12/18/Risk-and-the-Payment-Card-Industry-Data-Security-Standard
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2008/12/18/Risk-and-the-Payment-Card-Industry-Data-Security-Standard
Requested by 38.107.191.106 on Wednesday, 8 September 2010 at 00:51 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2008-2010 clerkendweller.com