Articles
PCI DSS: What Do You Know, Where Do You Stand?
July 29, 2009
Article: PCI DSS: What Do You Know, Where Do You Stand?
By Matt Pillar, Integrated Solutions For Retailers magazine
For a couple of months spanning the first and second quarters of this year, Integrated Solutions For Retailers surveyed its subscribers — hundreds of retailers from many segments, ranging the gamut from small and regional chains to tier-one enterprises — on their perceptions of the PCI DSS (Payment Card Industry Data Security Standard). The survey results surprised us. Respondents exuded nearly equal parts confidence, confusion, dismay, and ignorance. Some gloated. Some swore.
We quickly realized that many retailers were upset about the standard. Leading the list of reasons why were: 1.) Nobody likes mandates, and 2.) many misunderstand this one. Then we talked to some payment processing solutions providers about sponsorship of the report. Some of them were mad, too. While none denied the power of the standard as a rallying point to market payment solutions, several were dismayed that the keeper of the mandate, the PCI SSC (Payment Card Industry Security Standards Council), would not overtly recognize their specific solutions or technologies as compliance-enablers. So, while the survey was still live, we called Troy Leach, technical director at the PCI SSC, and shared some of our more colorful findings with him. We were glad the comments were well- received by Leach — expected, in fact — and we were amused to hear Leach take us through the "Five Phases Of Grief" experienced by the retailer when faced with a PCI mandate. We'll get back to that later. First, let's take a look at the numbers and dive into the standard itself.
Click Here To Download:Article: PCI DSS: What Do You Know, Where Do You Stand?
Used with permission from Integrated Solutions For Retailers magazine.
