Friday, 25 May 2007

PCI SSC Announces board advisors

Some big names elected onto the PCI SSC council (14 in all).

Their primary role being to serve on the board and provide strategic and technical guidance to the PCI Security Standards Council.

Microsoft and Verifone being the only technology companies the rest are retailers or PSPs with a vested interest in PCI.

I wonder if the PCI SSC will behave like a mini UN with lots of differing groups with their own agenda, generating ideas and statements about what should be done but too much in-fighting and Special Interests to actually get a majority vote to get motions passed through.

With a member like APACS involved (UK Payments association) their should be no excuses in the future from UK organizations to not being PCI compliant, as there were around 18 months ago when PCI DSS conflicted with what APACS required from retailers/PSPs.

It will be interesting to see any minutes from the initial meetings for any future PCI DSS changes, just to see who is in favor of PCI and who isn't.

Thursday, 24 May 2007

APAC market gains PCI momentum

A PCI Blog reports on the increase in interest levels within APAC region.

PCI Answers is a great source of PCI news and contributors very active in PCI space.

PCI pays off

Another Dark Reading article featuring a Bryan Sartin of Cybertrust, discussing how PCI can pay off in the short to long term. He states that "..No organization that has been completely compliant with PCI has been compromised."

Wednesday, 23 May 2007

PCI Costs, but not as much as a breach

Interesting article on Dark Reading. While it is generally accepted that breaches aren't great financially, staying ahead of PCI compliance could be beneficial in the long term, both financially and with respect to security of your organization.

Sunday, 20 May 2007

Too little too late perhaps??

While this is not necessarily a news item, only a press release for 7Safe's PCI DSS training service, it does highlight the last minute nature of PCI Compliance most companies have taken as their approach to tackling this requirement.

If true, PCI vendors should expect some increased levels of interest as 30th June 2007 approaches.

Tuesday, 15 May 2007

PCI: This is how we do things in Texas

Texas is mulling over a bill that would make PCI DSS a state law.
It is viewed that the bill would spur broader adoption of PCI security controls and is supported by a number of Texas Credit Unions, who want to push liability onto the merchants.
Texas isn't the first to push this kind of bill through, Massachusetts also proposed something back in Feb 2007

Monday, 14 May 2007

Security Breaches are good for you....

Interesting blog post about how breaches or bad news actually increases the company's profits.

Will this mean that companies will be queuing up to disclose their security breaches or health scares (in cases of your local eatery)!?

Is this reverse psychology gone mad?