Credit card payment
PCI Section 6.6 should not be treated as an approval system for e-commerce security

PCI payment standards come into play

But compliance not enough, warns security firm

Written by Clement James, vnunet.com

Companies have been warned to be aware of Section 6.6 of the Payment Card Industry (PCI) standard that comes into force at the end of June.

The new section mandates the use of web application code reviews or the installation of an application level firewall for any business dealing with online transactions.

However, security experts also advise that the new requirements of the standard should not be treated as a 'rubber stamp' approval system for e-commerce security, and should be included in a company's overall IT security plans.

David Hobson, managing director at specialist security reseller and systems integrator Global Secure Systems (GSS), said that information security had to be approached holistically.

"Understanding what organisational assets require protection, what risks (i.e. the consequence of loss) relate to those assets and what the correct risk treatment decisions are is critical in defining a security strategy," he said.

"On top of this, if organisations are going to slavishly follow standards like PCI in 'tick-box' fashion, they may achieve compliance, but they are almost certainly not going to be fully secure against fraud."

GSS believes that that organisations need to identify what they are trying to achieve, and how they are trying to achieve it, before any further steps are taken.

"If organisations are unable to answer these two simple questions they run the risk of spending large amounts of money meeting the PCI s6.6 standards requirements for very little improvement in their actual IT security posture," said Hobson.

"No amount of point solutions (firewalls, database security tools, code reviews) are going to deliver 'security' unless your organisation understands its control objectives and gets its executives to buy into the process of meeting those objectives.

"Only then should the company consider what the relevant controls should be. "

Reader comments

More from Computeractive

News

The latest home computing news

Downloads

The best PC tools, applications and more

Reviews

Independent opinions on new hardware and software

Step-by-step guides

Easy-to-follow projects with pictures

PC Help

Solve PC problems with our Q&A

Videos

PC projects demonstrated and product reviews

Articles

An in-depth look at how to get the best from your PC

Magazine

What's coming up in Computeractive

Forums

Get help with your PC problems from our readers

Competitions

Your chance to win computing prizes

Shopping

Great deals on products, services and more

Computeractive CD Rom 10
All 26 issues of Computeractive from 2007 on one CD-Rom.

Ultimate Guide to PC Troubleshooting
Everything you need to know to solve your PC problems.

Driving Test Success
The UK's best-selling driving test software.

Computeractive Back Issues
Missed an issue? Click here to find a back issue

Advertisement

Blogs

Windows Watch

Windows Watch

Keeping an eye on the latest XP and Vista news

More storage added to Windows Live Skydrive

19 Nov 2008The storage limit for Windows Live Skydrive is to be increased to a very respectable 25GB . As of just now my...

Download Junkie

Download Junkie

Your daily dose of download discussion

Tweak all areas of your display hardware

21 Nov 2008Most current graphics cards will come with a number of different display options. These settings are often pre-configured on any card installed...

Advertisement

Free email newsletters

Techno babble demystified...

[Display all definitions]

Or type in any computer-related word and click "Go"

Advertisement

Computeractive is not reponsible for content of Google adverts

Primary Navigation

© Incisive Media Ltd. 2008. Incisive Media Limited, Haymarket House,
28-29 Haymarket, London SW1Y 4RX, is a company registered in the United Kingdom with company registration number 04038503

Search computeractive.co.uk