About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Credit card payment
PCI Section 6.6 should not be treated as an approval system for e-commerce security
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

PCI payment standards come into play

But compliance not enough, warns security firm

Clement James, vnunet.com 30 Jun 2008
ADVERTISEMENT

Companies have been warned to be aware of Section 6.6 of the Payment Card Industry (PCI) standard that comes into force at the end of June.

The new section mandates the use of web application code reviews or the installation of an application level firewall for any business dealing with online transactions.

However, security experts also advise that the new requirements of the standard should not be treated as a 'rubber stamp' approval system for e-commerce security, and should be included in a company's overall IT security plans.

David Hobson, managing director at specialist security reseller and systems integrator Global Secure Systems (GSS), said that information security had to be approached holistically.

"Understanding what organisational assets require protection, what risks (i.e. the consequence of loss) relate to those assets and what the correct risk treatment decisions are is critical in defining a security strategy," he said.

"On top of this, if organisations are going to slavishly follow standards like PCI in 'tick-box' fashion, they may achieve compliance, but they are almost certainly not going to be fully secure against fraud."

GSS believes that that organisations need to identify what they are trying to achieve, and how they are trying to achieve it, before any further steps are taken.

"If organisations are unable to answer these two simple questions they run the risk of spending large amounts of money meeting the PCI s6.6 standards requirements for very little improvement in their actual IT security posture," said Hobson.

"No amount of point solutions (firewalls, database security tools, code reviews) are going to deliver 'security' unless your organisation understands its control objectives and gets its executives to buy into the process of meeting those objectives.

"Only then should the company consider what the relevant controls should be. "

See also:

Data securityDatabase security firm warns of gaping holes  23 Jun 2008
ShoppingQuick fixes not good enough, warn experts  19 May 2008
New rules on the storage of payment details  16 Apr 2008
Computer theftPCI compliance does not guarantee security  04 Apr 2008

All Ecommerce
Tags: Pci, Ecommerce, Government, Security, Software

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Aylesbury, Buckinghamshire, United Kingdom | Grass Roots
Business Analyst - £35,000 - £50,000 + benefits - Aylesbury    Grass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the ... more >
Reading, Berkshire, United Kingdom | EDS
Position # 396477 Environment Support Engineer Location - Reading Job Description: There is an initial requirement an Environment Support Engineer to provide support and maintenance for the development environments within ATLAS. This role encompases many ... more >
London, United Kingdom | City of London
ICT Project Officer - Guildhall, London EC2 18-month fixed-term contract Bring your project management expertise to one of the country's most prestigious institutions. The City of London is the local authority for the Square Mile, ... more >
Swindon, Wiltshire, United Kingdom | EDS
EDS are currently looking to recruit a Change, Risk and Issue Analyst to join our Project Management Defence team in Swindon, Wiltshire. Summary: The Regional Operations Cell Analyst will work as part of a small ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT