Firms failing to meet PCI security requirements

20 Sep 2007

Comment: 1

A Computing logo
Padlock and chain

More than half of enterprises are not meeting the data security standards established by the Payment Card Industry, according to a new report published by VeriSign. The main reason for the lack of compliance is because firms are not carrying out regular analysis of data that is being retained, the security specialist said.

Simon Church, head of VeriSign for Europe, the Middle East and Africa, advised firms to indoctrinate better procedures for managing data across their environments. He explained that many organisations retain information they do not need, and instead they should be more thorough in analysing their data and deciding which of it is necessary to keep.

Further reading

Church added that as the data security industry is changing so rapidly, if organisations establish certain processes just to pass the PCI audit, that might not be adequate to meet future standards requirements. Instead, firms need to assimilate good practice for data management and security in their DNA, he advised.

Companies failing to comply with PCI standards could face financial penalties or losing the ability to process credit card transactions. Church said that data security aspects need to be considered by the whole business rather than just the IT department, because ultimately bad publicity from compliance failures will cause serious consequences for the business.

Reader comments

Some PCI requirements more difficult than others

It does make sense that good practice for data security should be embedded into the firms' DNA, but it seems as though some of the requirements are more difficult to satisfy and verify than others. I've seen other recent research that shows the requirements around "file integrity monitoring" are among the last to be satisfied and represent the largest precentage of those not being fulfilled. While there doesn't seem to be one solution to solve all of the PCI requirements, luckily there is technology available to help satisfy and sustain the difficult requirements of PCI compliance for file integrity monitoring and ensuring critcal file data is not compromised. Specifically, I've been successful using Solidcore change control software.

Posted by: IT Director  21 Sep 2007

Have your say on this article

All fields required. Your email address will not be displayed on the site.

By submitting a comment you agree to abide by our Terms & Conditions

  • Digg
  • Tweet

Newsletters

Sign up for our FREE newsletters

Technology Patent Wars

Large companies such as Microsoft, Facebook and Google have been hoovering up technology patents recently. Is this stifling innovation?

87 %

5 %

8 %