Why PCI DSS Compliance Is Not Like The Flu
February 20th, 2013PCI DSS compliance is not like the flu. You can’t “catch” it from your service provider, even though that provider might be PCI compliant. Merchants must go beyond reading the marketing materials and taking a quick glance at the service provider’s attestation of compliance (AOC). The path to PCI compliance starts with PCI-compliant service providers, but it then takes the extra step of performing effective due diligence.
This lesson has been reinforced at least three times in the past few weeks in separate PCI Security Standards Council (PCI SSC) guidance documents. One question is whether merchants—particularly small and midsize merchants—will ever hear this advice. As a QSA, PCI Columnist Walter Conway occasionally gets the impression that clients might not spend more time researching their next smartphone, laptop or sailboat than they do reviewing service provider contracts and service-level agreements (SLA). It is particularly important for merchants to realize the source of the advice. It comes not from the PCI SSC staff but from active PCI practitioners with first-hand experience.
Read more...
Starbucks isn't going to replace their existing enterprise POS system with apps that have 1 percent of the functionality, control and reporting that they need to run their business. Likewise, I'm not going to replace my BMW with a free skateboard, just because both technically enable me to get from A to B.
-Gavin Phillips
