I Wonder If My Card Issuer Has A ROC?
Written by Walter ConwayAugust 11th, 2010
The PCI Council's Frequently Asked Questions (FAQ) #5391 states that "PCI-DSS applies to any entity that stores, processes or transmits cardholder data and any such entity is expected to comply with PCI-DSS, including issuers." Because that is the case, PCI Columnist Walt Conway wonders if his card issuer has validated its compliance with a Report on Compliance (ROC) prepared by a QSA. In addition to being retailers or service providers, everyone reading this column is a cardholder, so we all have a stake in this issue.
Conway wants to make it clear, though, that he does not believe card issuers should be ordered to validate PCI compliance. Rather, he believes issuers should voluntarily validate their compliance. And they should do it for three reasons: It is smart; it probably won't be that difficult; and, most importantly, it is the right thing to do.
This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.
Already a Subscriber? Login Here
Pages: 1 2
One Comment | Read I Wonder If My Card Issuer Has A ROC?
Leave a Reply
Readers, specifically those who want to comment on a story:
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.

-Ed

August 12th, 2010 at 10:43 am
Cardholder numbers belong to the issuer, not the cardholder. The issuer makes a diecison to grants revolving credit tot he cardholder and issues an account number and a card. Both the account numebr and the card remain issuer’s pro[perty and must be surrendered or destroyed by the cardholder upon issuer’s demand.