In The Security Vs. Compliance Battle Of The Mind, Security Is Winning
Written by Walter ConwayJanuary 18th, 2012
If ever there was an argument where security trumped compliance, the debate about tokenization versus encryption is it. Readers have made that point abundantly clear following a recent column describing the PCI scope reduction benefits of tokenization versus encryption.
The shift in emphasis from compliance to being secure is not new, but PCI Columnist Walter Conway was struck by how pronounced a perspective change retailers are experiencing.
This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.
Already a Subscriber? Login Here
Pages: 1 2
One Comment | Read In The Security Vs. Compliance Battle Of The Mind, Security Is Winning
Leave a Reply
Readers, specifically those who want to comment on a story:
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.

-Christine

February 1st, 2012 at 9:24 pm
Nice update post Walt, and thanks for the kind words :) I agree with pretty much all of what you have to say, and I think the implementation point is exactly why PCI is currently beavering away on the Point to Point Encryption (P2PE) program.
One of the major goals of this program is to place the burden of implementation back to the hands of the vendor(s), so that the merchant can rest assured that as long as they use the system provided for payments, everything else is taken care of.
I think that this has the potential to provide a terrific win for the merchants in scope for these sorts of systems, and also to the security posture of payments as a whole – exactly because it should ensure that people who know what they are doing are the only ones involved in the details.