Nothing New In “New” PCI Wireless Guidelines
Written by Fred J. AunJuly 22nd, 2009
Retailers fearful of having cardholder data swiped from their wireless networks won't, unfortunately, find any new and magical cures within the new guideline published by the PCI Security Standards Council (PCI SSC) July 16. Indeed, the document's authors concede they didn't come up with any requirements that weren't already included in the existing PCI standards. Then again, given an understanding between PCI and retailers, they really weren't allowed to come up with anything new.
But if there's any area where retailers would want more security standardization rules—or at least much more specific and realistic rules—it's clearly wireless security. To be fair, that's a very tall order and the nature of both wireless security and the PCI Council virtually make it impossible.
This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.
Already a Subscriber? Login Here
Pages: 1 2
3 Comments | Read Nothing New In “New” PCI Wireless Guidelines
Leave a Reply
Readers, specifically those who want to comment on a story:
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.

-Christine

July 23rd, 2009 at 10:44 am
I agree with Fred that wireless security is a hard problem. Additionally, retail environments are not the best to implement wireless security practices.
However, I disagree that there is nothing new in the PCI wireless guidelines. In fact, this the first time, wireless security guidelines have been described so unambiguously. This clarity was desperately need to help retail organizations really do something about the wireless security problem.
Additionally, the ad-hoc walkaround wireless audits of sites via random sampling was simply an eyewash and not aimed at true security. Use of a wireless IPS is the only effective way achieve both security and compliance with wireless guidelines.
July 29th, 2009 at 6:44 pm
The real question then is if PCI’s guidelines on wireless security are nothing new, why did they bother to produce them? It’s not as if reasonable guidelines aren;t already available.
Or is this just an attempt at security theater – appear to be doing something even if it is meaningless…
July 31st, 2009 at 9:08 am
As I mentioned in my earlier comment, the PCI wireless guidelines are fairly precise in what they recommend. They identify the types of cardholder data environments (CDEs) and precisely define how wireless security requirements apply to them. Therefore, I do not believe that they are meaningless. I see them as an attempt to clarify the PCI DSS in an area that was previously ambiguous.