PCI Service Provider Dilemma: A Chain Can Control The Manager But Not The Managed
Written by Evan SchumanMay 20th, 2010
When a retailer outsources any function to a third party, it can protect itself through legal contracts (the threat to sue) and through early termination or simply not renewing the service (the threat to stop giving the third party money). But in the PCI payment-card-data-protection world, responsibilities and punishment for non-performance become a lot murkier.
In this week's PCI column, Walter Conway makes an eloquent argument that chains must take special care to protect their data when changing processors. But Walt only briefly touches on the responsibility issues involving those processors. In PCI Requirement 12.8, the PCI powers-that-be mandate that the retailer properly manage the service provider, but they don't say what happens if the service provider does something wrong anyway.
This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.
Already a Subscriber? Login Here
One Comment | Read PCI Service Provider Dilemma: A Chain Can Control The Manager But Not The Managed
Leave a Reply
Readers, specifically those who want to comment on a story:
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.

-Christine

May 24th, 2010 at 10:15 pm
While it would be nice to see that the customer is not impacted, I don’t see that happening, no matter how this all falls out.
Higher prices, higher fees. Somehow the consumer will pay for it.