Squeezing More Value From Your PCI Assessment
Written by Walter ConwayMarch 25th, 2010
How do you use your PCI risk assessment? Requirement 12.1 tells you to have "an annual process that identifies threats, and vulnerabilities, and results in a formal risk assessment." The questions for retailers and their CIOs are: "What do you do with that risk assessment once you are done? Do you use it to question your current practices and reduce your PCI scope?"
PCI Columnist Walter Conway opines that he hates to do a bunch of work and get nothing for it. "That's too much like paying for dinner and then not sticking around to finish dessert. Often, merchants prepare a thoughtful risk assessment and then file it away (a.k.a., 'shelfware') until their QSA returns the next year, at which time it gets dusted off, reviewed and, hopefully, updated. If that describes your situation, you could be missing a golden opportunity to reduce your PCI scope, lower your risk and cut your cost of PCI compliance."
This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.
Already a Subscriber? Login Here
Pages: 1 2
Leave a Reply
Readers, specifically those who want to comment on a story:
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
I have strong reservations about the 'individual' certification and posting of that information for merchants. Can you imagine the potential employee poaching that might occur? The implications when competitors can look up how many are certified with each of their competitors?
-Christine
