When Better Security Equals Weaker Compliance
Written by David TaylorFebruary 4th, 2009
Sometimes, security and compliance are totally in sync. When you increase your security, you improve your compliance (with PCI, SOX, HIPAA, etc.). But other times, not so much.
PCI Guestview Columnist David Taylor opines that he has run into several different situations where retailers have rejected the use of security controls and reporting tools that would improve both their effective security and their awareness of threats. They turned down these technologies because buying them would have "made" the retailers non-compliant with PCI. Both the real and the perceived issues of this situation must be explained.
This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.
Already a Subscriber? Login Here
Leave a Reply
Readers, specifically those who want to comment on a story:
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
I have strong reservations about the 'individual' certification and posting of that information for merchants. Can you imagine the potential employee poaching that might occur? The implications when competitors can look up how many are certified with each of their competitors?
-Christine
