advertisement
advertisement


PCI Mobile Madness: Council Clarifications Not Helping

Written by Evan Schuman
February 10th, 2011
The intersection of PCI and mobile—an admittedly murky place—is getting more complicated. The PCI Council has pledged that it won't validate any more mobile applications for quite some time, at least not until it can determine what the best criteria are. Questions have now cropped up about the handful of mobile applications that had already been PCI validated.

The Council is in a very difficult position (between a ROC and a hard token place?), especially because it must give as much attention to political issues as it does to technological ones. In this case, the politics are not of the Washington, D.C., sort, but of the industry. Specifically, how to deal with the concerns of the many mobile application developers whose apps now cannot even be considered for PCI validation, especially when they complain of their rivals, who happened to have slipped in but PCI closed the evaluation door. Should the few already approved applications be delisted, so that all mobile applications can be evaluated at the same time, using the exact same criteria? Is that the fair approach?

This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.


advertisement

4 Comments | Read PCI Mobile Madness: Council Clarifications Not Helping

  1. Emma Jenkins Says:

    A ROC and a hard place. Evan, you crack me up!

    Emma.

  2. Ernie Says:

    It shouldn’t come as a surprise to anyone that the mobile evolution is causing strain on current standards. It didn’t really exist when the standards were contemplated. Now we’re playing catch up. But the evolution and adoption isn’t going to slow, because PCI isn’t ready for mobile. We might see some Level 1 and 2 merchants delay programs until PCI sorts out their thoughts. Others will run the risk hoping for a competitive advantage. That should make for interesting conversation with their QSA, if they choose to disclose it.

    The Level 4 merchants don’t know this debate is happening. Mobile apps are start popping up all over as small entrepreneurs look for a competitive edge. That trend will only increase. PCI could petition the app platform companies to disallow payment applications from being available for download to consumer devices, but that seems like a stretch.

    The longer PCI takes to get its position in place, the higher the likelihood that the requirements get ignored or marginalized.

  3. Chris Says:

    If I’m not mistaken, I believe the PCI SSC has already addressed approved applications being delisted in its statement from January 25, 2011: “Until it has completed a comprehensive examination of the mobile communications device and mobile payment application landscape, the Council will not approve *or list* (my emphasis) mobile payment applications used by merchants to accept and process payment for goods and services as validated PA-DSS applications unless all PA-DSS requirements can be satisfied as stated and the underlying mobile communications device supports the merchant’s PCI DSS compliance.”

    It appears this statement indicates that it is only a matter of time until the approved applications are delisted.

  4. Evan Schuman Says:

    We saw that, too, but it’s still subject to interpretation.

Leave a Reply

Readers, specifically those who want to comment on a story:
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.

Weekly, Monthly Newsletters

Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly report, with urgent bulletins as news merits—along with our monthlies on Mobile, Security, In-Store, E-Commerce and CRM.
advertisement

Most Recent Comments

"Careless" Systems Integrators Now Directly Under PCI DSS

This exact issue has been bothering me for years, and I was JUST talking about it with someone only yesterday. This may well be my favorite article, mostly because I'm biased and have hated this particular problem forever. Read more...
Good article, but how does this have anything to do with the DSS? Read more...
Actually, the QIR program has a lot to do with the DSS (or PCI). Since merchants rely on their reseller or integrator to implement their PA-DSS validated application, these resellers and system integrators play a critical role in merchants achieving and maintaining PCI compliance. As far as I can tell, the QIR program is designed to help merchants stay compliant by making sure their payment applications are installed according to the PA-DSS Implementation Guide, for example ensuring default passwords are changed (and protected), that the data encryption keys are properly set and secured, that the merchant's data retention policy is set, that no sensitive cardholder data are stored, and often that a firewall is in place and properly configured. Read more...
Although this is a great move forward in pushing the issue of highly trained people, it is also a good marketing ploy for the council. It begs the question: How much do they stand to make? The problem for this is that for people (like myself) that are just starting out their own business venture, PCI has typically charged a premium for their training and certifications. This change will likely force those of us with less capital to spin into the abyss. I have more than 15 years in the security and compliance fields with heavy hitter certs like CISSP, CRISC, and Sec+. There should not be a guide but a free test or a pre-requisite of either the PCI cert OR other heavy hitter certs. I just don't want the good guys in small places to get flushed out. Read more...

StorefrontBacktalk
Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.