The InformationWeek -- Blogs
Welcome Guest. | Log In| Register | Membership Benefits

Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

The Death Of PCI DSS? Don't Be Silly


Posted by George Hulme, Jan 27, 2009 10:13 PM

Yes, in the past year two big retailers, who were apparently compliant to the Payment Card Industry Data Security Standard, were breached. Does that mean PCI DSS has grown increasingly irrelevant? That's absurd.


First, I'm going to state the obvious to anyone who has studied IT security and compliance: being compliant to any mandate won't make one secure. And it never will. I can't make the case as to why any better than Mike Fratto did in his earlier post, so I won't even try. But the point is: focus on building a secure and sustainable infrastructure, no matter how big, or small.

I've spent the better part of this decade interviewing IT security experts, vendors, chief information security officers, and other security mangers in just about every industry. Generally -- and I stress *generally* (as there are always exceptions) -- retailers, manufacturers, and heath care providers have tended to have the least mature security programs in place. Not true in every case, but I found it to be true often enough to see a trend.

Prior to the adoption of PCI DSS several years ago, online retailers and brick-and-mortar retailers barely paid attention to IT security. Trust me, in 2003, when it came to a Top 10 list of the most pressing IT objectives for most merchants, IT security ranked around 580th. They probably spent more time evaluating stationery than how to secure their databases, Web applications, and VPNs. So when you see retail IT managers arguing over whether they should install a Web Application Firewall, or conduct application security vulnerability assessments, or even do both, you can thank PCI DSS to a large degree.

PCI DSS has done more to raise security awareness among retailers than anything else I can think of. Even the torrent of breaches earlier this decade. And, while I can't quantitatively prove it, PCI DSS has most certainly raised the security of the retail industry, in general.

The unfortunate breaches of Hannaford Bros. Co, and more recently Heartland Payment Systems, which were both PCI compliant, doesn't make PCI DSS either irrelevant, obsolete, or worthless. Whoever thought PCI DSS would eliminate data breaches in retailers should probably make sure they don't work in IT, and definitely make sure they don't work in IT security. Its goal was to raise security among retailers and merchants, and to a large degree its been a success.

This standard isn't perfect, not by a long shot. The standard won't eliminate security breaches -- and no one said it would. But the standard has increased the security of many retailers, and probably stopped quite a few breaches along the way.

Do we talk about the "failure" of law enforcement when someone commits a crime? Do we talk of the irrelevance of physical security when banks are robbed? Do we talk about how "worthless" the military is after a lost battle or two? Do we talk about how eating healthily and exercising is such a waste when falling ill?

No, intelligent people do not do those things.

The battle against cybercrime is like any other long-term fight, and once in awhile companies that strive to do everything right are going to find themselves breached. It's the nature of this beast, not the fault of PCI DSS.

« Content Management Recommendations That Pull No Punches | Main | We Have Met Linux, And It Is ... Us? »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Here's to the First Responders!
  2. HPC Joins the Dummy Revolution?
  3. Detecting Scalability Problems With Intel Parallel Universe Portal


Join The InformationWeek Group On LinkedIn


                           


  1. HTC Droid Eris To Get Android 2.0 Update
  2. HTC Droid Eris Receiving OTA Update From Verizon
  3. Samsung Redefines Vaporware: 'Bada'
  4. Google Revs Up iPhone Search App


  1. Practical Analysis: 802.11 -- The Blu-Ray Of Wireless
  2. 10 Questions To Ask About Netbooks
  3. Down To Business: The 'Jobs Summit' And The Role Of Government
  4. How To Improve Your End-User Device Strategy
  5. CIO Profiles: Marc Probst, VP And CIO Of Intermountain Healthcare
  6. Rolling Review: Zinstall Runs Windows 7 and XP

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007