it week leader logo
R E L A T E D   C O N T E N T
ADVERTISEMENT

IT Week staff

Leader: Is PCI asking too much?

New legislation may not be high on retailers agendas

IT Week, 03 Jul 2008
ADVERTISEMENT

More regulation for online retailers came into force last week, courtesy of the Payment Card Industry Data Security Standard (PCI-DSS) section 6.6.

The question is will online retailers rush to implement the recommendations – namely secure code reviews for self-written web applications and tacking a web application firewall onto their web server front ends?

Given the rocketing number of public-facing retail web sites, there might not be enough experts to do such a code review across all those sites, never mind the small matter of how much they would charge for such a service. And there is also the issue of how often these code reviews would need to run to be valuable, whether annually, quarterly or even monthly.

Add on the cost of a properly maintained web application firewall, and the cost to retailers could be something that they just would not countenance, even though the web’s share of total retail sales is increasing fast. Also taking into account in the shockwaves from the credit crunch and oil price increases, and retailers may elect to pass on this one – again.

Last August credit card giant Visa relaxed the PCI-DSS regulations after seeing that it would have had to penalise a massive number of online retailers for non-compliance. Has anything changed? Well, yes – the global economic situation has deteriorated considerably and the payment card providers might need to be as understanding once again.


Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
RELATED ARTICLES
M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Berkshire, Berkshire, United Kingdom | EDS
EDS are currently looking to recruit an experienced Core Infrastructure Project Manager to join our Project Management Defence team in one of the following locations: Reading or Bracknell (Berkshire) or Camberley (Surrey). Summary: Within DII ... more >
London, United Kingdom | Feltham City Learning Centre
ICT Systems Administrator - Feltham City Learning Centre - £23,097 - £24,528 A full time ICT Systems Administrator to work in the Feltham City Learning Centre. This role requires a broad range of ICT skills ... more >
London, United Kingdom | Deloitte
Technology and Systems Consulting Event - LondonWith the right balance, you'll achieve great things. Join our Consulting practice and have the opportunity to balance your technical and business consulting skills to bring out the best ... more >
Sandiacre, Nottinghamshire, United Kingdom | NHS Midlands
Workstream Lead Requirement, Design, Build and Test (Business Analyst) Strategic IM&T - Delivery   Band 7:      £29,091 - £38,352 per annum Hours:       37.5 per week Base:         Octavia House, Sandiacre Job Ref:     973 - 080810   ... more >
More job opportunities