Shopping
Many retailers are not in a position to live up to new payment card rules
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Retailers struggle to meet PCI deadline

Quick fixes not good enough, warn experts

Ian Williams, vnunet.com 19 May 2008
ADVERTISEMENT

Many retailers are not ready to meet the Payment Card Industry Data Security Standard (PCI-DSS) Section 6.6 deadline of 30 June, analyst firm Gartner has warned.

The new regulations stipulate that all merchants that accept payment card transactions after this date will have to use either a specialised firewall to protect web applications, or complete a web application software code review to ensure that all transactions are secure.

Even though these measures have been encouraged as best practice for 18 months, Gartner's research suggests that confusion over the actions retailers need to take means that many are not in a position to live up to the new rules.

Furthermore, information security consultancy DNS believes that even retailers that have started the process are in many cases looking for a quick fix instead of undertaking a full code review.

"With the deadline rapidly approaching retailers are going to be looking to bring in security policies quickly to ensure that they adhere to this regulation," said Lee Lawson lead penetration tester at DNS.

"But the PCI-DSS has been brought in for a reason and, unless companies fully understand the sensitive nature of the customer information they hold, the problems will continue and customer confidence will keep falling."

DNS reckons that, although this will bring retailers in line with current regulation, it still leaves them exposed to attack.

"We have come across companies who are unsure of what steps they should be taking and have left it until the last minute," concluded Lawson.

"They should not be looking for a quick fix in this case. It does not help the company long term as increased regulation is inevitable, and certainly does not help the customer if there are still flaws in existing applications."

See also:

Infosec Europe 2008Security is now everyone's problem  23 Apr 2008
New rules on the storage of payment details  16 Apr 2008
Computer theftPCI compliance does not guarantee security  04 Apr 2008
NetEvents panel warns of ambiguity in PCI compliance  28 Sep 2007

All Ecommerce
Tags: Pci-dss, Ecommerce, Government, Security, Strategy

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, United Kingdom | Utilyx
Senior Business Analyst - London Highly professional individual capable of working at senior / board level with blue chip clients - shaping and driving the analysis and design of their energy management solutions Proven capability ... more >
United Kingdom | Sussex HIS via Acertus Ltd
Business Development and Partnership Director - £62,337 to £77,179 plus benefits Any Sussex HIS location by agreement  The Sussex HIS was formed in mid 2004 through the merging of all IT services from all Trusts ... more >
London, United Kingdom | Barts and The London NHS
 Information Manager - £28,924 - £38,591 pa inc - London   Applications are invited for the post of Information Manager in the Head Office of the Central and East London Comprehensive Local Research Network. The ... more >
London, Berkshire, United Kingdom | EDS
EDS are currently looking to recruit an experienced Change Project Manager to support our Programme Directorate Defence team in Reading, Berkshire. Summary: This role sits within a secure site and will be to work on ... more >
More job opportunities