Latest Comments
"it's good one "
by khanbhai | Nov 22, 2008 9:00 PM
 
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM

PCI council streamlines merchant self-assessment

  • Email a Friend
  • Print Page
PCI council streamlines merchant self-assessment
The PCI Security Standards Council, charged with managing the 12-step mandate, today unveiled its new self-assessment questionnaire – a document to which all merchants that process credit card transactions must respond.

This is the first update to the questionnaire since the PCI Data Security Standard (PCI DSS) came into effect 1 ½ years ago. The previous version was based on the outdated Visa Cardholder Information Security Program (CISP)mandates.

There are four versions of the updated questionnaire, and businesses can request a particular type based on their technical configuration for processing credit card payments, according to a statement from the PCI council.

In the past, all merchants, no matter their size, were obliged to complete the questionnaire, which contained more than 230 questions, many irrelevant to smaller vendors.

“It cost in terms of time and effort if someone has to do this,” said Glenn Boyet, a spokesman for the council. “This is a project you have to allot resources to. If we make this easier and still get the desired result, that's what we want the merchants to have the ability to do.”

Avivah Litan, a Gartner analyst, told SCMagazineUS.com that the new questionnaires will feature 11, 21, 38 or 226 questions. The previous one-size-fits-all document – which had 234 questions – was written for large enterprises “that manage farms of PCs, servers and databases,” she said.

“If you look at a dry cleaner, why should a dry cleaner using a dial-up modem have to answer 234 questions?” Litan said.  “This stratifies and delineates the requirement based on the type of merchant.”

E-commerce companies, which do not take credit cards in person, also stand to benefit, she said.

“This is really welcomed news,” she said. “This is probably the most positive step they've (the council) taken.”

Litan has criticised the council for lacking authority to resolve PCI-related issues, such as enforcement and merchant classification, which are controlled by the credit card brands.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Breaches & Exposures Whitepapers