Latest Comments
"You should hire people to fight trojans and stuff"
by Me | Aug 29, 2008 7:27 AM
 
"Not exactly an innovative feature Microsoft. Other browsers have had this capability for a long ..."
by Chris Jones | Aug 28, 2008 7:38 PM
 
"Hey"
by Emilio Garcia | Aug 27, 2008 2:53 AM
 
"adfdas"
by ddd | Aug 26, 2008 4:24 PM
 
"i have seen a few iPhone porn sites and while most of them are crap I did run across one that ..."
by gate | Aug 23, 2008 6:30 AM

PCI standard 'ignores' insider threat

  • Email a Friend
  • Print Page
PCI standard 'ignores' insider threat
By Staff Writers
Jun 24, 2008 8:41 AM
Tags: PCI | compliance | e-commerce | credit | card
New measures implemented in section 6.6 of the Payment Card Industry (PCI) standard, which come into force on 30 June, do nothing to address the threat of insiders, according to a database security firm.

The updates require that companies dealing with stored credit card and other consumer financial data either install firewalls around all internet-facing applications or have all customer application code reviewed for common vulnerabilities.

However, Secerno warned that, although this is a useful step in ensuring that information remains as safe as possible, its focus on the perimeter fails to provide any safety provisions against the threat of insider breaches and theft of data.

"The PCI Data Security Standard has the best intentions but, as is the case with many compliance directives, it barely addresses the most immediate and upcoming threats to consumer data," said Paul Davie, founder of Secerno.

"PCI was historically written for e-commerce rather than general retailers where breaches have actually been taking place.

"It is generally inadequate for addressing the sort of internal threat that can be exploited easily, such as by general or privileged users."

The insider threat can be anything from employees with financial or other motives to obtain and sell data, or criminals who infiltrate an organisation with the sole intention of stealing information.

"The standard says nothing about any malware other than viruses, and nothing about encrypting internal data," said Davie.

"It says nothing about protecting data on private networks and it says nothing about securing the database. Unfortunately, the internal threat is PCI's blind spot."

Davie believes that the retail industry needs to make sure that it protects data at the source in order to secure sensitive customer information against internal and external threats.

Copyright © 2008 vnunet.com

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below: