Blog powered by TypePad

« Was TJX Non-compliant with PCI at Time of Breach? | Main | NIST Updates Provide Important Guidance for Email and Wireless Security »

February 28, 2007

A Rational Voice Among the PCI Noise

This guy, Mike Rothman, knows what he is talking about. Mike's been going through his Daily Incite's for 2007 and yesterday he landed on PCI compliance.

If only securty standards and regulations were really taken seriously.

But, as Mike points out, there's...

1. No real enforcement
2. A lot of ambiguity on what's required
3. Too much confusion among CSO and Compliance people

As Mike said, CSOs, CISOs, CIOs, and compliance officers need to focus less on what will make them compliant and a whole lot more on what will make their enterprise secure.

Oh, and a lot more public outcry is going to be needed! Until the penalties for non-compliance are as weighty as the laws themselves are to read, there's really nothing to prevent more data breaches like the TJX's of the world.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d834520ea169e200d8351fb66469e2

Listed below are links to weblogs that reference A Rational Voice Among the PCI Noise:

Comments

Magnificent collection of prayers - and I haven\'t begun to explore the rest of the website!

i love this site.a

No real enforcement? How about these carrot and stick enticements to let people know about deadlines and fines?
http://pcianswers.com/2007/01/21/non-compliance-fines/

What kind of enforcement are you looking for?

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment