« EMA Makes the Case for Systems Change and Configuration Management | Main | What do you think the fundamentals of security are? »

August 02, 2007

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00df351f7f82883300e3982186fb8833

Listed below are links to weblogs that reference Visa Posts PCI Compliance Figures:

Comments

Danny Moran

The amazing thing is that the PCI Security Council (as of today Sep 18) has not released a SAQ - self-assessment questionnaire for PCI DSS 1.1. They have an old version (1.0) on the Web site.

If you do the numbers of how many merchants at each level are compliant (I only have July stats from VISA and as you pointed out - M/C, Diners and AMEX don't share their compliance stats) - you will find that about 70% of all VISA transactions are performed by non-compliant merchants.

The little guys (Level 4) relative to their size would suffer the most since they are a soft target for hackers and a soft target for trusted insiders as well.

What needs to be done is to provide merchants with a practical tool to self-assess risk and start mitigating their threats - and be compliant - on the way. After all - this isn't compliance for compliance sake - the card associations need the payment processing supply chain and cardholder confidence to be strong.

See this cool article - at http://www.software.co.il
that talks about practical ways of doing this

Sounds good to me
Danny

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment