Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cloud
    • Cloud
    • Cybersecurity

    PCI Set to Testify on Security Standards

    Written by

    Sean Michael Kerner
    Published February 3, 2014
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The recent data breach at retailer Target—which left 70 million Americans and their personal information at risk—is receiving Congress’ attention this week in a number of hearings on data security. One of the participants in those hearings is Bob Russo, general manager of the Payment Council Industry Security Standards Council (PCI SSC), which oversees the PCI Data Security Standard (PCI DSS) for retailers and payment systems.

      Russo is set to testify before the House Energy and Commerce committee on Wed. Feb. 5, while Russo’s counterpart, Troy Leach, CTO of PCI SSC, is testifying before the Senate banking committee today. Both Leach and Russo have testified before Congress in the past about payment security and the work of PCI, Russo told eWEEK.

      The recent retail breaches that have been in the news highlight the need for a multi-layered approach to security, which is what the PCI DSS standard promises, Russo said. He stressed, however, that technology alone is not the solution. There have been some discussions that the use of EMV chip technology on credit cards would have prevented the Target data breach, since U.S. retailers largely only support magnetic-stripe-based cards.

      “Security is about people, process and technology,” Russo said. “We think that PCI is best positioned to drive this message, and we have a global body that has been doing this for the last seven and a half years.”

      The PCI standards have evolved over the years as market demands dictate. The U.S. government wants to do its part to help prevent future retail breaches, and the best place for the government to help is by putting its resources into law enforcement and information sharing, Russo said.

      The U.S. government today does not have any direct involvement in the PCI SSC, though Russo noted that the PCI Council does collaborate with the government at every chance it can get.

      Regarding the recent spate of retail breaches, Russo said that it’s too early to tell what actually went wrong. Major U.S retailers are typically compliant with PCI DSS, which could lead to speculation that perhaps the standard is missing something that enabled the breaches.

      “It’s very hard to figure out what’s going on, but if we go along the lines that it was some form of point-of-sale malware, there are a number of things in the PCI standard today to prevent malware from getting in,” Russo said.

      Once forensic information into the Target breach is available, understanding how the malware got into the system will be an important piece of the puzzle.

      “The standard tells you, that you need to put a lock on the door, but the people part of the equation means it’s up to you to actually lock the door,” Russo said.

      Once malware gets in, the PCI standards include provisions for monitoring the organization to see what’s going on, Russo said.

      Overall, Russo stressed that, as far as he is aware, the PCI standard and its approach of emphasizing people, process and technology is sufficient to limit the risks for retail payment systems.

      “My message to Congress is that up until now there has been a lot of ‘chicken little the sky is falling,’ but until we actually see what is going on, there is no way to make a determination,” Russo said.

      Though the current payment retail system is a very complex environment, overall Russo said that it is his firm conviction that the PCI standards provide a really solid baseline for security. Ultimately, the message that Russo expects will emerge is that PCI compliance will be part of ‘business-as-usual’ operations and not a once-in-a-year compliance exercise. It’s a message that is also a key part of the new PCI DSS 3.0 standard, which went into effect Jan. 1.

      While Russo is confident that PCI itself is a strong baseline for security, he’s eager to see real detailed forensic information at it emerges from the Target breach.

      “My gut feeling is that there isn’t anything missing in the PCI standard, but if there is something that is missing in the standard, then we want to know, which is why we will be urging the government to collaborate on information sharing and law enforcement,” Russo said. “Let’s not forget who the bad guy is here; it’s not the merchant and it’s not PCI; it’s the person somewhere in the world that hacked into the system and stole all the information.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×