IT Compliance Advisor

Apr 13 2009   7:08PM GMT

What does being PCI DSS compliant really mean?



Posted by: Scot Petersen
PCI DSS, compliance, Visa, data leakage, podcast

There is a big difference between being PCI DSS compliant and being “certified” as PCI DSS compliant, says e-commerce expert Evan Schuman of StorefrontBacktalk.com in this edition of the IT Compliance Advisor weekly podcast. Because audit results can sometimes be subjective, the results could mean that some retailers may not really be compliant even though someone says they are, he says.

 
icon for podpress  What does being PCI DSS compliant really mean? [13:58m]: Play Now | Play in Popup | Download

The PCI DSS specification is under fire for enabling such ambiguity. The House Committee on Emerging Threats, Cybersecurity and Science and Technology recently held a hearing on PCI and concluded that it has been inadequate in stopping credit card transaction data leakage. The administration of PCI DSS by credit card giant Visa is one reason, Schuman says. Find out more in this podcast.

Reblog this post [with Zemanta]

Comment on this Post


You must be logged-in to post a comment. Log-in/Register