nCircle The Lens Blog

PCI: Is Compliance Really the Goal?

In reading this article from Dark Reading, which quotes a recent RSA survey about PCI compliance, I'm struck by what seems like a missing component. The basic gist of the survey results is that while more than 50% of merchants haven't complied with PCI, the majority of them are smaller, level 4, merchants. There are other interesting bits of data in there too, but the whole article makes a tacit assumption: the goal of PCI is that merchants comply.

I think that really is the goal for larger merchants, but I'm not so sure about the smaller one's. I can't help thinking that for a smaller merchant, the cost of compliance would often exceed the cost of simply outsourcing the card processing such that PCI no longer applies. To be fair, I haven't done the serious research to determine whether that's true, but given the implementation time lines referenced in the article, it seems plausible. It's also possible that there aren't outsourcing services that really meet the needs of smaller merchants.

Either way, if PCI doesn't start "motivating" the smaller merchants, then compliance will continue to lag. The numbers are skewed, however. Perhaps it would be better for RSA to measure the percentage of PCI compliant transactions instead.


TrackBack

TrackBack URL for this entry:
http://blog.ncircle.com/cgi-bin/mt-tb.cgi/206


Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Verification (needed to reduce spam):



About

This page contains a single entry from the blog posted on April 23, 2007 7:40 AM.

The previous post in this blog was Bad Habits or Good Marketing.

The next post in this blog is The Law of PCI.

Many more can be found on the main index page or by looking through the archives.



Bio

Blog: The Lens
Author: Tim Erlin

Tim Erlin, CISSP, is a Principal Product Manager at nCircle, responsible for vulnerability management and configuration auditing. In his nearly 10 year tenure at nCircle, he has also held the positions of Senior Sales Engineer and QA Engineer. His career in information technology began with systems and network administration.


   




Categories

  • Blog
  • Information Security Market
  • Regulations and Compliance
  • Vulnerability Research