The Payment Card Industry Data Security Standard (PCI) is an excellent set of security requirements with which all of the major Credit Card companies expect merchants to comply. It includes technological, operational, and physical security measures designed to keep credit cards secure. To avoid penalties and fines, merchants are required to validate their business practices to these standards, and by this time, many merchants have invested a huge amount of time, effort and money into their PCI Compliance programs. As a security company, we applaud any measure that causes retailers to investigate and remediate their security vulnerabilities. While the effectiveness of PCI as a security standard will be evaluated over time, it appears that many retailers cannot see the forest for all of the trees that are in the way.
PCI is a credit card security standard. It deals with protecting sensitive cardholder data. Other data such as the name on the credit card, expiration date or anything else which can be tied back the primary account number on the credit card is considered to be cardholder data as well, but the key is that for PCI to be concerned with any data in general, credit cards have to be involved.
Merchants are so concerned with validating their compliance to their acquiring bank or to the credit card companies directly, that we are seeing many of them ignore other gaps in their security because they are not in scope for PCI. With enough personal information, thieves can steal someone's identity. Many retailers, especially fast casual restaurants with a loyalty program, have the names, birth dates, home addresses and other sensitive data about their customers. We have even see retailers ask for social security numbers which they use as the "ID" number for their programs. This personal data is just as critical to protect as credit cards, but your bank will not be checking on that security.
Here is the ironic part, PCI is not a law. The credit card companies are attempting to self-regulate security without the intervention or supervision of the government. On the other hand, there are both federal and state laws that concern themselves with protecting sensitive personal information which could be used to perpetrate identity theft. In fact, it is more devastating to a patron to have a criminal take personal information and obtain illegal (but legitimate) credit cards through identity theft than to have fraudulent credit card purchases made from stolen credit card data. The cardholder has built-in protection from fraudulent purchases made on their credit cards, but an identity thief who has established numerous illegal credit cards, or purchased assets in someone's name can destroy the credit score of victim for years. It is not uncommon for some identity theft victims to spend several years in court trying to reclaim their good name and defend themselves against angry creditors.
While it is true that PCI only concerns itself with credit cards, as a merchant, think about security holistically if you want to protect your patrons. If you have sensitive data of any kind, protect it. The recent stories about the identity theft from New York and Georgia should be enough to convince anyone that this issue should be on the mind of everyone who collects sensitive data (even if your bank is not asking about it).
452
http://global.networldalliance.com/new/images/slideshows/show452_thumb6515.gif
2012 NRA Show Kitchen Innovation winners
2012 NRA Show Kitchen Innovation winners
448
http://global.networldalliance.com/new/images/slideshows/show448_thumb6467.gif
Cheba Hut expanding footprint
Cheba Hut expanding footprint
446
http://global.networldalliance.com/new/images/slideshows/show446_thumb6424.gif
Burger King rolls out new menu, marketing initiatives
Burger King rolls out new menu, marketing initiatives
442
http://global.networldalliance.com/new/images/slideshows/show442_thumb6374.gif
Cousins Subs 40th anniversary makeover
Cousins Subs 40th anniversary makeover
433
http://global.networldalliance.com/new/images/slideshows/show433_thumb6178.gif
McDonald's nutritional kiosk
McDonald's nutritional kiosk
432
http://global.networldalliance.com/new/images/slideshows/show432_thumb6168.gif
Cold Stone Frozen Yogurt Creations
Cold Stone Frozen Yogurt Creations
427
http://global.networldalliance.com/new/images/slideshows/show427_thumb6060.gif
Dunkin' Donuts' new bakery sandwich line
Dunkin' Donuts' new bakery sandwich line
416
http://global.networldalliance.com/new/images/slideshows/show416_thumb5881.gif
QSR holiday promotions 2011
QSR holiday promotions 2011
403
http://global.networldalliance.com/new/images/slideshows/show403_thumb5594.gif
QSRs showcase Halloween promotions
QSRs showcase Halloween promotions
400
http://global.networldalliance.com/new/images/slideshows/show400_thumb5545.gif
Subway's Eco Restaurants
Subway's Eco Restaurants
Procurement and Sourcing Services
http://global.networldalliance.com/new/images/products/4492.png
4492/Procurement-and-Sourcing-Services
Marketing
http://global.networldalliance.com/new/images/products/4244.png
4244/Marketing
Print Supply Chain Management Services
http://global.networldalliance.com/new/images/products/4497.png
4497/Print-Supply-Chain-Management-Services
Mobile
http://global.networldalliance.com/new/images/products/4760.png
4760/Mobile
RoninCast® Software
http://global.networldalliance.com/new/images/products/4754.png
4754/RoninCast-Software
Scotsman Ice Machines
http://global.networldalliance.com/new/images/products/4869.png
4869/Scotsman-Ice-Machines
LG M5520CCBA - 55" class (54.6" measured diagonally)
http://global.networldalliance.com/new/images/products/4308.png
4308/LG-M5520CCBA-55-class-54-6-measured-diagonally
Executive Briefing and Exchange
http://global.networldalliance.com/new/images/products/4237.png
4237/Executive-Briefing-and-Exchange
Digital Signage & Kiosk Software - Nanopoint
http://global.networldalliance.com/new/images/products/2259.png
2259/Digital-Signage-Kiosk-Software-Nanopoint
LG M3204CCBA - 32" class (31.5" measured diagonally)
http://global.networldalliance.com/new/images/products/4317.png
4317/LG-M3204CCBA-32-class-31-5-measured-diagonally
|
Inside NetWorld Alliance Network Pizza Marketplace
|
Popular on NetWorld Alliance | Other NetWorld Alliance Sites | Global Partners |