Risk
9/24/2009
06:52 PM
George V. Hulme
George V. Hulme
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Survey Says: PCI DSS Compliance Not Strategic

That's right. A survey conducted by the Ponemon Institute, and backed by security firm Imperva, says that the vast majority of firms don't view the Payment Card Industry Data Security Standard (PCI DSS) as a strategic initiative.

That's right. A survey conducted by the Ponemon Institute, and backed by security firm Imperva, says that the vast majority of firms don't view the Payment Card Industry Data Security Standard (PCI DSS) as a strategic initiative.The question is why? Why don't companies that handle credit card information view security as a strategic priority? There are a couple reasons that come immediately to mind. First, it's hard work and requires persistence. Second, good security doesn't increase market share: consumers don't reward companies when nothing bad happens. Third, many companies simply don't believe the worst will happen to them. Or, even if they do, they figure they'll handle the cost of the breach and move on.

The survey (registration required) included more than 500 U.S.-based and multinational firms. And, with the average annual revenue of survey respondents at $5.6 billion, the survey was not filled with small businesses that one would expect to be strapped. Nevertheless, the survey found that 71% of respondents said that their company does not treat PCI DSS as a strategic initiative.

The kicker: 79% of this very same group has experienced a data breach that involved the loss or theft of credit card information.

That data hints that incurring the cost of a breach is cheaper than protecting systems and data. So does the finding that 60% of respondents don't think they have sufficient resources to comply with PCI DSS or to reach a necessary level of cardholder security.

I found that last data point especially troubling. The digital infrastructure is a crucial part of modern supply and delivery chain. And it needs to be maintained to be both sustainable, and secure, or it will break down. This should have nothing to do with regulatory compliance - but it does. Move away from heavily regulated companies and the attitude toward security gets more complacent.

They're simply not investing in the technology or the people necessary to manage risk properly.

So what happens when security isn't treated as a "strategic initiative" by a broad swath of the business community? You get what we have today, and that's the near daily news reports of credit card, financial, and other personal data being breached.

The sad fact is that PCI DSS compliance should be considered a security baseline -- not the ultimate objective, which would be a secure infrastructure. It seems many companies, most in fact, aren't even willing to make the investment required to hit bare minimum.

Follow me on Twitter, @georgevhulme

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6306
Published: 2014-08-22
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges via unknown vectors.

CVE-2014-0232
Published: 2014-08-22
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1)...

CVE-2014-3525
Published: 2014-08-22
Unspecified vulnerability in Apache Traffic Server 4.2.1.1 and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

CVE-2014-3563
Published: 2014-08-22
Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud.

CVE-2014-3594
Published: 2014-08-22
Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host aggregate name.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.