Opinion
PCI Is Security Simplicity, Not Complexity
The payment card industry data security standard seems to make relatively smart people instantly dim-witted as they complain about its so-called complexity.
By Ben Rothke
All it takes is one successful hack attack to wipe out years of so called “savings” gleaned from not implementing security. Online crime has become more sophisticated and far better organized over the past several years. No business wants to risk its bottom line or consumer confidence on the hopeful idea that a security breach just won’t happen to them.
The time to take security seriously is before an attack happens, not after. That is precisely what PCI aims to do.
Conclusion
Rather than making excuses about how difficult or costly PCI is, companies need to step up to the plate and start taking security seriously. They need to get a clear roadmap of their priorities and ensure they are accomplished to meet the minimal security requirements.
PCI is the best thing that has happened to consumer data protection in the payment industry in many years. The quicker it is embraced and implemented, the better off we all will be.
Ben Rothke, CISSP, QSA, is a security consultant with BT INS and the author of Computer Security: 20 Things Every Employee Should Know (McGraw-Hill, 2006).
pci data security standard
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



