In Depth
A Tale of Two PCI Security Audits
Robert Duran of Time Inc. and Allan Kintigh of National Card Services share their PCI auditing experiences. Why one's experience was unpleasant and the other fared better.
By Bill Brenner, Senior Editor
One auditor's advice
During the CSOonline PCI security event, Atlanta-based auditor James DeLuccia sat on the panel alongside Duran. He acknowledged that a lot of companies run into the difficulties Duran described. Among other things, he agreed there are probably auditors out there who go too far in pushing certain vendors on merchants as a condition for a passing grade.
However, he said, merchants have a better chance of getting a fair shake these days because there's a larger pool of auditors to choose from.
"At the beginning there were far fewer companies capable of performing a PCI security audit, but in the last couple years Visa and MasterCard have authorized a lot more," he said. "The bigger the pool of auditors, the more likely you will see transparency."
His parting advice to merchants facing an audit: Don't stick with the same auditors for too long.
"I always tell clients they shouldn't rely too much on the same auditor," he said.. "I suggest rotating the auditors so you'll always have fresh perspectives and second opinions."
Other stories by Bill Brenner
PCI
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



