Don't hinge security on PCI DSS

 

Summary

Data centers that do not handle credit card data can strive to meet Payment Card Industry Data Security Standard, but compliance is one-off and may give organizations false sense of security, experts warn.

Events

IBM Technology Conference & Expo 2012
May 22, 2012

One World Hotel, First Avenue, Bandar Utama City Centre, 47800 Petaling Jaya, Selangor

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

It may be beneficial for all data centers to demonstrate compliance with the Payment Card Industry Data Security Standard (PCI DSS) as the guidelines provide good basic information security principles. However, organizations need to look beyond this standard, which was developed to protect customer data and prevent identity theft, and focus on what it means to protect their assets, note industry experts.

NeoSpire, a Texas, U.S.-based managed hosting service provider, told ZDNet Asia that companies are increasingly using the PCI DSS as a "security bible" to meet mandatory requirements such as Sarbanes-Oxley Act and the HIPAA (Health Insurance Portability and Accountability Act), even though they may not process payment card data.

Such organizations need to communicate their commitment to data security to their customers and apart from PCI DSS, there are few "well-defined and broadly-scoped" security standards that are widely recognized by the business community, Sean Burton, NeoSpire's senior director of security, explained in an e-mail.

Ovum's principal analyst Graham Titterington observed that PCI DSS is already in use by many organizations as a significant number of businesses handle credit card data. He noted that the security standard is unique because it is "very prescriptive".

"It tells you what you have to do rather than set out goals for what you should achieve," Titterington said in an e-mail.

According to Bob Russo, general manager of the PCI Security Standards Council, the "guiding principles and prescriptive nature of the standard make it an excellent floor" on which a defense-in-depth security strategy can be built.

"It is a solid group of recognized best practices that can be used as the foundation for a more comprehensive security program," he said in an e-mail.

Russo noted that the PCI DSS can be relevant to any organization because "whether you are a small merchant or a large multinational corporation, there are contractual and cultural obligations [stating] you have to protect certain types of sensitive data", such as credit card data.

"Your customers, your shareholders and those that you do business with all have a certain expectation of diligence if they trust you with certain sensitive data," he added. "You must do everything you can to honor those obligations because if you lose the data of your customers, you can suffer financial damages and the tarnishing of your brand."

Not enough to declare full security
However, Russo noted that PCI compliance does not equate to a properly secured organization as compliance is "simply a snapshot in time".

"Organizations must go beyond simply striving for a Report on Compliance (ROC) and focus on strong security measures," he advised. "Compliance and security are two separate things. You need to build security into your daily business process."

Rob McMillan, Gartner's research director for security risk and privacy, concurred. Organizations looking to protect the entire set of organizational information will find useful pointers in the PCI DSS, but the standard does not necessarily give these businesses everything they need, McMillan explained in a phone interview. For instance, it may lack the necessary precautions needed to protect intellectual property in data forms, which are different from credit card information.

"PCI DSS gives you a good basic set of pointers on good infosecurity practices; it's not the be all and end all," he said.

Rather than fixate on meeting a standard such as PCI DSS, organizations should instead focus on "doing security well" because that would naturally lead to compliance, McMillan pointed out.

A sound security strategy would encompass efforts to assess the risks, determine the organizational risk appetite and implement controls that will bring the risks to a level that the business can live with, he noted.

When it comes to assessing cloud providers, McMillan said, again, there may be some useful provisions in PCI DSS but it "probably won't cover all you need". For instance, one of the areas the standard covers is awareness and organizations need to consider what exactly this means when purchasing a cloud service.

"The problem with cloud services is you are now one more level removed from the technology and the way the technology and information is managed," he explained. "So you need to make sure you are very clear on the security outcomes you need and how you're going to ensure those security outcomes are met."

Titterington noted that the PCI DSS, even at the higher tiers where requirements are more rigorous, is focused on preventing data theft and therefore, do not make a comprehensive data security policy.

The Ovum analyst concluded: "My feeling about PCI DSS is that it has achieved a great deal and has brought security to people who are not technically savvy, but it is not sufficiently comprehensive to be used to certify cloud service providers or enterprise IT departments in general."

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Mac users' indifference toward security 'worrying' http://t.co/MBTwqilk

RT @Bilafer: 25% of top VC firms investing in China, India or both. Good news for innovation, #SAPAPJ http://t.co/wkCXKkxU

Mac users' indifference toward security 'worrying' http://t.co/AkSlHrCH #cyber #infosec

RT @zdnetasia: Gartner: Mobile CRM gives better ROI than social. http://t.co/nTgj44H8

China hits back at Pentagon report on spy claims. http://t.co/CccR4SBM

China hits back at Pentagon report on spy claims http://t.co/YP380BYQ http://t.co/erFX4aVv #arcavir

http://t.co/VNaZtseV China hits back at Pentagon report on spy claims: Annual report by Pent... http://t.co/TvgCi5RE http://t.co/wiqY9ktt

#AntiVirus News: Mac users' indifference toward security 'worrying' http://t.co/spWS0CpU #AdAware

Mac users' indifference toward security 'worrying' http://t.co/BtVn1BAk
> expected! They still remember Mac vs PC ads
#infosec #news #apple

Pentagon report says China exploit US tech, conduct cyberespionage, China says it has been "unjustly criticized" http://t.co/P5wgqy6I #in

Mac users' indifference toward security 'worrying': 59 Jakarta 10350, Indonesia In light of the recent spate of ... http://t.co/Lxgnc1wM

Pakistan lifts block on Twitter - ZDNet Asia: Pakistan lifts block on TwitterZDNet Asia59 Jakarta 10350, Indones... http://t.co/61n85ajh

Pakistan lifts block on Twitter http://t.co/WHqoJOqm http://t.co/erFX4aVv #arcavir

http://t.co/VNaZtseV Pakistan lifts block on Twitter: Country restores access after briefly ... http://t.co/5gqegFWK http://t.co/wiqY9ktt

Pakistan lifts block on Twitter. http://t.co/y0arswpE

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

3 hours ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

20 hours ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

2 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

2 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

3 days ago by wykoong on Drop the egos, copy ideas, then innovate