it week leader logo

Leader: Is PCI asking too much?

New legislation may not be high on retailers agendas

Written by IT Week staff

More regulation for online retailers came into force last week, courtesy of the Payment Card Industry Data Security Standard (PCI-DSS) section 6.6.

The question is will online retailers rush to implement the recommendations – namely secure code reviews for self-written web applications and tacking a web application firewall onto their web server front ends?

Given the rocketing number of public-facing retail web sites, there might not be enough experts to do such a code review across all those sites, never mind the small matter of how much they would charge for such a service. And there is also the issue of how often these code reviews would need to run to be valuable, whether annually, quarterly or even monthly.

Add on the cost of a properly maintained web application firewall, and the cost to retailers could be something that they just would not countenance, even though the web’s share of total retail sales is increasing fast. Also taking into account in the shockwaves from the credit crunch and oil price increases, and retailers may elect to pass on this one – again.

Last August credit card giant Visa relaxed the PCI-DSS regulations after seeing that it would have had to penalise a massive number of online retailers for non-compliance. Has anything changed? Well, yes – the global economic situation has deteriorated considerably and the payment card providers might need to be as understanding once again.

See also:

reader comments

related articles

More regulation for online retail arrives

A new PCI-DSS regulation requires online retail firms to perform code reviews and use a web application firewall 02 Jul 2008

F5 teams with WhiteHat for automatic online security

E-commerce security boost for firms 14 Mar 2008

Security top priority for hosting customers

Elinia’s James Carnie says compliance with standards is key in gaining the trust of clients 18 Feb 2008

Retailers lagging behind in security

New Deloitte survey shows consumer businesses are still implementing PCI 01 Feb 2008

More regulation for online retail arrives

A new PCI-DSS regulation requires online retail firms to perform code reviews and use a web application firewall 02 Jul 2008

Retailers struggle to meet PCI deadline

Quick fixes not good enough, warn experts 19 May 2008

PCI crackdown to fuel spend

Resellers urged to push compliance solutions as Payment Card Industry standard comes into force 10 Jul 2008

latest news

Red Hat a good fit for Qumranet

Open source behemoth opens up Windows opportunities with acquisition of virtualisation specialist 05 Sep 2008

Infor praises partners

Software vendor outlines its channel vision at second annual EMEA partner summit in Marbella 05 Sep 2008

Version One and Accurate launch university push

Software vendors link arms to create integrated document and financial management offering for universities 05 Sep 2008

Most commented stories

poll

Stormy times ahead for PBX?

Stormy times ahead for PBX?

Will the credit crunch affect PBX takeup?

Previous poll results

In The Studio With CRN: Josh Claman, Dell

In an editorial coup for CRN, Josh Claman, vice president of EMEA channels at Dell, talks to CRN TV about the vendor's channel plans

CRN Fight Night bouts are LIVE!

ALL the bouts from CRN's first ever white collar boxing event at The Brewery in Chiswell Street, are now online in their full glory for CRN readers to watch.

events

CRN Golf Challenge 2008

CRN Channel Golf Challenge 2008

CRN's annual golfing day will this year be held on 16 September at a championship course in East Sussex

CRN Reseller Leadership Forum logo

CRN Reseller Leadership Forum

An exclusive channel conference from CRN, to be held over one action-packed day in September 2008

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories