Visa relaxes PCI stance

Card giant says it will give firms more time to comply with the data security standard

Written by Phil Muncaster

Credit card provider Visa has offered an olive branch to firms struggling to meet stringent Payment Card Industry Data Security Standards (PCI DSS), saying it will not penalise companies if it judges that they have made best efforts to comply.

The PCI DSS was created by the credit card companies in an effort to increase the security around cardholder data. It requires all firms that transmit, process or store credit card data to meet a 12-point list of requirements, including implementing strong encryption and user access controls.

However, a general lack of awareness about the standard exists among UK firms, and many failed to meet the 30 June deadline for compliance.

At a roundtable hosted by transaction management specialist The Logic Group, Stanley Skoglund, head of compliance and business support at Visa Europe, sympathised with retailers struggling to meet the PCI standard, explaining that Visa's own legacy IT systems had caused it many compliance problems.

"If an organisation shares its plans with us and the timeline itís working towards, and it is not storing [cardholder] data, then that is an acceptable position," Skoglund explained. "They must move forward, but if they do everything in the interim to mitigate risks it is to be applauded because it is a difficult thing to do."

Skoglund added that Visa has no plans to make an example of any big-name, non-compliant retailers by penalising them. Instead, he said the card giant is making greater efforts to listen to retailers' concerns, although more needs to be done to facilitate greater understanding between all industry stakeholders.

Gareth Wokes, chairman of The Logic Group, argued that his customers, which include the top 10 retailers in the UK, are finally beginning to understand the requirements and implications of PCI DSS.

"It's been a long journey but we are getting there and having conversations with customers who understand it," Wokes added. "PCI is about [reducing] organised crime, but now good governance requires retailers to consider it."

Skoglund added that Visa would continue to help its users. "My role is taking the tension out of the relationship between banks and retailers [and us] and getting them round the table," he said.

If all stakeholders were on the same page, the security initiative rolled out by Visa and MasterCard - known as 3-D Secure - may have been more effective, Skoglund argued. "The problem was on the issuing side of things, getting the banks to roll out to customers in a way that the customers would understand how to use it," he explained. "There was not a concerted effort across all UK markets."

See also:

reader comments

related articles

Firms ramp up content security and leak prevention

Trend Micro and Websense launch major new products 11 Jun 2007

 

Imperva moves to boost firms' compliance efforts

Application Defence Center Insight Service automates and secures regulatory compliance processes 04 Jun 2007

RSA launches PCI compliance suite

The RSA PCI Solution portfolio features professional services offerings as well as the firm's own products and those of new partners 23 Apr 2007

Chip and PIN success drives criminals online

Firms must be wary of attempts to mine customer card data from back-end systems, say experts 14 Feb 2007

PCI compliance eased

Newly established alliance seeks to educate firms 30 Jan 2007

Qualys eases PCI compliance

Qualys tool should help firms meet the requirements of card payment rules 08 Nov 2006

PCIe 2.0 up and running

PCI Express 2.0 base specification has now been finalised and released 18 Jan 2007

PCI SSC takes on Pin Entry Device security

Council takes over from credit card companies 13 Sep 2007

Payment data rules criticised

John Lewis IT chief says changing requirements hinder PCI compliance 10 Jul 2008

Fraudsters exploit card protection system

Warning issued over flaw in Address Verification System 12 Jun 2008

latest news

Red Hat a good fit for Qumranet

Open source behemoth opens up Windows opportunities with acquisition of virtualisation specialist 05 Sep 2008

Infor praises partners

Software vendor outlines its channel vision at second annual EMEA partner summit in Marbella 05 Sep 2008

Version One and Accurate launch university push

Software vendors link arms to create integrated document and financial management offering for universities 05 Sep 2008

Most commented stories

poll

Stormy times ahead for PBX?

Stormy times ahead for PBX?

Will the credit crunch affect PBX takeup?

Previous poll results

In The Studio With CRN: Josh Claman, Dell

In an editorial coup for CRN, Josh Claman, vice president of EMEA channels at Dell, talks to CRN TV about the vendor's channel plans

CRN Fight Night bouts are LIVE!

ALL the bouts from CRN's first ever white collar boxing event at The Brewery in Chiswell Street, are now online in their full glory for CRN readers to watch.

events

CRN Golf Challenge 2008

CRN Channel Golf Challenge 2008

CRN's annual golfing day will this year be held on 16 September at a championship course in East Sussex

CRN Reseller Leadership Forum logo

CRN Reseller Leadership Forum

An exclusive channel conference from CRN, to be held over one action-packed day in September 2008

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories