« Things worth reading: 27th September 2010 | Main | Things worth reading: 28th September 2010 »

September 27, 2010

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a01053620481c970b0133f49e8445970b

Listed below are links to weblogs that reference Why does the card securities council not care about card security?:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Steve Brunswick, Thales

The card schemes and PCI-SSC are naturally cautious. They like to make sure that what they put into their requirements is security standards based, NIST approved etc. PCI DSS 2.0 is a set of requirements built on standards rather than a standard itself. But there are no standards for tokenisation and E2EE, so they can't go in. Meanwhile the industry and the vendors that serve it are driving forward with implementations of end-to-end encryption and tokenisation to "protect cardholder data" (PCI-DSS requirements 3 and 4), and we have an impasse. To break this, (PCI-SSC do know they can't ignore what's actually happening, and recognise it is of value to improve security), we are getting guidelines promised for the same time as PCI-DSS 2.0 - and none too soon given how the industry is racing ahead anyway. The situation will resolve itself in time (in time for PCI-DSS 3.0?) when X9.119 deliver their tokenisation and E2EE standards. PCI-DSS and other PCI-SSC documentation can then refer to this, as they do to other X9 standards today.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Your email address:


Powered by FeedBlitz

Twitter FSClub

    follow me on Twitter
    Financial Brand Editor's Choice

    Financial Brand's Best Banking Blog, Reader's Choice

    Alex: The Finanser BlogAlex at the Financial Services Club
    Gaping Void: The Finanser BlogGaping Void's Hugh MacLeod worked with the Finanser
    Wordle: The Finanser Blog

    The Financial Brand

    NetBanker

    Payments News - from Glenbrook Partners

    Payments RSS

    Tomorrow's Transactions blog

    Analytics