No thanks, stay here.  

  We notice you are visiting from a U.S. Internet provider. Switch to our U.S. website.

Industry News

Miss a scan? You may still be compliant - but don't make a habit of it

By Joseph Trigliari

25/02/2010 - Requirement 11.2 of the PCI DSS states that merchants must pass a vulnerability scan for each of the past four quarters to be deemed compliant. But what happens if a merchant misses a scan? Do they have to wait another four quarters to pass an audit?

Maybe not, said QSA Walter Conway. In an article for StorefrontBacktalk.com, Conway said that there may be a loophole in this requirement, in that a QSA can still assess a merchant as compliance even if they missed a scan, as long as they have reason enough to believe that the merchant's risk "has been sufficiently addressed through [other] practices."

However, Conway notes that vulnerability scales are potentially the easiest part of the payment processing compliance process, which means that merchants who have missed a scan are likely not vigilant in other areas.

Even if they could potentially get a free pass for missing a scan, Conway advises merchants to try their best not to make it a habit.

"Vulnerability scans are a critical piece of any risk management program. Scans detect vulnerabilities you need to fix," Conway wrote. "The bad guys are scanning you right now, so why in the world don’t you want to know what they are learning?"

Experts also advise merchants to think outside the compliance box, and to invest in payment processing security measures all year round. ADNFCR-2514-ID-19638580-ADNFCR

Related News - Security and Fraud

Study: PCI compliance a no-brainer among Level Four merchants

10/01/2012

A recent survey by research firm Gartner found nearly one-fifth of retailers and credit card processing services are not compliant with Payment Card Industry Data Security Standards.

Full Article

Tracking spending can be made easy with credit cards

06/12/2011

Many people feel that plastic payment processing options can lead to overspending, but a recent article published by Forbes explains that making payments with credit cards is actually a great way to control costs and track expenses.

Full Article

Keeping business bank accounts safe and secure

11/10/2011

The internet has provided consumers with many new and convenient ways to access their account information, but these advances have also created the need for thorough security measures.

Full Article

Personalized payment chips get fraud prevention upgrade

10/10/2011

Payment chips made by Fiserv will now be further personalized using the Europay MasterCard Visa (EMV) standards, a global credit card payments technology that helps prevent fraud from lost, stolen or counterfeit cards.

Full Article