No thanks, stay here.  

  We notice you are visiting from a U.S. Internet provider. Switch to our U.S. website.

Industry News

PCI SSC's new QSA certification program presents potential drawbacks

By Joseph Trigliari

04/03/2010 - The PCI Security Standards Council is expected to release the details of a new QSA certification program in the next few months, allowing internal auditors at Level 1 and Level 2 merchants to become certified to conduct the company's annual PCI assessment.

Yet this presents some tricky questions in terms of payment processing security, reported StorefrontBacktalk.com.

First of all, the cost may not be worthwhile, the website reported.

"Merchants need to assess how significant the QSA's professional fees are in relation to the total cost of a PCI assessment," wrote QSA Walt Conway for StorefrontBacktalk.com. "Often, the infrastructure costs and dedicated internal resources - including the newly trained auditors - are a large part of the total cost. In addition, merchants still need internal and external penetration tests, the costs of which can be a major part of a QSA engagement."

Conway added that all quarterly external vulnerability scans still need to be conducted by a third-party professional, called an Approved Scanning Vendor, which can add to the cost.

In addition, there may be a conflict of interest when a company's own executive conducts an audit, which could result in the business being vulnerable to a payment processing breach despite being deemed "compliant."

Experts advise merchants that passing a PCI compliance audit does not necessarily mean a business is secure, either - merchants must follow general security best practices around the clock, not just in preparation for an audit.ADNFCR-2514-ID-19651960-ADNFCR

Related News - Security and Fraud

Study: PCI compliance a no-brainer among Level Four merchants

10/01/2012

A recent survey by research firm Gartner found nearly one-fifth of retailers and credit card processing services are not compliant with Payment Card Industry Data Security Standards.

Full Article

Tracking spending can be made easy with credit cards

06/12/2011

Many people feel that plastic payment processing options can lead to overspending, but a recent article published by Forbes explains that making payments with credit cards is actually a great way to control costs and track expenses.

Full Article

Keeping business bank accounts safe and secure

11/10/2011

The internet has provided consumers with many new and convenient ways to access their account information, but these advances have also created the need for thorough security measures.

Full Article

Personalized payment chips get fraud prevention upgrade

10/10/2011

Payment chips made by Fiserv will now be further personalized using the Europay MasterCard Visa (EMV) standards, a global credit card payments technology that helps prevent fraud from lost, stolen or counterfeit cards.

Full Article