The Payment Card Industry Data Security Standard (PCI) is an excellent set of security requirements with which all of the major Credit Card companies expect merchants to comply. It includes technological, operational, and physical security measures designed to keep credit cards secure. To avoid penalties and fines, merchants are required to validate their business practices to these standards, and by this time, many merchants have invested a huge amount of time, effort and money into their PCI Compliance programs. As a security company, we applaud any measure that causes retailers to investigate and remediate their security vulnerabilities. While the effectiveness of PCI as a security standard will be evaluated over time, it appears that many retailers cannot see the forest for all of the trees that are in the way.
PCI is a credit card security standard. It deals with protecting sensitive cardholder data. Other data such as the name on the credit card, expiration date or anything else which can be tied back the primary account number on the credit card is considered to be cardholder data as well, but the key is that for PCI to be concerned with any data in general, credit cards have to be involved.
Merchants are so concerned with validating their compliance to their acquiring bank or to the credit card companies directly, that we are seeing many of them ignore other gaps in their security because they are not in scope for PCI. With enough personal information, thieves can steal someone's identity. Many retailers, especially fast casual restaurants with a loyalty program, have the names, birth dates, home addresses and other sensitive data about their customers. We have even see retailers ask for social security numbers which they use as the "ID" number for their programs. This personal data is just as critical to protect as credit cards, but your bank will not be checking on that security.
Here is the ironic part, PCI is not a law. The credit card companies are attempting to self-regulate security without the intervention or supervision of the government. On the other hand, there are both federal and state laws that concern themselves with protecting sensitive personal information which could be used to perpetrate identity theft. In fact, it is more devastating to a patron to have a criminal take personal information and obtain illegal (but legitimate) credit cards through identity theft than to have fraudulent credit card purchases made from stolen credit card data. The cardholder has built-in protection from fraudulent purchases made on their credit cards, but an identity thief who has established numerous illegal credit cards, or purchased assets in someone's name can destroy the credit score of victim for years. It is not uncommon for some identity theft victims to spend several years in court trying to reclaim their good name and defend themselves against angry creditors.
While it is true that PCI only concerns itself with credit cards, as a merchant, think about security holistically if you want to protect your patrons. If you have sensitive data of any kind, protect it. The recent stories about the identity theft from New York and Georgia should be enough to convince anyone that this issue should be on the mind of everyone who collects sensitive data (even if your bank is not asking about it).
562
http://global.networldalliance.com/new/images/slideshows/show562_thumb8595.jpg
Order up: EMN8's self-order tech at Domino's, KFC India
Order up: EMN8's self-order tech at Domino's, KFC India
559
http://global.networldalliance.com/new/images/slideshows/show559_thumb8515.jpg
Naked Pizza thrives in Dubai
Naked Pizza thrives in Dubai
542
http://global.networldalliance.com/new/images/slideshows/show542_thumb8207.gif
Minsky's Pizza turns 37
Minsky's Pizza turns 37
537
http://global.networldalliance.com/new/images/slideshows/show537_thumb8119.gif
NAFEM 2013
NAFEM 2013
531
http://global.networldalliance.com/new/images/slideshows/show531_thumb8031.gif
Pizza chains' LTOs kick off 2013
Pizza chains' LTOs kick off 2013
512
http://global.networldalliance.com/new/images/slideshows/show512_thumb7713.gif
The Loop Pizza Grill new restaurant prototype
The Loop Pizza Grill new restaurant prototype
506
http://global.networldalliance.com/new/images/slideshows/show506_thumb7615.gif
Patxi's Pizza's new menu items
Patxi's Pizza's new menu items
505
http://global.networldalliance.com/new/images/slideshows/show505_thumb7583.jpg
4 technologies gaining ground in restaurant industry
4 technologies gaining ground in restaurant industry
495
http://global.networldalliance.com/new/images/slideshows/show495_thumb7351.gif
Boston Pizza's new menu
Boston Pizza's new menu
492
http://global.networldalliance.com/new/images/slideshows/show492_thumb7311.gif
September pizza launches
September pizza launches
Recipes
http://global.networldalliance.com/new/images/products/cubanmedianochepizza_100.jpg
1917/Recipes
Vital Link Point-of-Sale
http://global.networldalliance.com/new/images/products/4284.png
4284/Vital-Link-Point-of-Sale
Nationwide Criminal Records
http://global.networldalliance.com/new/images/products/Criminal_Search_iix.gif
1427/Nationwide-Criminal-Records
Restaurant technology news, trends & best practices
http://global.networldalliance.com/new/images/products/5079.png
5079/Restaurant-technology-news-trends-best-practices
FireFly Point-of-Sale
http://global.networldalliance.com/new/images/products/4282.png
4282/FireFly-Point-of-Sale
Low Cost ATM
http://global.networldalliance.com/new/images/products/RL2000_100.gif
1019/Low-Cost-ATM
Quote decoder: how to compare restaurant POS systems
http://global.networldalliance.com/new/images/products/1290.png
1290/Quote-decoder-how-to-compare-restaurant-POS-systems
DriverSafe
http://global.networldalliance.com/new/images/products/keyboard_iix.gif
1424/DriverSafe
ARGO - Touch Screen
http://global.networldalliance.com/new/images/products/6017.png
6017/ARGO-Touch-Screen
PCI Compliance Managed Network Services
http://global.networldalliance.com/new/images/products/4123.png
4123/PCI-Compliance-Managed-Network-Services
|
Inside Networld Media Group Network QSRWeb
|
Popular on Networld Media Group | Other Networld Media Group Sites | Global Partners |
User Comments