PCI to assess the assessors

By
Follow google news

The Payment Card Industry Security Standards Council (PCI SSC) has announced a new programme designed to improve consistency.

PCI to assess the assessors
The Payment Card Industry Security Standards Council (PCI SSC) today announced a new programme designed to improve consistency among qualified security assessors tasked with determining the compliance status of organisations affected by PCI.

The initiative will give Qualified Security Assessors and Approved Scanning Vendors a set of requirements to comply with if they want to retain the ability to conduct PCI assessments.

Bob Russo, general manager of the PCI SSC, explained that the programme will complement the current training and strict applications vetting process.

"This is the next evolutionary cycle, and we wanted to take things a bit further by looking at the reports [the assessors generate]," he said. "This quality assurance programme is because there are now so many assessors out there, not because we've had any complaints about them."

The organisations which perform the majority of PCI assessments will be assessed every year, while those which are less prolific will go through the cycle every two or three years, unless a complaint is lodged against them. In this case they will jump to the head of the queue, said Russo.
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:

Most Read Articles

Optus takes $826,000 hit for anti-scam breaches

Optus takes $826,000 hit for anti-scam breaches

Australia's AUKUS base to connect to subsea cables

Australia's AUKUS base to connect to subsea cables

Australia, US and UK sanction Russian cyber firms over ransomware links

Australia, US and UK sanction Russian cyber firms over ransomware links

JPMorgan, Citi, Morgan Stanley client data may be exposed by vendor's hack

JPMorgan, Citi, Morgan Stanley client data may be exposed by vendor's hack

Log In

  |  Forgot your password?