iTnews
  • Home
  • News
  • Technology
  • Security

Visa risk chief: Reports of PCI's death exaggerated

By Dan Kaplan on Mar 20, 2009 11:55AM

Visa's top risk official has defended payment industry security guidelines, but also called on organisations to invest in constant monitoring, information sharing and new technology -- while not letting the sour economy get in the way of security spending.

Visa's top risk official has defended payment industry security guidelines, but also called on organisations to invest in constant monitoring, information sharing and new technology -- while not letting the sour economy get in the way of security spending.

"Recent rumblings about the demise of the [Payment Card Industry Data Security Standard] are not only premature, they are dangerous to long-term security," Ellen Richey, Visa's chief enterprise risk officer, said during her keynote address at the Visa Security Summit in Washington, D.C. "Despite recent negative commentary, the PCI DSS remains an effective security tool when implemented properly. Simply put, it is the best defense against data theft available today."

At the start of her talk, Richey referred to Heartland Payment Systems, which disclosed a monster breach in January. She told attendees to consider this an exception, not the rule.

The New Jersey payment processor had been validated as PCI DSS-compliant when hackers installed data-sniffing malware on the company's internal network. This resulted in some industry observers questioning the effectiveness of the guidelines. Visa later pulled Heartland from its list of PCI DSS-approved service providers.

"I'm sure everyone in this room has read the headlines questioning how an event of this magnitude could still happen today," she said, according to a transcript of her speech. "The fact is, it never should have...As we've all read, [Heartland] had validated PCI compliance. But it was the lack of ongoing vigilance in maintaining compliance that left the company vulnerable to attack."

Richey told the audience that the country's current dismal financial state may pose more of a threat to payment security than hackers. She called on the audience to "increase our presence as educators and advocates for data security."

"If we cannot convey the urgent need to maintain investments in payment security -- particularly in today's environment -- years of progress in building consumer trust could slip through our fingers," she said.

In addition, she urged businesses to provide ways that customers can protect themselves from fraud. Law enforcement, processors, legislators and merchants, meanwhile, must increase their levels of information sharing.

Finally, Richey said investment must be made in new payment authentication measures, such as chip technology, so that the data criminals may steal becomes worthless. She mentioned measures being taken at financial institutions such as Fifth Third Bank, which uses unique magnetic stripes that can be used to verify the identity of the card being used.

Avivah Litan, vice president and distinguished analyst at Gartner, said it was important to hear that Richey realises the challenge of securing data will require new technology and an upgrade of the payment system to include things such as end-to-end encryption.

"I was glad to see Visa so progressive to admit they have to move beyond the PCI security standard, even though she didn't say that explicitly," Litan, who hosted a panel at the event, told SCMagazineUS.com.

See original article on scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
dsspciricheysecurityvisa

Partner Content

Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Promoted Content Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Security: Understanding the fundamentals of governance, risk & compliance
Promoted Content Security: Understanding the fundamentals of governance, risk & compliance
Avoiding CAPEX by making on-premise IT more cloud-like
Promoted Content Avoiding CAPEX by making on-premise IT more cloud-like
Why Genworth Australia embraced low-code software development
Promoted Content Why Genworth Australia embraced low-code software development

Sponsored Whitepapers

Free eBook: Digital Transformation 101 – for banks
Free eBook: Digital Transformation 101 – for banks
Why financial services need to tackle their Middle Office
Why financial services need to tackle their Middle Office
Learn: The latest way to transfer files between customers
Learn: The latest way to transfer files between customers
Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see

Events

  • Forrester Technology & Innovation Asia Pacific 2022
By Dan Kaplan
Mar 20 2009
11:55AM
0 Comments

Related Articles

  • Visa pilots enumeration attack prevention requirement in Australia
  • Smartphone payments for public transport can be abused to make unlimited purchases
  • Twitter says zero-day bug leaked account data
  • Android apps are invasive and unsafe: study
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Telstra deregisters 900MHz sites “hindering” Optus 5G rollout

Telstra deregisters 900MHz sites “hindering” Optus 5G rollout

Aussie Broadband nears end of NBN PoI fibre rollout

Aussie Broadband nears end of NBN PoI fibre rollout

Defence, DEWR drop $160m on Microsoft software, Azure

Defence, DEWR drop $160m on Microsoft software, Azure

Transport for NSW exits Global Switch data centre

Transport for NSW exits Global Switch data centre

Digital Nation

Case Study: Swinburne University overhauls student management system
Case Study: Swinburne University overhauls student management system
Case Study: Multicloud business drivers at MLC Life Insurance
Case Study: Multicloud business drivers at MLC Life Insurance
COVER STORY: What happens when Google changes its algorithm?
COVER STORY: What happens when Google changes its algorithm?
Personalisation strategies need to be built from the ground up
Personalisation strategies need to be built from the ground up
COVER STORY: Multiple cloud models make security more complex
COVER STORY: Multiple cloud models make security more complex
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.