Sunday | 20 July, 2008
Computerworld

Auditor warns: Beware of security vendors selling PCI compliance
Cybertrust and Cisco jump on the bandwagon
Michael Crawford 22/01/2007 14:31:20

Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    When Egos Dare 05/06/2007 10:17:02

    For some observers and practitioners, the federated model brings the best elements of centralization and decentralization to the IT table. Others aren’t so sure . . .
    The monarch was dead. Demoralized and shaken, the organization spent time mourning for a popular and high-profile CIO who had reigned for many years. Then, with time starting to dull the pain, the young princes began sharpening their knives, sensing their best opportunity in years to seize power
  • +

    Strategies for Dealing With IT Complexity 24/12/2007 10:30:47

    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
  • +

    Close Fast, Close Smart 26/02/2007 11:24:37

    When it comes to closing the books, the benefits of speed are undeniable. And CIOs are uniquely positioned to help their organizations reap them
    As long as they're meeting their regulatory reporting deadlines, most enterprises don't think a lot about closing their books more quickly.

    Maybe they should start.

    Increasingly, the speed with which an organization closes its books and reports its financial results is being looked at by practitioners, analysts and investors as a defining metric for evaluating whether the organization possesses the best possible processes and enabling technologies. And it turns out that many companies don't, even those making huge IT investments and supporting equally large IT departments.
  • +

    Taking a Systems View 07/02/2007 14:15:18

    Too many organizations are measuring the new with the old. A growing number of experts say the management methods of the manufacturing age are outdated and need to be replaced by metrics that measure the value of the intangible assets that make up organizational capital
    Talk about perverse consequences. BP sets out to slash 25 percent of its fixed costs and ends up killing 15 workers and injuring 180 others, in the worst industrial accident in the US in 15 years.
  • +

    What Price Innovation? 05/11/2007 13:44:31

    CIOs say they want more than the traditional “your mess for less” relationship with their outsourcing providers. And the providers want to market themselves as partners in innovation. So why isn’t it happening?
    CIOs say they want more than the traditional "your mess for less" relationship with their outsourcing providers. And the providers want to market themselves as partners in innovation. So why isn't it happening?
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualization technologies, products, news and features.
RSS Feeds

Customers beware when buying an approved Payment Card Industry Data Security Standard (PCIDSS) solution. It may be approved but implementing the solution doesn't mean customers are immediately compliant, according to a PCIDSS accredited auditor.

Drazen Drazic, managing director of auditing firm Security-Assessment.com, said customers shouldn't assume they are compliant simply because they have purchased an approved PCIDSS solution.

The standard was introduced in 2004 to ensure retailers are responsible for cardholder data or risk facing fines of more than $500,000.

Drazic's comments follow the launch of a number of merchant retail solutions that address PCI compliance.

It is the selling point for a new retail solution jointly released by security heavyweights Cybertrust and Cisco Systems last week.

According to a press release, Cisco will provide audited network architectures tailored to individual stores under the mandate and Cybertrust will validate the gear as PCI compliant.

Cybertrust is an approved assessor for the PCI DSS for American Express, MasterCard and Visa. Cisco provides approval under the Cisco Secure Store Program, which offers both the PCI Solution for Retail and a Digital Video Surveillance solution.

According to Cisco, the Digital Video Surveillance solution includes "human and automated video surveillance, and reduces retail shrink through improved loss prevention capabilities".

However, Cisco did not confirm whether the surveillance solution is part of the accreditation for PCI compliance, or an additional feature.

Cisco did not respond to repeated attempts by Computerworld to clarify how its solution complies with PCIDSS.

Drazic said using a solution from an approved assessor doesn't automatically make a company compliant.

He said some vendors are using PCI compliance to try and sell product.

"Like products from any other reputable vendor, it's how you implement, manage and maintain those systems that is the key; simply implementing this product doesn't make you compliant," Drazic said.

"Do you need to throw away what you have now? No way if it is working. Do you need to consider these offerings? Possibly, but it shouldn't be different to any other purchase.

"This is an interesting approach by Cisco and CyberTrust to make inroads into what is becoming a potentially lucrative market, and the PCI name is becoming a selling point. Is there anything really new about this solution aside from the PCI name? I doubt it."

Despite repeated attempts to get Cisco and CyberTrust to respond to these claims and clarify their partnership, both companies did not respond.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Beyond Virtualisation - The Roadmap to 2012

CIO Breakfast Briefing
8:30am - 10:30am

Brisbane | 22 July | Sofitel Brisbane
Sydney | 23 July | Four Seasons Hotel
Canberra | 24 July | The Hyatt

Attend and discover:

  • What happens after virtualisation
  • The benefits automation drives
  • When automated infrastructures will emerge
  • What the roadmap to 2012 looks like
  • How to deliver an automated architecture
  • How to maximise your investment in virtualisation
Whitepaper

Supercharging Aurora Energy's Core Business Applications

HP TestDirector & WinRunner offer business process savings, operational efficiencies and productivity gains. Discover how by reading on.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links