Businesses still unaware of risks of account data compromise

Benj Hosack · Computer Fraud & Security · 2011

PCI DSS and PA-DSS are helping to secure card payment processing and reduce fraud but data compromise remains a significant problem in the financial services sector. In nearly all cases, a compromised business will have rogue cardholder data that it was not aware existed in its systems. Should a criminal identify a flaw in security and gain access to this unprotected data, the compromised entity would find itself in a very difficult situation with regard to forensic investigations, remediation costs, card schemes fines and fraud losses. Benj Hosack of Foregenix examines the issues and offers guidance. In 2004, the Payment Card Industry Data Security Standard (PCI DSS) was announced as a set of security controls based on best practice and designed to protect cardholder data against the rising levels of fraud on credit cards. Formed initially by the card schemes (Visa, MasterCard, AMEX, JCB, Diners and Discover), the PCI DSS is now managed, maintained and developed by the PCI Security Standards Council (PCI SSC).

Read the paper · More papers on PaperTik