« Beware Publicity-Seeking Security Gurus | Main | The Changing Security Threat Landscape »

The Long Road to PCI Compliance

There are always plenty of businesses that have to be dragged kicking and screaming to the compliance killing floor. So it’s no surprise to read a survey by The Logic Group that suggests that only ten percent of organisations are fully compliant with the mandatory PCI security standard.

Closer analysis of the figures, however, shows that retailers are well on their way to compliance. According to the survey, awareness levels are up to 100% from 85% last year and 45% the pervious year. And eight out of ten merchants have assessed the impact of the PCI standard on their business. It’s clearly a slow process and understandably so, as PCI DSS is a highly prescriptive and potentially expensive standard to meet. I could never envisage any streetwise retailer diving in and implementing all those measures without a careful scrutiny of the financial and operational impact and a good look sideways at what everyone else is doing.

Compliance is not an overnight activity. It requires a gap analysis, impact assessment, business case and a rectification programme. You can’t conjure new budgets and the necessary resources out of thin air. According to the Logic Group survey, three quarters of companies are committed to achieving PC compliance over the next 18 months. And of these more than 40% are already in the remediation stage.

There are always laggards, so it’s not surprising to that 6% admitted to not having yet started the journey. What will happen to them? That’s the really interesting question. It will be interesting to see what fines and sanctions will be applied.

TrackBack

TrackBack URL for this entry:
http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/11858

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on September 21, 2007 10:09 PM.

The previous post in this blog was Beware Publicity-Seeking Security Gurus.

The next post in this blog is The Changing Security Threat Landscape.

Many more can be found on the main index page or by looking through the archives.