Mastering PCI-DSS - It's All About Changing Your Ways
Michael Dahn posted on the PCI Blog - Compliance Demystified about the recent discussions about the industry cost of PCI compliance. Both he and Walt Conway make important points about the key question being "Why is the cost of compliance so high?" and suggest that mastering PCI compliance is as much about defining scope down through business process changes as anything else. Walt writes: "Who said you have to keep doing things the same way as before? PCI is a great opportunity to actually reduce the institution's risk not by protecting CHD and all personally identifiable information (PII), but by getting rid of it."






Add your comment... (note that all comments are reviewed before they're published)