<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
    <title type="text">eSecurityDiva</title>
    
    <link rel="alternate" type="text/html" href="http://www.esecuritydiva.com/" />
    <id>tag:typepad.com,2003:weblog-1631774</id>
    <updated>2009-08-17T08:00:00-04:00</updated>
    <subtitle type="html">An Insider's Perspective</subtitle>
    <generator uri="http://www.typepad.com/">TypePad</generator>
    <link rel="self" href="http://feeds.feedburner.com/typepad/eSecurityDiva" type="application/atom+xml" /><feedburner:emailServiceId>typepad/eSecurityDiva</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><entry>
        <title>Focus on Security…and PCI Compliance Will Follow</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/eSecurityDiva/~3/ih6q66JNOhI/focus-on-securityand-pci-compliance-will-follow.html" />
        <link rel="replies" type="text/html" href="http://www.esecuritydiva.com/2009/08/focus-on-securityand-pci-compliance-will-follow.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e551f086aa88330120a4ef1c2f970b</id>
        <published>2009-08-17T08:00:00-04:00</published>
        <updated>2009-08-17T08:00:00-04:00</updated>
        <summary>While surfing LinkedIn recently, a user’s posted question caught my eye. The user, a small merchant, asked whether his approach to PCI compliance was the most cost-effective way possible. As his business was recently classified as a Level 4 merchant,...</summary>
        <author>
            <name>Joan</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="PCI Issues" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.esecuritydiva.com/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;While surfing &lt;strong&gt;LinkedIn&lt;/strong&gt; recently, a user’s posted question caught my eye.&lt;/p&gt;&lt;p&gt;The user, a small merchant, asked whether his approach to PCI compliance was the most cost-effective way possible. As his business was recently classified as a &lt;a href="http://usa.visa.com/merchants/risk_management/cisp_merchants.html" target="_blank" title="Level 4 merchant"&gt;Level 4 merchant&lt;/a&gt;, he said he needed only “focus on those areas where we may fall short.” He also said free or low-cost solutions might be the best option because while “not very user friendly,” they do “tick the right PCI boxes and get us PCI compliant.”   &lt;/p&gt;&lt;p&gt;The poster then went through several security measures he was considering, including internal scanning and file-integrity monitoring. “Or am I just wasting my time?” he asked.&lt;/p&gt;&lt;p&gt;Well, no. Anything you do to make your business more secure is a good thing.&lt;/p&gt;&lt;p&gt;But, as another LinkedIn user correctly pointed out, the merchant was asking the &lt;em&gt;wrong&lt;/em&gt; questions. &lt;/p&gt;&lt;p&gt;Instead of focusing on how to (and how much) it would take to better secure customer information, the merchant instead was laser-focused on simply becoming compliant.&lt;/p&gt;&lt;p&gt;&lt;a href="http://esecuritydiva.typepad.com/.a/6a00e551f086aa88330120a546330a970c-pi" style="float: left;"&gt;&lt;img alt="YellowBrickRoad" border="0" class="at-xid-6a00e551f086aa88330120a546330a970c " src="http://esecuritydiva.typepad.com/.a/6a00e551f086aa88330120a546330a970c-800wi" style="margin: 0px 5px 5px 0px;" title="YellowBrickRoad"&gt;&lt;/img&gt;&lt;/a&gt; This is the wrong approach, tactically and psychologically. The &lt;strong&gt;PCI Data Security Standard&lt;/strong&gt; is a way to validate basic data security. It’s not the Yellow Brick Road to Oz. It’s only a tool—a pretty good one—to help minimize danger along the way. &lt;/p&gt;&lt;p&gt;Neither I nor the other LinkedIn user, I’m sure, believes this merchant doesn’t care about the security of his customers. But the things the poster, and any merchant, should be focusing on first are the steps to improve the overall safety of cardholder data.&lt;/p&gt;&lt;p&gt;Steps like:&lt;/p&gt;&lt;ul&gt;&#xD;
&lt;li&gt;Using a &lt;strong&gt;compliant payment application&lt;/strong&gt;. You can &lt;a href="https://www.pcisecuritystandards.org/security_standards/vpa/vpa_approval_list.html" target="_blank" title="PCI compliant applications"&gt;access these applications here. &lt;/a&gt;&lt;/li&gt;&#xD;
&lt;li&gt;Securing transactions. All cardholder data must be encrypted during transmission.&lt;/li&gt;&#xD;
&lt;li&gt;Conducting regular &lt;strong&gt;Web application and vulnerability scans&lt;/strong&gt;. If you have externally-facing IP addresses, conduct regular scanning to identify critical vulnerabilities for remediation.&lt;/li&gt;&#xD;
&lt;li&gt;Setting cardholder data storage policies. Merchants should not electronically store credit card data without a compelling business reason.&lt;/li&gt;&#xD;
&lt;li&gt;Setting access policies. Employees who don’t need access to sensitive customer information should not be given access. &lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;As for the LinkedIn question, the reader who responded to the merchant’s post had a particularly valid point: “If you are worried about the cost (to become) PCI DSS compliant, check on the alternative. Be non-compliant when your system is compromised, then you will be talking about real money and possibly your company will go out of business.”&lt;/p&gt;&lt;p&gt;I couldn’t have said it better myself.&lt;/p&gt;&lt;p&gt;‘Till Next Time,&lt;/p&gt;&lt;p&gt;Joan&lt;br&gt;The eSecurityDiva&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=ih6q66JNOhI:xFrzLjffKNs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=ih6q66JNOhI:xFrzLjffKNs:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=ih6q66JNOhI:xFrzLjffKNs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=ih6q66JNOhI:xFrzLjffKNs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=ih6q66JNOhI:xFrzLjffKNs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=ih6q66JNOhI:xFrzLjffKNs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=ih6q66JNOhI:xFrzLjffKNs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=ih6q66JNOhI:xFrzLjffKNs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.esecuritydiva.com/2009/08/focus-on-securityand-pci-compliance-will-follow.html</feedburner:origLink></entry>
    <entry>
        <title>Study: Merchants Need Better Guidance on Security</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/eSecurityDiva/~3/cEwLxMUu5I8/study-merchants-need-better-guidance-on-security.html" />
        <link rel="replies" type="text/html" href="http://www.esecuritydiva.com/2009/08/study-merchants-need-better-guidance-on-security.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e551f086aa88330120a4d40d2f970b</id>
        <published>2009-08-10T07:00:00-04:00</published>
        <updated>2009-08-10T07:00:00-04:00</updated>
        <summary>If your store was breached, could you prove you were PCI compliant? In a new survey, 45 percent of small merchants who claimed to be PCI compliant said they did not have the documentation to support their Self Assessment Questionnaires....</summary>
        <author>
            <name>Joan</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="PCI Issues" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.esecuritydiva.com/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;If
your store was breached, could you prove you were PCI compliant?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;In
a new survey, &lt;strong&gt;45 percent&lt;/strong&gt; of small merchants who claimed to be PCI
compliant said they &lt;em&gt;did not&lt;/em&gt; have the documentation to support their Self Assessment
Questionnaires. This key statistic indicates that many merchants are just “going
through the motions” when it comes to becoming compliant with PCI guidelines.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;Thankfully,
the majority of these polled merchants were aware that PCI compliance was of
value in securing customer data. In addition, &lt;strong&gt;88 percent&lt;/strong&gt; of them said they
viewed data security as a “high” or “medium” priority. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;






&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;The
&lt;a href="https://www.controlscan.com/whitepapers/merchant_study_2009.php"&gt;report&lt;/a&gt;,
sponsored by my company, &lt;a href="http://www.controlscan.com/"&gt;ControlScan&lt;/a&gt;,
as well as the &lt;a href="http://www.nrf.com"&gt;National Retail Federation&lt;/a&gt; and
the &lt;a href="http://www.pciknowledgebase.com"&gt;PCI Knowledge Base&lt;/a&gt;, outlines
some surprising facts about small merchants’ attitudes toward data security and
provides recommended solutions to this crucial issue.&lt;/span&gt;&lt;/p&gt;



&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;A
key implication of the report: Acquirers, ISOs and other providers serving the
retail industry need to exercise more leadership and better guide merchants
along the path to PCI compliance.&lt;/span&gt;&lt;/p&gt;



&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;a href="http://esecuritydiva.typepad.com/.a/6a00e551f086aa88330120a4d409ae970b-pi" style="float: left;"&gt;&lt;img alt="Teacher-doris-day" class="at-xid-6a00e551f086aa88330120a4d409ae970b " src="http://esecuritydiva.typepad.com/.a/6a00e551f086aa88330120a4d409ae970b-320wi" style="margin: 0px 5px 5px 0px;" /&gt;&lt;/a&gt; Why
do these players need to do more? More than half of the 220 polled merchants
said they depend on their merchant banks and point-of-sale or
payment-application vendors for this knowledge. Also, while awareness of the PCI
standard is high among small merchants, the level of understanding about PCI
and how to comply is not. Of the merchants who said they were not PCI
compliant, the reasons cited included “don’t understand it”, “don’t have the
resources” and compliance is “too hard.”&lt;/span&gt;&lt;/p&gt;

&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;Most
merchants want to be more secure and PCI compliant, but they are confused about
how to go about doing it.&lt;/span&gt;&lt;/p&gt;



&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;But
don’t just take my word.&lt;/span&gt;&lt;/p&gt;





&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;“We
want to comply,” one survey taker said, “but we’re not IT gurus. Please educate
us and make it clear what we need to do.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;



&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;So…here
are a couple of things ISOs and acquirers can do—now—to help merchants protect credit
card data:&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-size: 10pt;"&gt;Loose the
   jargon! Explain to merchants in an easy-to-understand manner how to be
   more secure. Get tactical, provide the specific guidance small merchants
   need.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
  &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: 10pt;"&gt;Educate
   them on the very real risks of non compliance. Things like, 85 percent of
   all breaches occur at &lt;strong&gt;small businesses&lt;/strong&gt;. And that fines can reach up to
   &lt;strong&gt;$25,000&lt;/strong&gt; monthly until compliance is achieved.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
  &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;






&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;You can read the full report, “&lt;a href="https://www.controlscan.com/whitepapers/merchant_study_2009.php" target="_blank" title="PCI compliance research report"&gt;What Small
Merchants Know (and Don’t Know) about PCI Compliance&lt;/a&gt;”, here. &lt;/span&gt;&lt;/p&gt;




&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;I’ve
said this before. No measures will completely eliminate the threat of hackers.
As long as there is money to be had, hackers will always be there. Waiting.
Scheming. Evolving.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;



&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;Further,
we all know PCI compliance is not perfect. But I firmly believe that if we all
work a little harder—as a team—data security can improve substantially.&lt;/span&gt;&lt;/p&gt;
&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;&amp;#39;Till Next Time,&lt;/span&gt;&lt;/p&gt;
&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;Joan&lt;/span&gt;&lt;/p&gt;
&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt;"&gt;The eSecurityDiva&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=cEwLxMUu5I8:YpYP0cGy-lI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=cEwLxMUu5I8:YpYP0cGy-lI:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=cEwLxMUu5I8:YpYP0cGy-lI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=cEwLxMUu5I8:YpYP0cGy-lI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=cEwLxMUu5I8:YpYP0cGy-lI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=cEwLxMUu5I8:YpYP0cGy-lI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=cEwLxMUu5I8:YpYP0cGy-lI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=cEwLxMUu5I8:YpYP0cGy-lI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.esecuritydiva.com/2009/08/study-merchants-need-better-guidance-on-security.html</feedburner:origLink></entry>
    <entry>
        <title>What Happens in Vegas Will Be Everyone’s Business…If You’re a Retailer</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/eSecurityDiva/~3/Q_tXzrmauqU/what-happens-in-vegas-will-be-everyones-businessif-youre-a-retailer.html" />
        <link rel="replies" type="text/html" href="http://www.esecuritydiva.com/2009/07/what-happens-in-vegas-will-be-everyones-businessif-youre-a-retailer.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e551f086aa88330115712732a0970c</id>
        <published>2009-07-20T11:27:03-04:00</published>
        <updated>2009-07-20T11:33:54-04:00</updated>
        <summary>You’ve heard the saying. What happens in Vegas stays in Vegas. That might be true for vacationers. But thanks to a new Nevada law, merchants in that state won’t have it so easy: If you receive, transmit or store payment...</summary>
        <author>
            <name>Joan</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="PCI Issues" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.esecuritydiva.com/">&lt;p&gt;You’ve heard the saying. What happens in Vegas stays in Vegas. &lt;/p&gt;&lt;p&gt;That might be true for vacationers. But thanks to a new Nevada law, merchants in that state won’t have it so easy: If you receive, transmit or store payment card information, and you’re not PCI compliant next year, you’ll be breaking the law.&lt;/p&gt;&lt;p&gt;&lt;a href="http://esecuritydiva.typepad.com/.a/6a00e551f086aa88330115721b9ed7970b-pi" style="float: left;"&gt;&lt;img alt="Nevada-welcome" border="0" class="at-xid-6a00e551f086aa88330115721b9ed7970b image-full " src="http://esecuritydiva.typepad.com/.a/6a00e551f086aa88330115721b9ed7970b-800wi" style="margin: 0px 5px 5px 0px; width: 352px; height: 298px;" title="Nevada-welcome"&gt;&lt;/img&gt;&lt;/a&gt; Yes, Nevada has become the first state to legislate full &lt;strong&gt;PCI Data Security Standard&lt;/strong&gt; compliance. Only Minnesota’s 2007 law, which involves a small portion of PCI rules, comes close. California and other “progressive” states haven’t even touched this; they’ve only passed breach notification laws or other less strict data privacy laws.&lt;/p&gt;&lt;p&gt;If you’re a merchant in Nevada, the effect is obvious. Comply or face additional penalties on top of those imposed by credit card brands. Plus, the new law, &lt;a href="http://leg.state.nv.us/75th2009/Bills/SB/SB227_EN.pdf" target="_blank" title="Nevada's PCI law"&gt;SB 227&lt;/a&gt;, among other things, particularly mandates the encryption of transmitted customer data between entities. (PCI DSS already requires this, by the way).&lt;/p&gt;&lt;p&gt;If you don’t do business in the Silver State, the effect could be the same. That’s because many experts, with good reason, predict &lt;a href="http://www.bankinfosecurity.com/articles.php?art_id=1599" target="_blank"&gt;other states will follow suit&lt;/a&gt;. Time and time again, states have followed California’s lead on similar issues.&lt;/p&gt;&lt;p&gt;Whether you like PCI DSS or not, or government regulation on this issue, there are some serious questions to think about. &lt;/p&gt;&lt;p&gt;What happens if 50 different states pass 50 different PCI-related laws? That could be rather confusing, cumbersome…and expensive. At least with &lt;strong&gt;Sarbanes-Oxley&lt;/strong&gt;, a controversial accounting oversight law, it’s federal. That means one rule. In 50 states.&lt;/p&gt;&lt;p&gt;Also, the &lt;strong&gt;PCI Security Standards Council&lt;/strong&gt; went through a thorough process to come up with its rules. Some experts such as &lt;strong&gt;David Taylor&lt;/strong&gt;, founder of the &lt;a href="http://www.pciknowledgebase.com/" target="_blank" title="PCI Knowledge Base"&gt;PCI Knowledge Base&lt;/a&gt;, worry that state legislators will not go through the same processes. In a recent blog post, Taylor laments the fact that the Nevada law makes a point to add encryption…when it was already included in PCI rules. (Further, encryption itself is hardly standardized.)&lt;/p&gt;&lt;p&gt;“This is more proof that government organizations should not be writing technically-detailed security legislation,” &lt;a href="http://www.storefrontbacktalk.com/securityfraud/can-the-government-be-sued-for-plagiarizing-pci-dss/" target="_blank"&gt;Taylor writes&lt;/a&gt;. He continues: “Since security legislation does not have to go through such as process, I remain skeptical that state, federal or international legislation can improve on what PCI DSS already provides in terms of technical detail.”&lt;/p&gt;&lt;p&gt;I also wonder how strictly, if at all, these state laws will be enforced. Other things to consider—will Nevada’s upcoming law, and other PCI-related laws, actually put a dent in fraud? &lt;/p&gt;&lt;p&gt;Quoted in &lt;a href="http://www.bankinfosecurity.com" target="_blank"&gt;BankInfoSecurity.com&lt;/a&gt;, &lt;strong&gt;Tom Wills&lt;/strong&gt;, a senior analyst for &lt;strong&gt;Javelin Strategy and Research&lt;/strong&gt;, says Nevada’s interest is a step in a right direction. But, ultimately, “I don’t expect fraud to drop significantly because of it—until we see a strong educational push,” he says.&lt;/p&gt;&lt;p&gt;Bottom line, legislation might spread the wrong belief that PCI compliance is the absolute goal. As I’ve said several times in this blog, PCI compliance is only a point-in-time measurement. Security is an ongoing process.&lt;/p&gt;&lt;p&gt;I hope our state legislators have a firm grasp of this concept when they tackle this very important issue.&lt;/p&gt;&lt;p&gt;Till Next Time,&lt;/p&gt;&lt;p&gt;Joan,&lt;br&gt;The eSecurityDiva&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Q_tXzrmauqU:ODzZTxboJ2I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Q_tXzrmauqU:ODzZTxboJ2I:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Q_tXzrmauqU:ODzZTxboJ2I:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Q_tXzrmauqU:ODzZTxboJ2I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=Q_tXzrmauqU:ODzZTxboJ2I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Q_tXzrmauqU:ODzZTxboJ2I:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Q_tXzrmauqU:ODzZTxboJ2I:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=Q_tXzrmauqU:ODzZTxboJ2I:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.esecuritydiva.com/2009/07/what-happens-in-vegas-will-be-everyones-businessif-youre-a-retailer.html</feedburner:origLink></entry>
    <entry>
        <title>Tired of Shopping Cart Abandonment?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/eSecurityDiva/~3/nqFbv_e164U/tired-of-shopping-cart-abandonment.html" />
        <link rel="replies" type="text/html" href="http://www.esecuritydiva.com/2009/06/tired-of-shopping-cart-abandonment.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e551f086aa88330115706ee6c1970c</id>
        <published>2009-06-29T08:00:00-04:00</published>
        <updated>2009-06-29T08:00:00-04:00</updated>
        <summary>If you’ve tracked visits to your ecommerce site lately, you’ve likely noticed that as many as half of your shoppers got cold feet at the last minute…right before the part where they were supposed to click “Pay Now.” Known as...</summary>
        <author>
            <name>Joan</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Merchandising" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.esecuritydiva.com/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;If you’ve tracked visits to your ecommerce site lately, you’ve likely noticed that as many as half of your shoppers got cold feet at the last minute…right before the part where they were supposed to click “Pay Now.”&lt;/p&gt;&lt;p&gt;Known as &lt;strong&gt;shopping cart abandonment&lt;/strong&gt;, it’s a major issue that ecommerce technology companies and consultants are tackling.   &lt;/p&gt;&lt;p&gt;The reasons are plenty why a shopper would go through the effort to fill his or her cart and then bail out. Uncertainty of the economy is likely one major cause. A horse racing fan would be happy to find, say, a bronze replica of &lt;a href="http://www.ntra.com/stats_bios.aspx?id=35663" target="_blank" title="Mine That Bird"&gt;Mine That Bird&lt;/a&gt;, the 2009 &lt;strong&gt;Kentucky Derby&lt;/strong&gt; winner, on your site. But then things like sales quotas and job security come to mind. Your shopper then becomes just a visitor.&lt;/p&gt;&lt;p&gt;Well, according to a &lt;a href="http://www.webpronews.com/topnews/2009/06/23/online-shoppers-wary-of-high-shipping-costs" target="_blank" title="PayPal / comScore ecommerce report"&gt;new ecommerce report&lt;/a&gt; by &lt;strong&gt;PayPal&lt;/strong&gt; and &lt;strong&gt;comScore&lt;/strong&gt;, the No. 1 reason for abandoned carts is &lt;strong&gt;sticker shock&lt;/strong&gt;. Not on the product itself but on the cost to ship that product. In a poll &lt;a href="http://esecuritydiva.typepad.com/.a/6a00e551f086aa88330115706ee856970c-pi" style="float: left;"&gt;&lt;img alt="Shopping cart" border="0" class="at-xid-6a00e551f086aa88330115706ee856970c " src="http://esecuritydiva.typepad.com/.a/6a00e551f086aa88330115706ee856970c-800wi" style="margin: 0px 5px 5px 0px; width: 383px; height: 246px;" title="Shopping cart"&gt;&lt;/img&gt;&lt;/a&gt;of U.S. consumers, 45 percent said they had abandoned an order at the last minute because of higher-than-expected shipping fees.&lt;/p&gt;&lt;p&gt;So what’s a solution to this? The report indicates that 40 percent of those people who cited shipping costs as the No. 1 reason would not have abandoned the purchase if the retailer had provided shipping fees upfront. Transparency is key here, folks.&lt;/p&gt;&lt;p&gt;Another reason why shoppers bail, the study says, is concern over &lt;strong&gt;credit card security&lt;/strong&gt;—21 percent. &lt;/p&gt;&lt;p&gt;What does that mean in dollars? According to a &lt;a href="http://www.javelinstrategy.com/2009/03/17/survey-finds-retailers-missed-out-on-21-billion-in-sales-in-2008-due-to-online-shopping-fears/" target="_blank" title="Fear of identitity theft"&gt;March report&lt;/a&gt; by &lt;strong&gt;Javelin Strategy &amp;amp; Research&lt;/strong&gt;, this fear equated to &lt;strong&gt;$21 billion&lt;/strong&gt; in lost sales in 2008! That’s a lot of abandoned carts. &lt;/p&gt;&lt;p&gt;Nothing will eliminate this fear because it’s based in reality. Identity theft and credit card fraud are growing exponentially. And so are the headlines of data breaches.&lt;/p&gt;&lt;p&gt;But there are steps you can take to decrease shopping cart abandonment and increase shopper confidence:&lt;/p&gt;&lt;ul&gt;&#xD;
&lt;li&gt;Go through the effort to get your site scanned for security and PCI compliance. Make sure you address any known vulnerabilities immediately.  And work with your PCI vendor to ensure that scans are conducting regularly, at least weekly.&lt;/li&gt;&#xD;
&lt;li&gt;Display the security seal you earned proudly. &lt;/li&gt;&#xD;
&lt;li&gt;Make your contact information prominent. And provide an address. Your prospects want to feel as if you’re a real company with a real locale. Not some faceless store in the netherworld of virtual space.&lt;/li&gt;&#xD;
&lt;li&gt;Make your privacy policy prominent too. Communicate clearly that you won’t be using your prospects’ info for anything other than processing their orders. &lt;/li&gt;&#xD;
&lt;li&gt;Provide product reviews if applicable. When a shopper sees customer reviews, there is just something real they bring to the table. Reviews convey a sense of community…and hence a feeling of security.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;You can’t do much about the economy part—36 percent of respondents said “&lt;strong&gt;lack of money&lt;/strong&gt;” was the primary reason for changing their minds. But with a little work, you can do a lot to inspire more confidence. &lt;/p&gt;&lt;p&gt;‘Till Next Time,&lt;/p&gt;&lt;p&gt;Joan,&lt;br&gt;The eSecurityDiva&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=nqFbv_e164U:RHEMGpVA0Yo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=nqFbv_e164U:RHEMGpVA0Yo:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=nqFbv_e164U:RHEMGpVA0Yo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=nqFbv_e164U:RHEMGpVA0Yo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=nqFbv_e164U:RHEMGpVA0Yo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=nqFbv_e164U:RHEMGpVA0Yo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=nqFbv_e164U:RHEMGpVA0Yo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=nqFbv_e164U:RHEMGpVA0Yo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.esecuritydiva.com/2009/06/tired-of-shopping-cart-abandonment.html</feedburner:origLink></entry>
    <entry>
        <title>Batteries.com Breach: Headaches All Around</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/eSecurityDiva/~3/Dm6CN5oHUcs/batteriescom-breach-headaches-all-around.html" />
        <link rel="replies" type="text/html" href="http://www.esecuritydiva.com/2009/06/batteriescom-breach-headaches-all-around.html" thr:count="2" thr:updated="2009-06-27T23:07:29-04:00" />
        <id>tag:typepad.com,2003:post-68139107</id>
        <published>2009-06-16T09:00:00-04:00</published>
        <updated>2009-06-16T09:00:00-04:00</updated>
        <summary>The recent breach of online retailer Batteries.com may have escaped your attention. The Indiana-based company, according to a few reports, issued a letter to officials in New Hampshire indicating that hackers penetrated the Batteries.com network over a period of two...</summary>
        <author>
            <name>Joan</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Breaches" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.esecuritydiva.com/">&lt;p&gt;The recent breach of online retailer &lt;a href="http://www.batteries.com"&gt;Batteries.com&lt;/a&gt; may have escaped your attention.&lt;/p&gt;&lt;p&gt;The Indiana-based company, according to a few reports, issued &lt;a href="http://doj.nh.gov/consumer/pdf/batteries.pdf" target="_blank" title="Letter from Batteries.com to New Hampshire"&gt;a letter&lt;/a&gt; to officials in &lt;strong&gt;New Hampshire &lt;/strong&gt;indicating that hackers penetrated the Batteries.com network over a period of two months from February to April 2009. In the letter, the company indicated that 865 residents of New Hampshire had been victimized. Stolen data included customer names, addresses and credit card details. &lt;/p&gt;&lt;p&gt;Some of that data, Batteries.com says, was used for fraudulent purposes.&lt;/p&gt;&lt;p&gt;Information has yet to be released on how many victims there are outside of New Hampshire. But I don’t think a hacker would have a grudge only against residents of the “Live Free or Die” state. It’s safe to assume many more customers’ identities and credit card accounts have been affected.&lt;/p&gt;&lt;p&gt;Those customers will undoubtedly suffer severe headaches. Dealing with credit card companies. Credit bureaus. Banks. Automated phone systems. Paperwork. The list goes on.&lt;/p&gt;&lt;p&gt;One alleged Batteries.com customer on &lt;a href="http://slashdot.org/submission/1006739/Batteriescom-massive-credit-card-security-breach" target="_blank" title="Batteries.com customer"&gt;this message board&lt;/a&gt; said he had “thousands of charges” on his credit card from someone in the United Kingdom. &lt;/p&gt;&lt;p&gt;“(I)t looks like the operation is very sophisticated,” the poster says. “Some of the charges occurred within 1 second of each other and must have been automated because one of the companies, British Airways, indicated that they do not permit an airline ticket to be purchased by somebody and paid for by somebody else, and the card ‘looked’ like it was issued in the UK…I suspect thousands of other victims are seeing charges on their cards too.”&lt;/p&gt;&lt;p&gt;But Batteries.com, and any other merchant who is hacked like this, will also suffer severe headaches. First of all, the company will be issuing two years of free credit monitoring services to victims. Second, how many of these victims are likely to shop at Batteries.com again? And what about negative press coverage?&lt;/p&gt;&lt;p&gt;Further, can you imagine the amount of costly and time-consuming forensics work that goes into determining the details of two months worth of hackings? &lt;/p&gt;&lt;p&gt;&lt;a href="http://esecuritydiva.typepad.com/.a/6a00e551f086aa883301157021252c970c-pi" style="float: left;"&gt;&lt;img alt="Home_forensics" border="0" class="at-xid-6a00e551f086aa883301157021252c970c image-full " src="http://esecuritydiva.typepad.com/.a/6a00e551f086aa883301157021252c970c-800wi" style="margin: 0px 5px 5px 0px; width: 590px; height: 300px;" title="Home_forensics"&gt;&lt;/img&gt;&lt;/a&gt; As a merchant, if you are breached like this, you’ll pay a forensics auditor &lt;strong&gt;$250 an hour&lt;/strong&gt; to spend days—many times several weeks—to pour through your “log” files, which register all events on your network. These auditors will conduct “reverse engineering” and scour your network for all sorts of data, such as if any users accessed your network from unusual locations. If your log files have been compromised, or not backed up properly, the process can even take longer. &lt;/p&gt;&lt;p&gt;An IT forensics audit is so complex that &lt;strong&gt;Visa&lt;/strong&gt; has certified only seven vendors as “&lt;a href="http://usa.visa.com/download/merchants/cisp_qualified_cisp_incident_response_assessors_list.pdf" target="_blank" title="Visa assesor list"&gt;qualified incident response assessors&lt;/a&gt;.” (The data gathered during these audits, by the way, help companies such as &lt;strong&gt;Verizon Business&lt;/strong&gt;, one of the seven assessors, publish &lt;a href="http://74.125.95.132/search?q=cache:oCgrWYJwYuYJ:www.verizonbusiness.com/resources/security/databreachreport.pdf+2008+verizon+breach+report&amp;amp;cd=1&amp;amp;hl=en&amp;amp;ct=clnk&amp;amp;gl=us&amp;amp;client=firefox-a" target="_blank" title="Verizon Breach Report"&gt;great breach reports like this&lt;/a&gt;.)&lt;/p&gt;&lt;p&gt;An IT forensics audit, in many ways, is similar to a homicide forensics exam. But an IT audit can cost you &lt;strong&gt;$20,000&lt;/strong&gt; or more when it’s all said and done. &lt;/p&gt;&lt;p&gt;That may be good news for Visa’s qualified assessors. But for small merchants, a massive breach can be devastating. &lt;/p&gt;&lt;p&gt;‘Til Next Time,&lt;/p&gt;&lt;p&gt;Joan&lt;br&gt;The eSecurityDiva.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Dm6CN5oHUcs:BUM3w1CNYVA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Dm6CN5oHUcs:BUM3w1CNYVA:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Dm6CN5oHUcs:BUM3w1CNYVA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Dm6CN5oHUcs:BUM3w1CNYVA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=Dm6CN5oHUcs:BUM3w1CNYVA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Dm6CN5oHUcs:BUM3w1CNYVA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Dm6CN5oHUcs:BUM3w1CNYVA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=Dm6CN5oHUcs:BUM3w1CNYVA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.esecuritydiva.com/2009/06/batteriescom-breach-headaches-all-around.html</feedburner:origLink></entry>
    <entry>
        <title>When it Comes to PCI Compliance, You Need a Partner</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/eSecurityDiva/~3/Fke-jskFUy4/when-it-comes-to-pci-compliance-you-need-a-partner.html" />
        <link rel="replies" type="text/html" href="http://www.esecuritydiva.com/2009/06/when-it-comes-to-pci-compliance-you-need-a-partner.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-67513899</id>
        <published>2009-06-03T12:27:26-04:00</published>
        <updated>2009-06-03T12:27:11-04:00</updated>
        <summary>As Payment Card Industry deadlines come and go, I’ve noticed a rash of acquiring banks, card processors, ISOs AND vendors jumping into the mix to get a piece of the compliance pie fees. So, what does this mean for small-...</summary>
        <author>
            <name>Joan</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="PCI Issues" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.esecuritydiva.com/">&lt;p&gt;As&lt;a href="https://www.pcisecuritystandards.org/" target="_blank"&gt; Payment Card Industry&lt;/a&gt; deadlines come and go, I’ve noticed a rash of acquiring banks, card processors, ISOs AND vendors jumping into the mix to get a piece of the compliance pie fees.&lt;/p&gt;&lt;p&gt;So, what does this mean for small- or medium-sized merchants? Well, this influx does show that companies of all walks are becoming more aware of security and PCI compliance. That is good. &lt;/p&gt;&lt;p&gt;But the influx also means plenty of opportunities for questionable practices that may not serve to improve the true state of security with the best interest of the merchants. That is not good. &lt;/p&gt;&lt;p&gt;Becoming PCI compliant is a daunting task for any merchant, especially small merchants. Whether you’re a merchant or an acquirer, you should learn more about security and PCI before selecting a compliance partner. You should also beware of simply going with the vendor who offers the lowest fees. Understand what you can expect from the PCI vendor and make sure the result is a more secure business.&lt;/p&gt;&lt;p&gt;Despite the inherent complexities surrounding PCI compliance, we’ve all seen ill-conceived  programs that don’t provide the most basic of services or support to merchants. Some don’t even provide a basic education in PCI. Bottom line, smaller merchants need real help with becoming—and staying—compliant. &lt;/p&gt;&lt;p&gt;After all, no one wins if you get fined. Or worse, breached.&lt;/p&gt;&lt;p&gt;Which makes me think. What is really driving this behavior? Is it to protect shoppers’ payment card data? Is it to minimally satisfy the card brands’ mandates? Or is it to create an incremental revenue stream? &lt;/p&gt;&lt;p&gt;Can these drivers co-exist…or are they mutually exclusive?&lt;/p&gt;&lt;p&gt;Some recent trends suggest to me that it will take a while for the PCI market to shake out. Merchants and acquirers will eventually grow wise to shoddy activity and will gravitate toward quality PCI-compliance services. Unfortunately, in the meantime, not enough is being done to truly advance increased security for small merchants.  &lt;/p&gt;&lt;p&gt;&lt;a href="http://esecuritydiva.typepad.com/.a/6a00e551f086aa8833011570bbe4d2970b-pi" style="float: left;"&gt;&lt;img alt="Pendulum1-101.jpg903f08b0-f0dd-43c1-8f53-e70d6eb43793Large" border="0" class="at-xid-6a00e551f086aa8833011570bbe4d2970b " src="http://esecuritydiva.typepad.com/.a/6a00e551f086aa8833011570bbe4d2970b-800wi" style="margin: 0px 5px 5px 0px; width: 272px; height: 229px;" title="Pendulum1-101.jpg903f08b0-f0dd-43c1-8f53-e70d6eb43793Large"&gt;&lt;/img&gt;&lt;/a&gt; Congress is aware of this, as we’ve seen with the &lt;a href="http://www.homeland.house.gov/hearings/index.asp?ID=185" target="_blank"&gt;recent PCI hearings&lt;/a&gt;. As the pendulum tilts toward more regulation on everything from carbon emissions to debt lending, this lack of true security improvements could ultimately lead to Congress legislating compliance—which the PCI Council has been diligently working at to avoid.&lt;/p&gt;&lt;p&gt;Worse, these trends will hurt your efforts to become PCI compliant, which will ultimately leave your shoppers more exposed to hackers and data thieves. &lt;/p&gt;&lt;p&gt;As the new PCI market begins to mature, having the right partners will help you stay compliant in the most efficient manner possible. Having the right partners will also ensure you’re not being taken advantage of.&lt;/p&gt;&lt;p&gt;‘Til Next Time,&lt;/p&gt;&lt;p&gt;Joan&lt;br&gt;The eSecurity Diva&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Fke-jskFUy4:Fi3208XBczY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Fke-jskFUy4:Fi3208XBczY:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Fke-jskFUy4:Fi3208XBczY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Fke-jskFUy4:Fi3208XBczY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=Fke-jskFUy4:Fi3208XBczY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Fke-jskFUy4:Fi3208XBczY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=Fke-jskFUy4:Fi3208XBczY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=Fke-jskFUy4:Fi3208XBczY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.esecuritydiva.com/2009/06/when-it-comes-to-pci-compliance-you-need-a-partner.html</feedburner:origLink></entry>
    <entry>
        <title>More Has to Be Done to Enhance Security. But What?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/eSecurityDiva/~3/IUzk69CdFKM/more-has-to-be-done-to-enhance-security-but-what.html" />
        <link rel="replies" type="text/html" href="http://www.esecuritydiva.com/2009/05/more-has-to-be-done-to-enhance-security-but-what.html" thr:count="1" thr:updated="2009-06-27T23:10:34-04:00" />
        <id>tag:typepad.com,2003:post-66366669</id>
        <published>2009-05-05T09:00:00-04:00</published>
        <updated>2009-05-05T09:00:00-04:00</updated>
        <summary>If you read about the recent Congressional PCI hearings, you know just being PCI compliant doesn’t equal security. PCI compliance is only a point-in-time measurement. So…what’s a small- or medium-sized merchant to do? After all, the PCI compliance process can...</summary>
        <author>
            <name>Joan</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.esecuritydiva.com/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;If you read about the &lt;a href="http://blogs.verisign.com/securityconvergence/2009/03/review_of_pci_congressional_he.php" target="_blank"&gt;recent Congressional PCI hearings&lt;/a&gt;, you know just being PCI compliant doesn’t equal security. PCI compliance is only a point-in-time measurement.&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;So…what’s a small- or medium-sized merchant to do? &lt;/p&gt;&lt;p&gt;After all, the PCI compliance process can be challenging enough. But now, it’s become crystal clear that retailers, even the smallest of ones, have to make sure they’re going above and beyond what the credit card companies mandate.&lt;/p&gt;&lt;p&gt;&lt;a href="http://esecuritydiva.typepad.com/.a/6a00e551f086aa88330115706d7cd8970b-pi" style="float: left;"&gt;&lt;img alt="Card-swipe-small" class="at-xid-6a00e551f086aa88330115706d7cd8970b " src="http://esecuritydiva.typepad.com/.a/6a00e551f086aa88330115706d7cd8970b-120wi" style="margin: 0px 5px 5px 0px; width: 131px; height: 186px;"&gt;&lt;/img&gt;&lt;/a&gt; Remember the &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=336907&amp;amp;intsrc=news_ts_head" target="_blank"&gt;Hannaford Bros. breach&lt;/a&gt; last year? Hannaford was certified PCI compliant by a third-party assessor—one day after the grocer was notified of massive system intrusions that had occurred months prior. The likely cause? The hackers’ malware intercepted data on magnetic strips as they were swiped by customers. &lt;/p&gt;&lt;p&gt;That doesn’t mean PCI compliance is worthless. Not by a long shot. In fact, &lt;strong&gt;Visa &lt;/strong&gt;maintains that no company suffering a breach has been proven to be PCI compliant at the time of the compromise. It’s important to remember that PCI security standards are industry best practices that have protected tens of thousands of merchants—and cardholders—against malicious behavior.  &lt;/p&gt;&lt;p&gt; But these standards still have room for improvement. &lt;a href="https://www.pcisecuritystandards.org/" target="_blank"&gt;The PCI Security Standards Council &lt;/a&gt;is continuously seeking feedback from merchants, processors and other industry stakeholders on ways to strengthen the standard. To this end, the council has recently commissioned a study on emerging technologies that could further protect cardholder data.  &lt;/p&gt;&lt;p&gt;The PCI data security standards, according to a recent report by the &lt;strong&gt;Society of Payment Security Professionals&lt;/strong&gt;, “must be recognized for what (they are)—a tool in the protection of data rather than the last line of defense.”&lt;/p&gt;&lt;p&gt;I know it’s easy to put security on a lower priority list, especially if you’re a small retailer. But if you are a smaller retailer, you’re a bigger target. That’s because savvy hackers know you have fewer resources on hand, including money and time, and are often running older, unsecure payment application versions.&lt;/p&gt;&lt;p&gt;And trust me, it’s well worth your money and time to take security seriously. If a breach has been detected in your system, you may be responsible for:&lt;/p&gt;&lt;ul&gt;&#xD;
&lt;li&gt;A “forensics” examination, which can cost $10,000 or more, according to&lt;a href="http://www.pcicomplianceguide.org" target="_blank"&gt; www.pcicomplianceguide.org.&lt;/a&gt;&lt;/li&gt;&#xD;
&lt;li&gt;Between $5,000 to $50,000 (or more) in compliance fines.&lt;/li&gt;&#xD;
&lt;li&gt;Legal fees.&lt;/li&gt;&#xD;
&lt;li&gt;Up to $10 per card for replacement.&lt;/li&gt;&#xD;
&lt;li&gt;Complying with breach notification state laws as applicable.&lt;/li&gt;&#xD;
&lt;li&gt;Restoring your customers’ confidence.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;Total costs for a breached “Level 4” merchant, or those processing fewer than 20,000 e-commerce transactions annually and all other merchants processing up to a million transactions, average $36,000 and may be catastrophic for small businesses.&lt;/p&gt;&lt;p&gt;So, what can you do to prevent the hassles and potential business killers of a breach? First, let’s address a few things smaller merchants must do to become compliant:&lt;/p&gt;&lt;ul&gt;&#xD;
&lt;li&gt;Complete an annual Self Assessment Questionnaire.&lt;/li&gt;&#xD;
&lt;li&gt;Pass quarterly vulnerability scans (merchants with externally facing IP addresses).&lt;/li&gt;&#xD;
&lt;li&gt;Develop in-house information security policies.&lt;/li&gt;&#xD;
&lt;li&gt;Launch security awareness training for you and your employees.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;Don’t approach PCI compliance with a “check-the-box” mentality. Use it as an opportunity to maintain a high security posture and make it part of your daily routine.  Remember, defending against criminals is not a one-time event, it’s perpetual.  &lt;/p&gt;&lt;p&gt;Of course, the burden shouldn’t be completely up to retailers. Banks, processors, gateways, credit card companies and security providers all have to do a better job at coming up with new methodologies, technologies and education programs to help you better protect your business and your customers’ important information. &lt;/p&gt;&lt;p&gt;Congress agrees.&lt;/p&gt;&lt;p&gt;At the hearing, a number of suggestions came up, including the need for the United States to adopt encrypted PIN technology and smarter credit cards. For years, several European countries have been using chip cards, which have small computer processors on them. Chip technology can protect against “skimming,” which involves the copying of private information from the magnetic stripe. A chip, on the other hand, cannot be copied.&lt;/p&gt;&lt;p&gt;According to &lt;strong&gt;Rep. Yvette Clarke&lt;/strong&gt;, chairwoman of the subcommittee that held the hearing, such technologies can help reduce incidences by nearly &lt;strong&gt;70 percent&lt;/strong&gt;!&lt;/p&gt;&lt;p&gt;Here are some other steps advocated by the &lt;a href="https://www.paymentsecuritypros.com/" target="_blank"&gt;Society of Payment Security Professionals&lt;/a&gt;: &lt;/p&gt;&lt;ul&gt;&#xD;
&lt;li&gt;The reduction of sensitive data storage. The less crucial data you have on premise, the less data can be stolen.&lt;/li&gt;&#xD;
&lt;li&gt;The adoption of a more structured IT governance program. This would push us from a system of simple compliance to “real security.”&lt;/li&gt;&#xD;
&lt;li&gt;The deployment of a more collaborative approach to address security issues. By sharing information, new security issues and fixes will arise.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;I want to hear from you. What needs to be done to improve the PCI compliance process? How can &lt;a href="http://www.controlscan.com" target="_blank"&gt;ControlScan&lt;/a&gt; help educate you on what you need to do to become PCI compliant? And what can be done to improve security at our nation’s retailers?&lt;/p&gt;&lt;p&gt;Until Next Time,&lt;/p&gt;&lt;p&gt;Joan,&lt;br&gt;The eSecurityDiva&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=IUzk69CdFKM:32yorkP8MWM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=IUzk69CdFKM:32yorkP8MWM:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=IUzk69CdFKM:32yorkP8MWM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=IUzk69CdFKM:32yorkP8MWM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=IUzk69CdFKM:32yorkP8MWM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=IUzk69CdFKM:32yorkP8MWM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=IUzk69CdFKM:32yorkP8MWM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=IUzk69CdFKM:32yorkP8MWM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.esecuritydiva.com/2009/05/more-has-to-be-done-to-enhance-security-but-what.html</feedburner:origLink></entry>
    <entry>
        <title>Choosing the Best Hosting Provider for Your Website</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/eSecurityDiva/~3/cIwUoVkV2mM/choosing-the-best-hosting-provider-for-your-website.html" />
        <link rel="replies" type="text/html" href="http://www.esecuritydiva.com/2009/05/choosing-the-best-hosting-provider-for-your-website.html" thr:count="1" thr:updated="2009-06-04T06:31:07-04:00" />
        <id>tag:typepad.com,2003:post-66340049</id>
        <published>2009-05-04T07:45:43-04:00</published>
        <updated>2009-05-04T07:45:15-04:00</updated>
        <summary>We talk to thousands of small merchants each month. Their questions span many topics, but we’re often asked if we can provide any guidance in helping a small merchant select a hosting provider. Our customers are looking for a provider...</summary>
        <author>
            <name>Joan</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Industry News" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Other" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="PCI Issues" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Securing Transactions" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.esecuritydiva.com/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p style="margin-bottom: 0.0001pt; line-height: normal; font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt;We
talk to thousands of small merchants each month.&lt;span&gt;&amp;#0160; &lt;/span&gt;Their questions span many topics, but we’re
often asked if we can provide any guidance in helping a small merchant select a
hosting provider.&lt;span&gt;&amp;#0160; &lt;/span&gt;Our customers are
looking for a provider who will meet their specific business needs &lt;em&gt;and&lt;/em&gt; offer a cost-effective&amp;#0160; solution.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0.0001pt; line-height: normal; font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt;&lt;a href="https://www.controlscan.com/about_team.php#david" target="_blank"&gt;David Abouchar&lt;/a&gt;, senior director of product management at ControlScan, recently led a
podcast on this&amp;#0160; topic. In the podcast,&lt;a href="https://www.controlscan.com/podcasts/choose_best_hosting_provider.php" target="_blank"&gt; &lt;/a&gt;&lt;a href="https://www.controlscan.com/podcasts/choose_best_hosting_provider.php" target="_blank"&gt;&amp;quot;Tips to Choosing the Best Hosting
Provider for your Website&amp;quot;&lt;/a&gt;, David gave insight into the kind of questions you
should ask and the level of support you should expect when choosing a hosting
provider.&amp;#0160; A few of the key takeaways that I think you’ll find helpful are:&lt;/span&gt;&lt;/p&gt;&lt;ul style="font-family: inherit;"&gt;&lt;li&gt;Anticipate your Website traffic and how you will be processing credit cards first so you can determine the right hosting plan.&lt;/li&gt;
&lt;li&gt;Decide whether or not you will need managed or unmanaged services based on your technical resources.&lt;/li&gt;
&lt;li&gt;The level of support is a key consideration. Know up front how and when support will be available to you.&lt;/li&gt;
&lt;li&gt;Use your resources. Ask your Web designer and other vendors for referrals.&lt;/li&gt;
&lt;li&gt;Be sure to review the agreement and contract terms in detail &lt;em&gt;before&lt;/em&gt; your final selection. Know which services covered in the base services agreement and which are not.&lt;/li&gt;
&lt;li&gt;Make sure the hosting provider you select is PCI compliant as this will greatly simplify your own PCI compliance process.&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0.0001pt; line-height: normal; font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt;To learn more about choosing a hosting provider, check out the podcast
by visiting &lt;a href="https://www.controlscan.com/podcasts/choose_best_hosting_provider.php"&gt;https://www.controlscan.com/podcasts/choose_best_hosting_provider.php&lt;/a&gt;.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0.0001pt; line-height: normal; font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0.0001pt; line-height: normal; font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt;&amp;#39;Til next time,&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0.0001pt; line-height: normal; font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt;Joan&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0.0001pt; line-height: normal; font-size: 10px; font-family: Arial;"&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt;&lt;p style="font-size: 12px; font-family: Arial;"&gt;The eSecurity Diva&lt;/p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0.0001pt; line-height: normal; font-size: 10px; font-family: Arial;"&gt;&lt;a href="https://www.controlscan.com/podcasts/choose_best_hosting_provider.php"&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;/a&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0.0001pt; line-height: normal; font-size: 10px; font-family: Arial;"&gt;&lt;br /&gt;&lt;span style="font-size: 10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p style="font-size: 10px; line-height: 115%; font-family: Arial;"&gt;.&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Arial;"&gt;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Arial;"&gt;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Arial;"&gt;&lt;/p&gt;&lt;p style="font-size: 12px; line-height: 115%; font-family: Arial;"&gt;&lt;/p&gt;&lt;p style="font-size: 12px; line-height: 115%; font-family: Arial;"&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=cIwUoVkV2mM:sq0nnTdo6fQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=cIwUoVkV2mM:sq0nnTdo6fQ:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=cIwUoVkV2mM:sq0nnTdo6fQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=cIwUoVkV2mM:sq0nnTdo6fQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=cIwUoVkV2mM:sq0nnTdo6fQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=cIwUoVkV2mM:sq0nnTdo6fQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=cIwUoVkV2mM:sq0nnTdo6fQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=cIwUoVkV2mM:sq0nnTdo6fQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.esecuritydiva.com/2009/05/choosing-the-best-hosting-provider-for-your-website.html</feedburner:origLink></entry>
    <entry>
        <title>Congress: If You’re Just PCI Compliant, You’re Not Secure</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/eSecurityDiva/~3/R6FiMU0fJi0/congress-if-youre-just-pci-compliant-youre-not-secure.html" />
        <link rel="replies" type="text/html" href="http://www.esecuritydiva.com/2009/04/congress-if-youre-just-pci-compliant-youre-not-secure.html" thr:count="2" thr:updated="2009-04-30T20:08:03-04:00" />
        <id>tag:typepad.com,2003:post-65146195</id>
        <published>2009-04-06T16:01:34-04:00</published>
        <updated>2009-04-06T16:01:34-04:00</updated>
        <summary>Is regulation coming to a point-of-sale device near you? It certainly appears so. At least if the credit card ecosystem—banks, processors, security companies, assessors and retailers—doesn’t do more to ensure consumer transactions are safer. Last week, Congress held hearings designed...</summary>
        <author>
            <name>Joan</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Industry News" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.esecuritydiva.com/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Is regulation coming to a point-of-sale device near you?&lt;/p&gt;&lt;p&gt;&lt;a href="http://esecuritydiva.typepad.com/.a/6a00e551f086aa883301156efcbf0c970c-pi" style="float: left;"&gt;&lt;img alt="Cards" border="0" class="at-xid-6a00e551f086aa883301156efcbf0c970c " height="251" src="http://esecuritydiva.typepad.com/.a/6a00e551f086aa883301156efcbf0c970c-800wi" style="margin: 0px 5px 5px 0px;" title="Cards" width="291"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
 It certainly appears so. At least if the credit card ecosystem—banks, processors, security companies, assessors and retailers—doesn’t do more to ensure consumer transactions are safer.&lt;/p&gt;&lt;p&gt;Last week, Congress held &lt;a href="http://www.homeland.house.gov/hearings/index.asp?ID=185" target="_blank"&gt;hearings&lt;/a&gt; designed to get to the bottom of what is being done, and what can be done, to help stem the tide of cyber fraud and identity theft. It left little to debate. More has to be done. Now. &lt;/p&gt;&lt;p&gt;Bottom line, said a no-nonsense &lt;strong&gt;Rep. Yvette Clarke&lt;/strong&gt;, chairwoman of the subcommittee that held the hearing, just being PCI compliant does not guarantee security. &lt;/p&gt;&lt;p&gt;Clarke said a recent investigation found PCI standards are of “questionable strength and effectiveness.” As a result, she warned, retailers need to take proactive measures to protect themselves and their consumers. She also said new security technologies and practices are needed—ASAP:&lt;/p&gt;&lt;p&gt;“The time for waiting is over. The time for shifting risk is over. Today, the responsibility is yours to make this situation better.”&lt;/p&gt;&lt;p&gt;Clarke spoke those words to a panel consisting of high-ranking representatives from the &lt;strong&gt;Department of Justice&lt;/strong&gt;, the &lt;a href="https://www.pcisecuritystandards.org/" target="_blank"&gt;PCI Security Standards Council&lt;/a&gt;, &lt;strong&gt;Visa&lt;/strong&gt;, &lt;strong&gt;Michaels Stores&lt;/strong&gt; and the &lt;strong&gt;National Retail Federation&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;For a change, it certainly appeared to me that our elected officials got it. And I also think the panel did an excellent job delivering a down-and-dirty assessment of the strengths, limits and dangers of our current security compliance system. Even if they did shift blame a little.&lt;/p&gt;&lt;p&gt;I think we all can appreciate just how vulnerable we are when &lt;strong&gt;Rep. Dan Lungren&lt;/strong&gt;, vice chair of the committee, admitted his family was recently a victim of credit card fraud. He was particularly peeved at how he was informed: Embarrassingly, at a restaurant, when the waiter said his card wasn’t working. When Lungren called the credit card company, it didn’t have any information other than his account had been “compromised.”&lt;/p&gt;&lt;p&gt;Talk about more work to be done. If this can happen to Lungren, it can happen to anyone. &lt;/p&gt;&lt;p&gt;The PCI Council’s &lt;strong&gt;Robert Russo&lt;/strong&gt; said his organization’s standards are solid. The challenge is that the council doesn’t enforce standards. That’s up to the credit card brands and the banks/processors. Many companies also approach PCI with a checking-the-box mentality. PCI compliance should be viewed as an opportunity to build solid security best practices for long term security versus point in time security. Visa’s &lt;strong&gt;Joseph Majka&lt;/strong&gt;, meanwhile, said the credit card company never found a breached company to not be in compliance with PCI standards. &lt;/p&gt;&lt;p&gt;Regardless of these testimonials, data security standards need some work, said &lt;strong&gt;Michael Jones&lt;/strong&gt;, CIO of Michaels Stores, who delivered a no-holds barred critique on the PCI compliance process. These standards were “set up for the credit card companies and banks to have all the power over fines and mandates,” Jones testified. “It is not an industry standards body.”&lt;/p&gt;&lt;p&gt;He continues: “We would be more secure…if the credit card companies would take more responsibility.”&lt;/p&gt;&lt;p&gt;Jones’ concerns: The inconsistencies, confusion, high cost and ambiguity in data security standards. Not to mention the credit card monopoly that controls these standards. While there is some debate over his particular issues, I agree PCI standards need to be much better. I also agree more responsibility can be shared. The retailer, after a breach, is left holding the bag. The retailer is demonized in the press. And it is often the one hit with fines.&lt;/p&gt;&lt;p&gt;We can debate the fine points of Jones’ concerns all we want. But it’s clear the United States is lagging behind. And it’s also clear retailers’ systems need to be better protected. While several European countries have enacted stricter and smarter standards, regulations and technologies, fraud has decreased in those countries. However, it is increasing globally, chairman Clarke points out. Why is this? Because hackers are taking advantage of countries with weaker technologies and security practices. &lt;/p&gt;&lt;p&gt;In other words, countries such as the United States. Of course, we must all keep in mind that the European countries' new technologies have much fewer companies to worry about versus the United States.&lt;/p&gt;&lt;p&gt;In a coming post, I will lay out some best practices specifically focused on small merchants. In the meantime, the seriousness of the situation cannot be underestimated. Not only are U.S. retailers the means of which more hackers are becoming rich, but U.S. retailers are also the means of which terrorists are financing their murderous activities. &lt;/p&gt;&lt;p&gt;Clarke reminded the panel that the 2002 Bali nightclub bomber financed his &lt;a href="http://en.wikipedia.org/wiki/2002_Bali_bombings" target="_blank"&gt;mission&lt;/a&gt; with credit card fraud. &lt;/p&gt;&lt;p&gt;Terrorists are clearly on the hunt for cyber vulnerabilities. &lt;/p&gt;&lt;p&gt;They could find that next vulnerability in your system.&lt;/p&gt;&lt;p&gt;Until next time,&lt;/p&gt;&lt;p&gt;Joan&lt;br&gt;The eSecurityDiva&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=R6FiMU0fJi0:GdmHoQXcWV4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=R6FiMU0fJi0:GdmHoQXcWV4:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=R6FiMU0fJi0:GdmHoQXcWV4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=R6FiMU0fJi0:GdmHoQXcWV4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=R6FiMU0fJi0:GdmHoQXcWV4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=R6FiMU0fJi0:GdmHoQXcWV4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=R6FiMU0fJi0:GdmHoQXcWV4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=R6FiMU0fJi0:GdmHoQXcWV4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.esecuritydiva.com/2009/04/congress-if-youre-just-pci-compliant-youre-not-secure.html</feedburner:origLink></entry>
    <entry>
        <title>The Greatest Threat to Retail Security Lies Within</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/eSecurityDiva/~3/negK7VfrgNE/the-greatest-threat-to-retail-security-lies-within.html" />
        <link rel="replies" type="text/html" href="http://www.esecuritydiva.com/2009/03/the-greatest-threat-to-retail-security-lies-within.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-64622695</id>
        <published>2009-03-25T15:47:04-04:00</published>
        <updated>2009-03-25T16:22:56-04:00</updated>
        <summary>In the best of times, retailers know that theft is a matter of when, not if. In times like these, well, you can only imagine that the threat is amplified. Some estimates show retail theft soaring 20 percent over the...</summary>
        <author>
            <name>Joan</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Other" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.esecuritydiva.com/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;In the best of times, retailers know that theft is a matter of when, not if.&lt;/p&gt;&lt;p&gt;In times like these, well, you can only imagine that the threat is amplified. Some estimates show retail theft soaring 20 percent over the past six months or so. For a small retailer, a 20 percent increase can be a death knell. It’s a serious increase even for the &lt;strong&gt;Wal-Mart&lt;/strong&gt;s of the world.&lt;/p&gt;&lt;p&gt;&lt;em&gt;But before you cast an overly-cautious eye at the next customer who comes in, you may want to look within first. &lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://esecuritydiva.typepad.com/.a/6a00e551f086aa883301156f53d41b970b-pi" style="float: left;"&gt;&lt;img alt="Shulman" class="at-xid-6a00e551f086aa883301156f53d41b970b " src="http://esecuritydiva.typepad.com/.a/6a00e551f086aa883301156f53d41b970b-120wi" style="margin: 0px 5px 5px 0px;"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
 I recently had a chance to talk to &lt;strong&gt;Terrence Shulman&lt;/strong&gt;, head of the &lt;a href="http://www.theshulmancenter.com/" target="_blank"&gt;Shulman Center for Compulsive Theft and Spending&lt;/a&gt;. Companies a year ago—before the credit meltdown—he says, were losing $50 billion annually from employee theft. Shoplifting, meanwhile, accounted for $15 billion to $20 billion—&lt;strong&gt;60 percent less!&lt;/strong&gt; Worse, Shulman says, shoplifters usually don’t habitually frequent the same locales. Employees, on the other hand, are there everyday. And on average, it takes 18 months to catch a thieving employee.&lt;/p&gt;&lt;p&gt;“It’s hard to live in an environment where you can’t trust anybody,” Shulman says. “But we all need universal precautions. Especially today.”&lt;/p&gt;&lt;p&gt;Shulman, author of “&lt;a href="http://www.bitingthehandthatfeeds.com/" target="_blank"&gt;Biting the Hand That Feeds: The Employee Theft Epidemic&lt;/a&gt;,” is a therapist who helps people who are addicted to everything from shoplifting to credit card fraud. Oh, and in case you were wondering, he really knows what he’s talking about: He’s a former compulsive thief. He was even arrested—twice—for his crimes.&lt;/p&gt;&lt;p&gt;&lt;a href="http://esecuritydiva.typepad.com/.a/6a00e551f086aa883301156f53cec4970b-pi" style="float: right;"&gt;&lt;img alt="Cuffed" border="0" class="at-xid-6a00e551f086aa883301156f53cec4970b " src="http://esecuritydiva.typepad.com/.a/6a00e551f086aa883301156f53cec4970b-800wi" style="margin: 0px 0px 5px 5px;" title="Cuffed"&gt;&lt;/img&gt;&lt;/a&gt;&#xD;
 We talked about steps retailers can take to lessen employee theft. We also talked about the psychology of employee theft. After all, you can better prevent problems if you better understand them.&lt;/p&gt;&lt;p&gt;Yes, theft is up due to the bad economy. When people have less money, they steal more. &lt;/p&gt;&lt;p&gt;However, employee theft is also driven by anger at their perspective employers, not necessarily by a feeling of financial necessity. Lack of respect is a big driver, he says. Another driver is having their hours or benefits cut, or having increased responsibilities levied on them with no increased compensation. &lt;/p&gt;&lt;p&gt;Anger at the current business and political climate is also a factor. Many employees, he explains, see the headlines of “fat cat execs” getting million-dollar bonuses, while their failed companies are getting bailed out by U.S. taxpayers. This is leading to an “entitlement environment” in which some employees feel they deserve more than they really do, because others—such as bank CEOs, &lt;strong&gt;AIG&lt;/strong&gt; execs, certain politicians, and even &lt;strong&gt;Bernie Madoff&lt;/strong&gt;—are rolling in money they don’t deserve, Shulman says. &lt;/p&gt;&lt;p&gt;These feelings can manifest in stealing money, merchandise or even identities.&lt;/p&gt;&lt;p&gt;“People are beginning to think differently about ethics,” Shulman says. “They are increasingly thinking that life is not fair, that nobody is honest. When you’re working hard, and when you’re only criticized and not rewarded, this thinking increases. It might start off small. Like lying on a time card. Or taking office supplies home. Little by little, the seeds are planted.”&lt;/p&gt;&lt;p&gt;He continues: “They’re thinking, ‘Why should I be busting my butt for so little?’ It creeps in even with people of integrity. Over time, it becomes addictive.”&lt;/p&gt;&lt;p&gt;Which leads to how to decrease the probability that you will become a victim:&lt;/p&gt;&lt;ul&gt;&#xD;
&lt;li&gt;Conduct background checks on prospective employees.&lt;/li&gt;&#xD;
&lt;li&gt;Look into “honesty assessment” tests. &lt;/li&gt;&#xD;
&lt;li&gt;Require letters of reference.&lt;/li&gt;&#xD;
&lt;li&gt;Set up a probationary period for new employees. So not to make them feel like they’re under suspicion, make sure the policy is applied to everyone. &lt;/li&gt;&#xD;
&lt;li&gt;Consider technologies such as more advanced &lt;strong&gt;cameras&lt;/strong&gt;, &lt;strong&gt;RFID&lt;/strong&gt; and &lt;strong&gt;barcoded timecards&lt;/strong&gt;.&lt;/li&gt;&#xD;
&lt;li&gt;Conduct random audits to limit embezzlement.&lt;/li&gt;&#xD;
&lt;li&gt;If a theft does occur, &lt;strong&gt;prosecute&lt;/strong&gt;. It may be tempting to forego the hassles of prosecution, but you’ll send a message to other employees. And you may actually help the thief out. Going to jail may be the catalyst that affects change in his or her life, Shulman says.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;But perhaps the most important tip: Don’t forget the “&lt;strong&gt;human element&lt;/strong&gt;.” Trust your intuition when interviewing a prospective employee. We can rely on all the technology in the world. But in the end, human instinct is often the most powerful tool in detecting—and preventing—bad behavior.&lt;/p&gt;&lt;p&gt;And…once you’ve hired an employee, treat him or her well! Employees who are respected by their employers are less apt to steal, Shulman says. Further, having happier employees may actually lead to less customer shoplifting. That’s because shoplifters often commit their crimes on a whim, perhaps when confronted by a rude or complacent employee. Happy employees are simply less apt to be rude or complacent.&lt;/p&gt;&lt;p&gt;And since we’re on the topic of the human element, watch the bottom-line instinct when confronted by decreasing revenue. The first thing many retailers do when facing financial pressures is to cut back on employees' hours. But this can actually cause increased opportunities for customer theft because there will be fewer eyes.&lt;/p&gt;&lt;p&gt;I’ll leave you with a few sobering and optimistic figures. According to Shulman, about 30 percent of retail employees will steal regardless of what you do; it’s just in them. However, 30 percent also will &lt;em&gt;never&lt;/em&gt; steal, due to their good ethics. That leaves &lt;strong&gt;40 percent&lt;/strong&gt; that you can affect…&lt;/p&gt;&lt;p&gt;Positively or negatively.&lt;/p&gt;&lt;p&gt;Until next time,&lt;/p&gt;&lt;p&gt;Joan,&lt;/p&gt;&lt;p&gt;The eSecurityDiva&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=negK7VfrgNE:up1J39atfgI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=negK7VfrgNE:up1J39atfgI:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=negK7VfrgNE:up1J39atfgI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=negK7VfrgNE:up1J39atfgI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=negK7VfrgNE:up1J39atfgI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=negK7VfrgNE:up1J39atfgI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?a=negK7VfrgNE:up1J39atfgI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/typepad/eSecurityDiva?i=negK7VfrgNE:up1J39atfgI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://www.esecuritydiva.com/2009/03/the-greatest-threat-to-retail-security-lies-within.html</feedburner:origLink></entry>
 
</feed><!-- ph=1 --><!-- nhm:from_kauri -->
