AP: Weak Security Opens Door To Credit Card Hacks

Stock quotes in this article: IT , TJX  

Visa's head of global data security, Eduardo Perez, said the company scaled back its records review because it took too much work and because the PCI standards have improved the industry's security "considerably."

"I think we've made a lot of progress," he said. "While there have been a few large compromises, there are many more compromises we feel we've helped prevent by driving these minimum requirements."

Representatives for MasterCard, American Express, Discover and JCB — which, along with Visa, steer PCI policy — either didn't return messages from the AP or directed questions to the PCI security council.

PCI's general manager, Bob Russo, said inspector certification is "rigorous." Yet he also acknowledged that inconsistent audits are a problem — and that merchants and payment processors who suffered data breaches possibly shouldn't have been PCI-certified. Those companies also might have easily fallen out of compliance after their inspection, by not installing the proper security updates, and nobody noticed.

The council is trying to crack down on shoddy work by requiring annual audits for the dozen companies that do the bulk of the PCI inspections. Smaller firms will be examined once every three years.

  • Loading Comments...
  •  

SHARE:

  • email
  • print
  • comment
  • digg
  • delicious
  • linkedin

Recent Comments





Connect with TheStreet

Dow Jones S&P 500 NASDAQ 10-Year Note
10,441.12 1,109.18 2,206.91 35.96
Oil *
73.55
DOWN
10.88
UP
1.25
UP
5.86
DOWN
0.07
10 Yr
3.60%
SPDR Gold
111.59
-0.10%
+0.11%
+0.27%
-0.19%
Data delayed 20 minutes

More From TheStreet

Latest Headlines

Brokerage Partners

TheStreet Premium Services

All Services