By Jaikumar Vijayan
Excerpt:
The key takeaway from the hearing is that the time may have come "for some real oversight in the credit card industry" on how card data is secured, said Tom Kellerman, vice president of security awareness at Core Security Technologies, a security software vendor in Boston. "We saw PCI being challenged in a way it never has been," he said.
Kellerman, who was a member of a think-tank commission that issued a set of cybersecurity recommendations for the federal government in December, added that security standards should be based on actual threats, not on a consensus approach aimed at appeasing all stakeholders. And, he said, the credit card companies need to realize that merely transferring to merchants the risks and responsibilities associated with securing data won't cut it any longer.
Source: ComputerWorld











