This is cache of http://blogs.forrester.com/srm/2008/03/the-hannaford-p.html. Cache is the snapshot of article that we took when we index feed.
To see original page click here.
We are not affiliated with the authors of this article and not responsible for its content.
The Hannaford PCI Fallout
2008-03-28 13:07:12 by Marc Othersen in Security & Risk Management
 

By now, most people have heard about the data breach at Hannaford. Here are some thoughts regarding potential fallout:

1) PCI standard may change. Much depends on Hannaford disclosing the control failures leading to the data breach. The standard may be strengthened to address control areas that may have been overlooked. Should the controls that failed not be part of the current PCI standard, they will most likely be added in the future. Should the controls already exist in the standard, they may be re-written for clarity or greater implementation details may be needed.

2) PCI compliance auditors may be scrutinized. It is unclear at this point in time if the methodology used by Hannaford’s auditors was inadequate. The payment card industry may re-evaluate its criteria for certification and impose more stringent requirements. They may follow in the footsteps of the PCAOB and release audit guidelines to increase the consistency of compliance audits.

3) Lawsuits abound. Cardholders may form a class action lawsuit against Hannaford for failing to protect their information. Hannaford may sue its PCI auditors for damages caused by inadequate audits.

4) Organizations may want a second opinion. Organizations governed by PCI may, in the short term, pay for additional reviews of their controls from sources other than their normal PCI auditors in order to gain further assurance they have effective controls in place. PCI audit and consulting companies may see a dramatic short term increase in business.

 
 
 
 
 
 
TOP SEARCH
Expand / MinimizeClose Widget
  •  
RECENT SEARCH
Expand / Minimize
  •  
RELATED VIDEO
Expand / Minimize
SecurityRatty FAQ
Sergey Zarubin, 31yo
CISSP, CCSP
Moscow, Russia