Find White Papers
Home
About Us
List Your Papers
    
> Tripwire > PCI Compliance: Are UK Businesses Ready?

PCI Compliance: Are UK Businesses Ready?

White Paper Published By: Tripwire

As the UK faces its first real deadline for PCI compliance, a recent survey indicates that attitudes toward PCI compliance and misperceptions of actual compliance status may lead to compliance troubles for many UK organizations. Learn more about the survey results and how the right attitudes and technical controls can change that outlook.



Tags : 
tripwire, pci compliance, pci dss, it security, auditing, compliance, internet security, data protection

Tripwire
Published:  Apr 28, 2010
Type:  White Paper
Length:  9 pages

PCI Compliance:
Are UK Businesses Ready?
WHITE PAPERExecutive Summary
The Payment Card Industry Data Security Standard (PCI KEY FINDINGSDSS), one of the most prescriptive data protection stan-dards ever developed, addresses the ever-increasing threats . Only 12% of United Kingdom (UK) organizations pro-to customer cardholder data by requiring security controls cessing credit and debit cardholder data are currently for the cardholder data environment. As a pass/fail regula- certified as being PCI compliant.tion, organizations must pass each and every one of the . While 58% of Level 1 merchants have been audited and 214 requirements to be certified as PCI compliant. In 2010, certified as compliant, that falls to 6%, 8% and 4% for almost three years after the United States market mandated Level 2, 3 and 4 organizations.that organizations comply with the (PCI DSS), the United . Over half (57%) of retail organizations admit to not Kingdom now faces its compliance deadline. fully understanding the requirements of the Payment Following an initial, significant reluctance to MasterCard, Card Industry Data Security Standard (PCI DSS).Visa and American Express dictating compliance, the US . Brand awareness and fear of reputation damage is a sig-market has recently experienced a rapid change of heart. nificant driver for achieving PCI compliance.The combination of high penalties and the threat of being unable to accept payments via each of these card brands . Over three quarters (77%) of organizations have had no certainly focused attention on PCI. But more importantly, difficulty in securing funding and resource to ensure those storing cardholder data have been rocked by the PCI DSS requirements are met.huge brand damage, loss of customers and financial costs . 88% of organizations have senior management on the incurred by organizations that have endured high profile PCI DSS team or working group-a figure that is 100% data breaches. for Level 1 organizations.But is this attitude reflected in the UK market today? According to research commissioned by Tripwire, only 11 invest time and resources in achieving compliance rather percent of UK organizations processing credit and debit than pay penalties for non-compliance or endure a data cardholder data are currently certified PCI compliant. Level breach that damages their reputation.1 merchants-those processing over six million transac- However, the study revealed a disturbing trend; many tions annually-embraced the regulation first, with over Level 3 and Level 4 merchants, (those most likely to be half (58 percent) audited and certified compliant. For those early in their PCI compliance efforts) perceive that their merchants processing under six million transactions, the existing security procedures exceed the level of security percentage of certified organizations falls to a surprising low required by PCI. In contrast, none of the Level 1 and 2 of 4 percent to 8 percent. merchants surveyed-those more likely to be further along The study revealed a particularly interesting finding: that the compliance route-hold this opinion. Rather, these senior management in organizations studied have a resound- more experienced merchants feel the PCI DSS requirements ing commitment to PCI compliance. In fact, organizations are actually only on par now with their current security easily raise funds for compliance projects. This second find- procedures. ing is extraordinary given recent restrictions in IT spending. This raises a worrying concern that organizations not yet Furthermore, senior management is represented on the PCI certified may have a tendency to underplay the PCI require-compliance team in the majority of organizations. ments and risk complacency. Unfortunately, as the PCI This top-level commitment reflects a key conclusion of the compliance deadline approaches in which these organiza-research: brand awareness and fear of reputation damage tions must experience a full PCI audit, they may realize too significantly drive PCI compliance activities in most organi- late that they face a steep climb to achieving PCI compli-zations. It makes sense then, that organizations prefer to ance and ensuring cardholder data protection.
2 | WHITE PAPER | PCI Compliance: Are UK Businesses Ready?Introduction
Effective September 30, 2010, the Payment Card Industry Brand ValueData Security Standard (PCI DSS) will apply to or... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search