IDG Contributor Network: The dangers of cramming for your PCI test
I am currently working with a tier 1 PCI company, assisting it with various compliance tasks. As part of the project, I am simultaneously preparing it for its annual PCI audit, responding to audits by other organizations for which the company is a key third party, and reviewing organizations that are its key third parties. It seems that with the focus on PCI compliance these days, everyone is auditing everyone else. Despite this, we don't seem to be reducing the number of credit card breaches, or actually making organizations more secure.
According to the Verizon 2015 PCI Compliance Report, the number of security incidents is still growing, and at a significant rate –- 66% per year. The same report demonstrates that despite all of the PCI audits happening, most companies are still missing the mark, with 80% failing their interim assessments. Verizon concludes from this that organizations “failed to sustain the security controls they put in place.”
To read this article in full or to leave a comment, please click here