Showing posts with label PCI-DSS. Show all posts
Showing posts with label PCI-DSS. Show all posts

Friday, October 7, 2011

Attorneys General continue to increase legal standards for data privacy compliance

Many have written about it and several have contemplated it -- whether states will adopt private data security standards, such as the Payment Card Industry Data Security Standards (PCI DSS), and use them as legal standards that owners and holders of personal information (PI) must comply with.



That’s exactly what the Massachusetts Attorney General did when it recently filed suit against Briar Group, LLC and alleged, among several other things, that Briar was not PCI compliant at the time of its data breach in November 2009, affecting 53,000 MasterCard and 72,000 Visa accounts.

PCI DSS are private data security standards created by the Payment Card Industry Security Standards Council that apply to all organizations collecting credit cards. The Complaint alleged that Briar’s failure to implement basic data security measures on its computer system allowed hackers to gain access to Briar’s customers’ credit and debit card information.

Please see full article for more information.

Briar ultimately settled with Massachusetts through a consent judgment with the following penalties, in part:
• Briar Group to pay State of Massachusetts $110,000;
• Establish a Written Information Security Program;
• Maintain PCI compliance and verify same within fourteen days;
• Revise password management process; and
• Implement various network system changes.


So here is a point that Briar Group or any company that is responsible for private information about their employees, suppliers or customers should consider.  Having a Written Information Security Plan (WISP) in place "Before" a breach happens is a worthwhile investment. 

So much so, that if they were compliant with a working WISP plan, they might not have been breached in the first place.  Fire drills save lives, because people are prepared and can stay calm in an emergency. 

A WISP plan prepares an organization.  The "plan" ensures that a company follows industry best practices.  Nothing is perfect, but the heavy fines and bad publicity are minimized by being prepared.  A WISP plan creates a defensible position.

Dolvin Consulting and Cyber Security Auditors & Administrators (CSA2) work with organizations that are worried about the threat of lawsuits related to the loss of private information and concerned about the loss of their customer base from the erosion of confidence that results from data breaches.

Contact us today to see how we can help you sleep better at night.



Wednesday, July 27, 2011

Did your customer just make you non-compliant with PCI guidelines?

Did your customer just make you non-compliant with PCI guidelines?

The convenience and ease at which technology has connected us may open the door to inadvertently exposing your organization to violations and PCI audits.  If, for an example, a customer sends their credit card information to you in an email or other social medium format, which sends (or should send) red flag warnings.  You absolutely cannot process the transaction.



According to Walter Conway, “If you do, then your company’s email servers, cell phones, web browser caches, Twitter, and Facebook accounts are all subject to a PCI-DSS audit.”

Refusing the transaction is not good for business, but accepting it means that everything in the communications channel is now handling cardholder data and must be compliant.

Worse yet, because much of these communications are not encrypted, what happens if that card information is compromised?  You now have a post-breach situation which notification requirements and regulators looking for your Written Information Security Plan (WISP).  Fines are sure to follow, but what about the loss of that customer and others that now look at your company as liability.


Better to refuse the transaction and explain the gory details to the customer rather than risk the alternatives.  Dolvin Consulting works with Cyber Security Auditors and Administrators (CSA2) to help you prepare.  Contact us to discuss how we can help protect your reputation and bank balance.