QSA's View on PCI Compliance for Mail Orders
Submitted by peterspier on Mon, 08/09/2010 - 7:39am
Published in
http://blogs.bankinfosecurity.com/posts.php?postID=656
By Peter Spier
Despite the Payment Card Industry Security Standards Council's establishment of a Quality Assurance program "to promote consistent interpretation of the PCI standards and ensure [that] quality is maintained" ... the proverbial devil remains in the details.
So, let's for a moment take the complications of technology-based controls out of it and, for simplicity, consider exactly how the PCI Data Security Standard affects a decidedly more "low-tech" form of cardholder data -- hardcopy transactions...