Tuesday, November 18, 2008

Blog #5_PCI DSS Compliance: Just Whose Responsibility is It?

Hospitable firms globally accepting credit or debit cards are required to comply with the Payment Card Industry’s (PCI) Data Security Standard (DSS). PCI’s standard is a set of extensive requirements for enhancing payment account data security. PCI compliance is normally associated to the actively involved tech IT department of an organization, but realistically, the responsibility must be shared throughout the organization.

Dr. Connolly and Mark Haley (CHTP) explain that becoming compliant is more than securing systems, tightening up password control, encrypting data and adding firewalls to the company’s computer network. These vital information security precautions represent only a subsection of the compliance requirements. Others include data stored in paper-based files, such as credit card imprints on back of registration cards.

Failure to comply fully can have a devastating impact on the organization, causing significant financial costs, undesired legal costs, or terminating your career (not just the IT employees). Many security breaches consequences of insufficient training, lack of policies, poor business practices, or an employee’s careless error. Consumers desire to do business with responsible and trustworthy organizations, and especially in the hospitality industry, PCI compliance is critically associated with one’s brand reputation.

The Unintentional association of PCI standards and IT department are commonly viewed together, failing to recall the complete picture. It must be taken into consideration that card numbers and cardholder data are at risk of fraudulent use, in which the activity is not always focused on the IT department, instead on the concierge’s end. The article explains, “PCI compliance is about protecting and securing every facet of one’s business and should focus on people, processes, and technology, not just the technology.” Agreeing with the quotation, an issue that seems to associate itself with the implantation of technology is human error such as a mistake of an employee leaving recorded information obtainable by the public (i.e. a sticky note with essential information on it).

Maintaining and operating a business fluently, it is important to incorporate the entire picture of an organization (not just the IT department) when dealing with PCI DSS. The article makes clear “one must view security and PCI compliance as an important business function and not simply as a task for one’s IT department, even though IT can be both part of the problem and part of the solution.”  Furthermore, the responsibility for PCI DSS compliance should be seized by not only the IT section, but also shared throughout the organization.

 

Connolly, Daniel J. Haley, Mark G (2008 November 4). PCI DSS Compliance: Just Whose Responsibility is it?

http://www.htmagazine.com/ME2/dirmod.asp?sid=&nm=&type=MultiPublishing&mod=PublishingTitles&mid=3E19674330734FF1BBDA3D67B50C82F1&tier=4&id=D70138F32BB54C2ABED5EFDB27ACB157

1 comment:

DV said...

This is a great article. It brings to light several important aspects of PCI DSS. First, I think there's a general tendency to categorize, and over-simplify, business responsibilities i.e. relegating PCI soley to the IT sector. In reality, there are very few functions that can be totally controlled by one section, such as IT, accounting, sales, etc. Moreover, from an organizational effectiveness perspective, it is easy to avoid ownership of a program if it is officially stated that it belongs to someone else. It also discourages teamwork, as it fails to highlight the importance and advantages of group interaction.