Home > Ask the Security Channel Experts > Selling Security Technology and Services with Christofer Hoff Questions & Answers > How will the planned changes in PCI-DSS affect the channel?
Ask The Security Channel Expert: Questions & Answers
EMAIL THIS

How will the planned changes in PCI-DSS affect the channel?

Christofer Hoff EXPERT RESPONSE FROM: Christofer Hoff

Pose a Question
Other Security Channel Categories
Meet all Security Channel Experts
Become an Expert for this site


Security Channel Update
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 16 May 2008
How will the planned changes in PCI-DSS affect the channel?

>

Opportunity knocks.

Each iteration of the Payment Card Industry Data Security Standard (PCI-DSS) brings requirements that are more specific about the controls needed to satisfy the safeguarding of critical data and infrastructure assets. Sometimes these changes mean the selection and adoption of new technology, and oftentimes it means adapting a current PCI-DSS standard to be more effective.

Sometimes these changes are subtle; sometimes they are profound. The upcoming changes in PCI-DSS are a little of both, but rather than focus on them specifically, let's look at PCI-DSS compliance in general.

At this point it should be clear to everyone with a pulse that the delicate balance needed in shifting the requirements from "should" to "shall" are driven by the ever-increasing pace of data breaches and the legislation governing their disclosure and remedy.

What PCI-DSS represents is the minimal standard required by the industry to indicate that a certain level of due care and diligence has been performed. It doesn't, however, certify that an entity that is "PCI compliant" is "secure." It also doesn't mean that risk is appropriately managed and mitigated to an acceptable level. It simply means that certain steps have been taken to become compliant with the requirements defined within the standards.

If you need an example, look no further than the recent case of Hannaford Brothers groceries, a company that was certified as being compliant with PCI-DSS and managed to suffer an egregious security breach.

Why is this unfortunate example an opportunity for the channel? The answer comes in two parts:

First, it's clear that compliance does not equal security. Despite the need for compliance, really digging down deep with a customer to partner with them to manage risk -- for which compliance is a by-product -- provides a true service that is a win-win for both you and your customer.

Second, refuse to offer "compliance made easy" as a solution to your customers. This will earn you respect. As revisions to compliance regulations arise, you will be the trusted advisor who will provide assessments of readiness against those requirements. If you can leverage a well-stocked solutions portfolio to address any warranted technical requirements needed to satisfy certain evolving elements of compliance when combined with strategic risk-focused consulting approach, you will gain the trust of your customers.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Selling Security Technology and Services with Christofer Hoff
Can enterprises place too much emphasis on security regulatory compliance?
What are the best data leakage prevention strategies for my clients?
What is the future of antivirus or antimalware software?
What accounts for the trend toward SMB security?
Where do I start in discussing virtual security with my customers?
Why is it important to use security metrics with my clients?
How can service providers help with IT risk management?
What should I know about green security?
How do I help clients with end-user security policies?
How do I determine the right number of security vendor partners?

Regulatory Compliance
Red Flags Rules compliance: Are your customers informed?
PCI compliance guide: A resource for solution providers
PCI DSS pre-assessment services: Prelude to a QSA
The impact of PCI compliance on the channel
Compliance drives opportunities for security integrators
How to turn the HIPAA compliance changes into opportunities
Data protection services offer revenue for security solution providers
Agiliance and McAfee partner for better governance, risk and compliance services
SonicWall announces partnership with Western NRG
Building a framework-based compliance program

Business risk assessment and risk analysis
Loss leaders: Security products and services to get a foot in the door
Getting to know the NERC CIP standards
The intersection of security and disaster recovery
Remote vulnerability scanning: Process, roles and responsibilities
How to perform a network security audit for customers
Creating your checklist and Summary
How to generate revenue from unified threat management
Unified threat management: Migration and management techniques
Unified threat management: An intro for solution providers
Podcast with Dr. Paul Rohmeyer on choosing a remote management platform

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts