PCI Issues Security E-Commerce Guidance

The PCI Security Standards Council has issued new guidance recommendations for enhancing data security.

February 05, 2013

FOSTER CITY, CA - In advance of an expected major update to be released later this year, the PCI Security Standards Council (PCI SSC) has issued new guidance recommendations for organizations on enhancing data security, E-Security Planet reports.

"A lot of the exploits we're seeing today are older exploits that should not still be happening," said Bob Russo, general manager, PCI SSC. "This set of guidelines is an attempt by the community at large to make sure that people have guidance."

While the guidance document does not add to the existing PCI-DSS 2.x standard, it provides guidance that aligns with the most up-to-date standards, including areas that Russo said have proven the most vulnerable to breaches. Topping that list are SQL injection and cross-site scripting (XSS) attacks, which mostly affect web and highly connected retail chains and not c-store operators.

"These are exploits that are in some cases 12 years old. There are a myriad of ways to prevent these exploits within the PCI-DSS standard," Russo said. "This guidance provides more clarity to make sure that a merchant can make sure these items are top of mind."

Russo also explained the difference between PCI-DSS compliance and security, the latter a reflection of adopting the most current safeguards and practices to protecting data.

"You can be PCI compliant by having all the right things in place, but if you don't use them correctly, you're not secure," he said.

Advertisement
Advertisement
Advertisement