Now that I’ve had the opportunity to review the full draft standard, it’s clear that there’s very little that’s difficult for you to achieve in the short term if, and I mean IF, you were doing PCI properly from v2.0 onwards. The majority of the changes are simple clarifications, and if your QSA was doing their validation and QA correctly, you would already be doing 99% of them.

That’s really all v3.0 is; a closer approximation to the Report on Compliance (RoC) scoring mechanism that’s been around for years. I understand the clarifications and the guidance are supposed to bring everyone’s understanding of the INTENT of each requirement into closer alignment, but all that does is reflect very badly on the current quality of the QSAs and the available guidance.  The corollary is that the QSA and ISA training needs some serious attention, and the DSS needs to focus less on the detail, and more on the senior management buy-in.

I also understand that it is VERY difficult to make dramatic changes to a standard when organisations have already invested significant capital and resources into achieving compliance. But even the SSC made it VERY clear from the beginning that the DSS was a MINIMUM set of controls around a single form of sensitive data, and should not be seen as a security programme that meets the entire business’s needs (per the PCI DSS v3.0: “PCI DSS comprises a minimum set of requirements for protecting cardholder data…“).

So why aren’t the changes in v3.0 more significant?  Or more in line with good practices?  I don’t really have a constructive (a.k.a. non-soapbox) answer to that, so I’ll focus on what I perceive to be the major flaws.

Here’s my Top 3 Flaws:

Governance:  This has as many definitions as there are people defining it, but in the end it’s very simple; Governance is the Business side and the IT side having conversations.  Business has the requirements (growth, profit, transformation etc.), IT has the enablement, and the organisation as a whole moves forward appropriately. Nothing should happen in an organisation outside of this framework if the business wants to grow/innovate/adapt effectively (for more see Security Core Concept 4: Governance & Change Control and Security Core Concepts: Tying it All Together)

Guess how many times the word ‘Governance’ (or equivalent) appears in v3.0?

Not once.

Risk Assessment (RA): The whole business/IT/security life-cycle starts with a risk assessment.  The business wants something, the RA determines the balance of risk/reward, and you move on to implementation if the balance is favourable.  The DSS calls for a RA, but it’s still woefully understated, and stuck down in the ‘paperwork’ section (Section 12).  This should have been performed even before you chose a QSA, should be intrinsic to services you eventually receive from them, and should have driven all purchase(s) of technology used to achieve both compliance and security in general (for more see Security Core Concept 1: Risk Assessment / Business Impact Analysis).

The Risk Assessment even had its own Special Interest Group (SIG) to improve the quality of the guidance, but the results were so watered down as to be ineffectual.

Sampling: MUCH better explanation than previously, but it’s missing the most important phrase; “There is no sampling in PCI DSS validation unless the client can reasonably demonstrate how all ‘like’ systems are configured and maintained identically, managed and monitored centrally, and are promoted into production through a well defined and documented  process.”

For too long sampling has been seen as a right, it’s not, it’s a privilege (like spandex). Saying “Sampling is an option…” is not enough to avoid clients demanding ‘pragmatism’ from their QSAs in the ‘this-is-too-difficult’ sense of the word.

I have so much more to say, and some of it is actually positive (like pushing policy enforcement validation), but I’ve already overrun my self-imposed word limit.

Finally, every organisation that relies totally on PCI for their security deserves to be hacked – sorry, but you do – but the SSC and the card brands still have an obligation to do more to evolve the standard into something that can be integrated seamlessly into an established, and comprehensive good-security-practice framework.  By the time the DSS catches up with the real world of security, payments will have moved on from payment cards.

Just ask any non-QSA security expert what you should be doing with your IT budget, I’ll bet it’s not PCI compliance.

[If you liked this article, please share! Want more like it, subscribe!]

Who doubts that the future of 3-D printing is that you will soon be able to print with almost any substance that can be turned into a spray?  Or better yet, the drive for new compounds and materials will harbour an explosion in stronger-than-metal fibres that will negate the need for high temperature processing?

Obviously this is many years off, but you can already produce some of the crappy little plastic nick-knacks that tourists pay squillions for every year in a 3-D printer you can buy for less than £1,000 and put on your office desk. The price of these printers goes down as the quality goes up (very similar to Moore’s Law on transistors), so it’s fair to say that, like computers, they will become just as mainstream and widespread as any other home computing device.

So why this blog?  I was just sitting here, on a gorgeous Autumn day, in the house in front of my computer (like you do), when I  took a look at everything within my reach to see where it was made.  I’m sure you can guess; anything small plastic and disposable was made in China.  My next though was; what happens to all of those people whose livelihood revolves around making cheap, plastic, disposable, and in no way useful crap, when I can print equally useless crap at home?

Then I thought of a scenario; I see a guy in a far away airport rushing for a plane to get home to his family.  It suddenly occurs to him that he has not bought anything for his for his 2 little children – that’s why it’s a ‘him’ in my story BTW, women are far less stupid – and he has no time to buy something. So, he takes out his smartphone and takes a picture of a generic toy for the country he’s in, processes it through a scanning app, and sends the results to his printer sitting at home in his office.

By the time he gets home, there’s two, identical but for the colour, cheap, plastic, disposable, and in no way useful, pieces of crap sitting on his desk. Great for Daddy, bad for shopkeeper in far away airport, and VERY bad for family scraping by on the income the receive from making the cheap …you get the point.

I have no solution for this, in case you’re wondering, I LOVE the thought of what we’ll be able to do 5 – 10 years from now, nor do I have it in me to do anything more than write a stream-of-consciousness blog on something I read while browsing Wired articles.

I understand that technology, innovation, and the sheer inventiveness of the human race means that things change, and they change quicker every year, and that if you’re not ahead of the wave you will get left behind and potentially suffer.  But I can’t help wonder if this is not a perfect time for concepts such as corporate social responsibility to make their way off the marketing fluff, and into a demonstrable service provided by the leaders in the future trends.

Maybe I just ate a bad bagel…

 

I have posited several times that compliance with the PCI DSS, with all of its idiosyncrasies and expense, has driven innovation in the payments space to a degree never before seen.  I even wrote a blog on the subject; How PCI Has Driven Innovation in Payments

However, over recent months, I have had the honour of working with several organisations who are throwing their hats in the ring, and trying to come up with ways to increase both the effectiveness of non-cash payments, but also the security.  Admittedly, these are still piggy-backing off credit cards, but the technologies are precursors to the demise of the card number itself. Basically;

If you don’t need a card number at the beginning of a transaction, why have a card OR a number in the first place?

Continue reading “How PCI Is Stifling Payments Innovation”

Just chatting with my wife the other day about mentoring, and she raised a very interesting, and valid, point. A coach and a mentor are two very different things, though often used interchangeably. This led to the thought that in the course of our careers, we may ask for (or settle for), and get, the wrong one. Or just as bad, the right one at the wrong TIME!

As I think she described it – bearing in mind she’s a lot smarter than me -, a coach is someone who teaches you to get better at the thing in which they are expert, but a mentor is someone who helps you get better at whatever YOU want to be better at doing. Even if the mentor is not an expert in it themselves. Another way of putting it, is that a mentor helps you think in different ways, understand things of which you have no prior experience, and guide you in scenarios through which you have yet to live yourself.

So which one do we need? Quite simply, both. The trick is to know when you need them, and you will never be able to do that if you don’t know what you want. Or just as importantly; what you are good at. I have posited several times (like in Loyalty vs. Personal Values, and Never Follow the Money), that unless you are ‘honestly introspective’, you will always have challenges that could so easily have been avoided.

Neither a coach, nor a mentor, nor anyone for that matter can help you if you don’t know what it is that YOU want. And if what you want is not realistic, you are basically wasting your time. I’m not saying don’t push yourself, but wanting to be a supermodel or astronaut is only OK for a tiny percent of the population. No offence, but if you’re reading this it’s unlikely you’re one of them.

Word of warning: There is a fine line between a true mentor and someone who wants you to become like them, don’t cross it. Emulation is OK in very few circumstances, and unless your actions stem from YOU as the foundation, they will come across as fake. No mentor will be perfect, they will have an ego, and be easily flattered by your request for help. This can lead them to advise you in ways that are simply not within you to emulate.

From my perspective, I will ask for a coach when there is something I really want to be able to do, and just can’t get my head around. But this will be very specific, and I will control the outcome. As for a mentor, I now have several people in my life who have already done things I am trying to do, and while the relationships are not ‘formal’ in terms of mentor / mentee, I love listening, and they love talking! 🙂

There is absolutely no stigma attached to asking for help of ANY sort, and those who don’t ask, will never achieve as much as those who do. Don’t be a pest, but don’t sit on your arse either.

[If you liked this article, please share! Want more like it, subscribe!]

For those of you who are unfamiliar with the concept of ‘Disruptive Innovation’ (like me until 5 days ago), it is defined as;

a process by which a product or service takes root initially in simple applications at the bottom of a market and then relentlessly moves up market, eventually displacing established competitors.” (http://www.claytonchristensen.com)

For decades, the card schemes (Visa, Mastercard, Amex, Discover etc.) have ruled the non-cash payments space, despite the fact that the technology behind the credit card; the card number, is now over 60 years old. There have been few alternatives proposed because:

  1. There were none that did not rely on some other form of number or separate device to authenticate. For example, bio-metrics has never been 100% free of false positives or false negatives, and therefore is not accurate enough for the payments space. Yet.
  2. Credit cards worked, the infrastructure is pretty much global, and they are still expanding.
  3. The card brands themselves are very aggressive in protecting their empires.

Even the PCI Standards (PCI DSS, PA-DSS, and PTS) can be seen as innovation stiflers, because it’s so difficult to achieve compliance that most organisations have little time or money left to experiment. Also, no-one wants to be the first to stray from the established norm as there’s simply too much to lose, and recovery is increasingly difficult given the globalisation of competition in almost every industry sector.

But, with the massive amount of innovation that AVOIDING PCI has spurned, the number of non-card-brand options has increased to the point where only the most naive of organisations are not looking around for alternative payment methods. Why use a credit card when consumers can obtain lines of credit directly from their banks and access this from their mobile device faster, more securely, and without the outrageous fees the card brands have charged all these years?

The Internet is more distributed and available than the card brands can ever be, and mobile devices already outnumber card payment terminals by orders of magnitude. There will soon be more smartphones than PEOPLE in the world, so the demand for efficiency and functionality will only increase.

And what of chip and PIN (a.k.a. EMV)? Why would anyone bother buying the expensive payment terminal (PED) models currently provided by the Ingenico’s, Verifone’s, and Micros’s of the world, when a simple software ‘fix’ on ANY terminal will provide the same functionality? Functionality that is portable to every form of transaction, from card present, to eComm, to mobile (e.g. myPinPad).

OK, so the last paragraph assumes you’re still using a credit cards, but it just goes to show the knock-on effect that the demise of credit cards will engender. PED manufactures will move into something else that requires hardware, encryption and centralised management (B.Y.O.D perhaps?), most QSA companies will fail (or start doing security properly for a change), and the banks will be held fully accountable for the security of their customer’s payment transactions.

So PCI, which started out as an attempt to keep the US Fed off the card brand’s backs, has, through its complexity, expense, and inflexibility, driven the type of innovation from which there is no turning back. The card brands will either spend all of their money buying companies that provide credit card alternatives in order to future-proof themselves (like Visa buying a stake in Square for example), or they will fail.

I’d say they have 5 – 10 more good years, you simply can’t replace something as ubiquitous as the credit card until the new payment methods have worked out all the kinks. That said, it’s the Internet again that will provide the platform, and software applications that will provide the function, so global distribution is as simple as going online.

I can’t wait to see what’s next.