Seeing as the US Federal Trade Commission (FTC) orders came out last week, I am a little late to express an opinion. But I’m sitting here in my hotel in Short Hills, NJ waiting for my Chinese food to arrive and I’m at a loss for subject matter.

For those who don’t know, the FTC ordered 9 QSA companies to “provide the agency with information on how they conduct assessments of companies to measure their compliance with the Payment Card Industry Data Security Standards (PCI DSS).”

Press Release here; FTC To Study Credit Card Industry Data Security Auditing

Having just ploughed through their 7 page ‘Order to File a Special Report‘, it’s clear that the FTC did not consult with an experienced QSA prior to drafted their questions. If they had, they would not ask questions like;

3. the  typical  length of time  to complete Compliance Assessments;”, or;

4. the  Company’s pricing structure for Compliance Assessments and typical cost to clients of Compliance Assessments;”

Seriously? Why not just ask them to describe the average company, or how long is a piece of string!

They do ask some very sensible questions mind you;

5. the method by which the scope of Compliance Assessments is determined“, and;

6. the process by which the Company determines whether to use sampling as part of a Compliance Assessment, including, but not limited to, a description of the methodology used to determine that any sample is sufficiently large to assure that controls are implemented as expected.

…but overall, the questions show a naiveté of several things about which I, and many others, have written ad nauseam (French and Latin in one sentence, aren’t I impressive!?). For example; asking about a policy that may prevent an organisation from providing additional services that are considered conflicting, goes against the SSC’s own written standard.

That said, you can read a number of things into the questions they DO ask that will likely have ‘The Sacrificial 9’ QSA companies messing their shorts if they don’t have a robust methodology in place.

Very few do.

My thoughts on their questions are as follows:

  1. For them to ask a question about sampling would suggest they have concerns that it is being seen by QSAs as a right and not the privilege it is;
    o
  2. Questions on conflict of interest suggest that they think the current system of ‘disclosure only’ is horribly flawed. Which it is;
    o
  3. The numerous references to methodology and policies indicates that the absence of a requirement for them is an egregious omission. Which it is;
    o
  4. The question related to training outside of the SSC’s QSA training suggests that it is required due to the poor state of QSA quality (there are some exceptional QSAs out there, but this is the minority). Which is true;
    o
  5. The recurring reference to document evidence to be provided with each requirement suggests that they are aware that validation is not performed well. Which it isn’t.

…and so on and so on.

I suspect that by the time the FTC come out with their report and implement their own requirements around privacy the world will have moved on from plastic to mobile, but this should be a wake-up call for EVERY QSA company to start doing their jobs properly. Not because I care about cardholder data, I don’t, but whatever the FTC are up will clearly involve privacy of all personal data. This I do care about.

Whether the FTC are testing the efficacy of a prescriptive, controls based, assessment methodology for their own ends I cannot say, but there’s no way this is just about payment cards.

The other QSA companies are hereby warned; you may have dodged the bullet for now, but your consulting practices will die with PCI if you aren’t careful.

[If you liked this article, please share! Want more like it, subscribe!]