Now that I’ve had the opportunity to review the full draft standard, it’s clear that there’s very little that’s difficult for you to achieve in the short term if, and I mean IF, you were doing PCI properly from v2.0 onwards. The majority of the changes are simple clarifications, and if your QSA was doing their validation and QA correctly, you would already be doing 99% of them.

That’s really all v3.0 is; a closer approximation to the Report on Compliance (RoC) scoring mechanism that’s been around for years. I understand the clarifications and the guidance are supposed to bring everyone’s understanding of the INTENT of each requirement into closer alignment, but all that does is reflect very badly on the current quality of the QSAs and the available guidance.  The corollary is that the QSA and ISA training needs some serious attention, and the DSS needs to focus less on the detail, and more on the senior management buy-in.

I also understand that it is VERY difficult to make dramatic changes to a standard when organisations have already invested significant capital and resources into achieving compliance. But even the SSC made it VERY clear from the beginning that the DSS was a MINIMUM set of controls around a single form of sensitive data, and should not be seen as a security programme that meets the entire business’s needs (per the PCI DSS v3.0: “PCI DSS comprises a minimum set of requirements for protecting cardholder data…“).

So why aren’t the changes in v3.0 more significant?  Or more in line with good practices?  I don’t really have a constructive (a.k.a. non-soapbox) answer to that, so I’ll focus on what I perceive to be the major flaws.

Here’s my Top 3 Flaws:

Governance:  This has as many definitions as there are people defining it, but in the end it’s very simple; Governance is the Business side and the IT side having conversations.  Business has the requirements (growth, profit, transformation etc.), IT has the enablement, and the organisation as a whole moves forward appropriately. Nothing should happen in an organisation outside of this framework if the business wants to grow/innovate/adapt effectively (for more see Security Core Concept 4: Governance & Change Control and Security Core Concepts: Tying it All Together)

Guess how many times the word ‘Governance’ (or equivalent) appears in v3.0?

Not once.

Risk Assessment (RA): The whole business/IT/security life-cycle starts with a risk assessment.  The business wants something, the RA determines the balance of risk/reward, and you move on to implementation if the balance is favourable.  The DSS calls for a RA, but it’s still woefully understated, and stuck down in the ‘paperwork’ section (Section 12).  This should have been performed even before you chose a QSA, should be intrinsic to services you eventually receive from them, and should have driven all purchase(s) of technology used to achieve both compliance and security in general (for more see Security Core Concept 1: Risk Assessment / Business Impact Analysis).

The Risk Assessment even had its own Special Interest Group (SIG) to improve the quality of the guidance, but the results were so watered down as to be ineffectual.

Sampling: MUCH better explanation than previously, but it’s missing the most important phrase; “There is no sampling in PCI DSS validation unless the client can reasonably demonstrate how all ‘like’ systems are configured and maintained identically, managed and monitored centrally, and are promoted into production through a well defined and documented  process.”

For too long sampling has been seen as a right, it’s not, it’s a privilege (like spandex). Saying “Sampling is an option…” is not enough to avoid clients demanding ‘pragmatism’ from their QSAs in the ‘this-is-too-difficult’ sense of the word.

I have so much more to say, and some of it is actually positive (like pushing policy enforcement validation), but I’ve already overrun my self-imposed word limit.

Finally, every organisation that relies totally on PCI for their security deserves to be hacked – sorry, but you do – but the SSC and the card brands still have an obligation to do more to evolve the standard into something that can be integrated seamlessly into an established, and comprehensive good-security-practice framework.  By the time the DSS catches up with the real world of security, payments will have moved on from payment cards.

Just ask any non-QSA security expert what you should be doing with your IT budget, I’ll bet it’s not PCI compliance.

[If you liked this article, please share! Want more like it, subscribe!]

I have posited several times that compliance with the PCI DSS, with all of its idiosyncrasies and expense, has driven innovation in the payments space to a degree never before seen.  I even wrote a blog on the subject; How PCI Has Driven Innovation in Payments

However, over recent months, I have had the honour of working with several organisations who are throwing their hats in the ring, and trying to come up with ways to increase both the effectiveness of non-cash payments, but also the security.  Admittedly, these are still piggy-backing off credit cards, but the technologies are precursors to the demise of the card number itself. Basically;

If you don’t need a card number at the beginning of a transaction, why have a card OR a number in the first place?

Continue reading “How PCI Is Stifling Payments Innovation”

For those of you who are unfamiliar with the concept of ‘Disruptive Innovation’ (like me until 5 days ago), it is defined as;

a process by which a product or service takes root initially in simple applications at the bottom of a market and then relentlessly moves up market, eventually displacing established competitors.” (http://www.claytonchristensen.com)

For decades, the card schemes (Visa, Mastercard, Amex, Discover etc.) have ruled the non-cash payments space, despite the fact that the technology behind the credit card; the card number, is now over 60 years old. There have been few alternatives proposed because:

  1. There were none that did not rely on some other form of number or separate device to authenticate. For example, bio-metrics has never been 100% free of false positives or false negatives, and therefore is not accurate enough for the payments space. Yet.
  2. Credit cards worked, the infrastructure is pretty much global, and they are still expanding.
  3. The card brands themselves are very aggressive in protecting their empires.

Even the PCI Standards (PCI DSS, PA-DSS, and PTS) can be seen as innovation stiflers, because it’s so difficult to achieve compliance that most organisations have little time or money left to experiment. Also, no-one wants to be the first to stray from the established norm as there’s simply too much to lose, and recovery is increasingly difficult given the globalisation of competition in almost every industry sector.

But, with the massive amount of innovation that AVOIDING PCI has spurned, the number of non-card-brand options has increased to the point where only the most naive of organisations are not looking around for alternative payment methods. Why use a credit card when consumers can obtain lines of credit directly from their banks and access this from their mobile device faster, more securely, and without the outrageous fees the card brands have charged all these years?

The Internet is more distributed and available than the card brands can ever be, and mobile devices already outnumber card payment terminals by orders of magnitude. There will soon be more smartphones than PEOPLE in the world, so the demand for efficiency and functionality will only increase.

And what of chip and PIN (a.k.a. EMV)? Why would anyone bother buying the expensive payment terminal (PED) models currently provided by the Ingenico’s, Verifone’s, and Micros’s of the world, when a simple software ‘fix’ on ANY terminal will provide the same functionality? Functionality that is portable to every form of transaction, from card present, to eComm, to mobile (e.g. myPinPad).

OK, so the last paragraph assumes you’re still using a credit cards, but it just goes to show the knock-on effect that the demise of credit cards will engender. PED manufactures will move into something else that requires hardware, encryption and centralised management (B.Y.O.D perhaps?), most QSA companies will fail (or start doing security properly for a change), and the banks will be held fully accountable for the security of their customer’s payment transactions.

So PCI, which started out as an attempt to keep the US Fed off the card brand’s backs, has, through its complexity, expense, and inflexibility, driven the type of innovation from which there is no turning back. The card brands will either spend all of their money buying companies that provide credit card alternatives in order to future-proof themselves (like Visa buying a stake in Square for example), or they will fail.

I’d say they have 5 – 10 more good years, you simply can’t replace something as ubiquitous as the credit card until the new payment methods have worked out all the kinks. That said, it’s the Internet again that will provide the platform, and software applications that will provide the function, so global distribution is as simple as going online.

I can’t wait to see what’s next.

Have you all seen the ‘sneak peek‘ yet?

I have to admit, that with 3 YEARS to accept and process feedback, I was hoping for a little more in the way of progress.  I’m optimistic that way, but I really should have known better.

Many changes were proposed, lots of the them good, some of them naive and bordering on the comical, but any that made it through are so watered down as to be virtually irrelevant.  And we won’t get any more for 3 more years?

The standard is already behind the times, and is only going to become more so if it does not keep up with payments innovation, and show a better integration with the needs of the business. i.e. STAYING in business.

I have taken the table of changes out of the SSC’s document and added my own thoughts.  Unfortunately they are overwhelmingly negative, and at times my frustration is clear. Go here if you want to download it.

I do however want to make it clear that I’m not against the PCI DSS as much as I appear.  No standard has raised security awareness as much before, or since, and it’s the only one that puts its money where its mouth is.  While there is still some vagueness and room for interpretation, it’s a damned-sight better that just saying ‘use appropriate security based on good practices’ like most do.

The reason I stick to the negative is I’m assuming the positive is self evident, and all I really care about is addressing the gaps to where it should be.  As Ego says in Ratatouille; “In many ways, the work of a critic is easy. We risk very little yet enjoy a position over those who offer up their work and their selves to our judgment. We thrive on negative criticism, which is fun to write and to read. But the bitter truth we critics must face is that, in the grand scheme of things, the average piece of junk is more meaningful than our criticism designating it so.”

This applies every bit as much to my blogs.

I have only addressed the PCI DSS stuff, PA-DSS is not my thing.  If someone wants to take a stab at that, I’ll be happy to post it here as a guest blog.

 

 

I can’t resist dramatic titles, but I’m not actually going to badmouth the SSC, PCI, or ‘Just-QSAs’ (see Heads-Up to the Just-QSAs, It’s Time to Diversify), I’m simply going to state my opinion on why every QSA has at some point had to cut significant corners in the assessment process, and written their reports accordingly. If they didn’t, their clients would, quite literally, never have achieved compliance.

Here’s a ridiculous analogy; If every PCI requirement was a tennis ball, you could very easily carry them all from a weight perspective, but it’s impossible to hold them all together without some kind of container (Tennis ball = DSS Requirements, Container = Security Programme). In other words, the requirements themselves are basic, but completely out of context from a ongoing management, business, or even good security practice perspective.

The PCI DSS is 350-odd MINIMUM security controls, that must be in place across all systems, applications, and processes at all times. Even though the individual controls themselves are very reasonable, and SHOULD be mostly in place anyway, there is no way in any environment (that warrants an onsite assessment) that 100% compliance can be maintained at all times. Not without considerable expense anyway.

For example; 1) PCI does not REQUIRE centralised logging, but try complying with 10.5.X without it. 2) You don’t HAVE to use 3rd party penetration testers, but do you really want to employ that skill-set in-house? 3) The paperwork aspect of policies is easy, but it take years and a significant change in corporate culture to put them properly into effect. And so on.

What this leads to is organisations either giving up and accepting ‘tick-in-the-box’ compliance, or spending way too much money on things that provide little value to the overall organisation.

The business must never be changed to fit into PCI compliance alone, the INTENT of PCI must be fit into business to the benefit of both.

As I’ve said countless times, it’s not that the DSS is a bad standard, it’s just that it doesn’t start in the right way, doesn’t finish where it matters, and only covers one specific data type. The outcome of this is that no business is going to make the necessary expense to attempt letter-of-the-law compliance. Nor should they in my opinion, which means that QSAs MUST be … errrr pragmatic in their enforcement.

Which brings up one of the biggest flaws of PCI; The QSA is held accountable to enforce the standard as written, but is also under commercial pressure as a vendor. There are hundreds of other QSA companies just waiting in the wings to ‘help’ businesses achieve compliance if you’re not pragmatic enough for their liking.

The conflict of interest is undeniable, and ruins the objectivity required to conduct the assessment. Not to mention that the price compression associated with this competition has, over time, massively eroded the level of service that can be provided at a reasonable profit.  Junior ‘Just-QSAs’, are the only way to make money in PCI if you don’t sell them other things on the side.

Finally, QSAs are allowed to interpret the DSS to a large degree, as well as make decisions on what constitutes a compensating control. There is very little official guidance, or standardisation in this regard, and the card brands themselves will always refer questions back to the QSA. There have been some very good trainers at the SSC, and some very poor ones, and the far from optimal training program itself just exacerbates the problem faced by businesses looking to do the right thing. That is, the right for PCI compliance, but also the right thing for their business. You can guess which takes priority.

In the end, the right thing is to just do security properly. The benefits far outweigh the costs, and your PCI compliance will be good enough for what it represents.