I can’t resist dramatic titles, but I’m not actually going to badmouth the SSC, PCI, or ‘Just-QSAs’ (see Heads-Up to the Just-QSAs, It’s Time to Diversify), I’m simply going to state my opinion on why every QSA has at some point had to cut significant corners in the assessment process, and written their reports accordingly. If they didn’t, their clients would, quite literally, never have achieved compliance.
Here’s a ridiculous analogy; If every PCI requirement was a tennis ball, you could very easily carry them all from a weight perspective, but it’s impossible to hold them all together without some kind of container (Tennis ball = DSS Requirements, Container = Security Programme). In other words, the requirements themselves are basic, but completely out of context from a ongoing management, business, or even good security practice perspective.
The PCI DSS is 350-odd MINIMUM security controls, that must be in place across all systems, applications, and processes at all times. Even though the individual controls themselves are very reasonable, and SHOULD be mostly in place anyway, there is no way in any environment (that warrants an onsite assessment) that 100% compliance can be maintained at all times. Not without considerable expense anyway.
For example; 1) PCI does not REQUIRE centralised logging, but try complying with 10.5.X without it. 2) You don’t HAVE to use 3rd party penetration testers, but do you really want to employ that skill-set in-house? 3) The paperwork aspect of policies is easy, but it take years and a significant change in corporate culture to put them properly into effect. And so on.
What this leads to is organisations either giving up and accepting ‘tick-in-the-box’ compliance, or spending way too much money on things that provide little value to the overall organisation.
The business must never be changed to fit into PCI compliance alone, the INTENT of PCI must be fit into business to the benefit of both.
As I’ve said countless times, it’s not that the DSS is a bad standard, it’s just that it doesn’t start in the right way, doesn’t finish where it matters, and only covers one specific data type. The outcome of this is that no business is going to make the necessary expense to attempt letter-of-the-law compliance. Nor should they in my opinion, which means that QSAs MUST be … errrr pragmatic in their enforcement.
Which brings up one of the biggest flaws of PCI; The QSA is held accountable to enforce the standard as written, but is also under commercial pressure as a vendor. There are hundreds of other QSA companies just waiting in the wings to ‘help’ businesses achieve compliance if you’re not pragmatic enough for their liking.
The conflict of interest is undeniable, and ruins the objectivity required to conduct the assessment. Not to mention that the price compression associated with this competition has, over time, massively eroded the level of service that can be provided at a reasonable profit. Junior ‘Just-QSAs’, are the only way to make money in PCI if you don’t sell them other things on the side.
Finally, QSAs are allowed to interpret the DSS to a large degree, as well as make decisions on what constitutes a compensating control. There is very little official guidance, or standardisation in this regard, and the card brands themselves will always refer questions back to the QSA. There have been some very good trainers at the SSC, and some very poor ones, and the far from optimal training program itself just exacerbates the problem faced by businesses looking to do the right thing. That is, the right for PCI compliance, but also the right thing for their business. You can guess which takes priority.
In the end, the right thing is to just do security properly. The benefits far outweigh the costs, and your PCI compliance will be good enough for what it represents.
