BreachExchange mailing list archives

Re: Visa Puts Heartland on Probation Over Breach


From: "Jamie C. Pole" <jpole () jcpa com>
Date: Fri, 13 Mar 2009 09:17:30 -0400


Oh wow!  That's going to make a HUGE difference!

Let's not forget that they WERE PCI "compliant" when they got  
breached.  How is hiring another clueless QSA going to change the  
basic facts here?

The whole PCI "standard" is a joke.  The PCI Standards Body needs to  
go the way of the dodo, and the whole QSA concept needs to be  
eliminated.  The only way there will ever be any reasonable level of  
assurance that credit card transactions are safe is for a body made up  
of COMPETENT security professionals to come together to define  
meaningful controls that will actually make a difference.  And the  
whole "pay to play" QSA game needs to be replaced with a process  
whereby COMPETENT security professionals are able to demonstrate  
proficiency by actions, NOT by virtue of the fact that their  
application fee check cleared.

Actually, I wonder if they take credit cards for the QSA fees?  :-^   
Maybe the QSA criteria should be "show us that you have breached a  
payment processor, and we'll let you test other payment  
processors..."  If that happened, the list of approved QSA providers  
would be VERY small - and I'd bet that VERY few, if any of the people  
on the current list would be on the new list.

This same thing is going to keep occurring over and over and over  
until the PCI program itself is overhauled.  With the current  
"controls" in the PCI DSS, I'm not sure how any of these people sleep  
at night.  Especially when you consider that the QSA providers seem to  
all be relying on automated scanning tools when they do their  
assessments.  Two words come to mind - unlimited liability.

I love the part about "more stringent conditions"...  What?  They have  
to run Nessus or Qualys ONCE a month instead of quarterly?  That's  
definitely going to make a difference!  Twice nothing is still  
nothing.  I suck at math, but even I can work that one out.  (By the  
way, no offense meant to Nessus - it's a great product that I use  
myself - I just don't believe in basing C&A decisions on automated  
tools.)

Gotta love this world we live in - the PCI people have mortgaged the  
future of their industry in order to sell QSA "subscriptions"...

Jamie



On Mar 13, 2009, at 8:38 AM, lyger wrote:


(courtesy Anthony M. Freed)

http://information-security-resources.com/2009/03/13/visa-puts-heartland-on-probation-over-breach/

*Removal from Visa~Rs List of Compliant Service Providers - Visa has
removed Heartland from its online list of Payment Card Industry Data
Security Standard (PCI DSS) compliant service providers. HPS has  
advised,
however, that it is aggressively working on remediation and re- 
validation
of its systems to comply with PCI DSS standards. The company will be
relisted once it revalidates its PCI DSS compliance using a Qualified
Security Assessor and meets other related compliance conditions.*

*System Participation - HPS is now in a probationary period, during  
which
it is subject to a number of risk conditions including more stringent
security assessments, monitoring and reporting. Subject to these
conditions, Heartland will continue to serve as a processor in the  
Visa
system.*

[...]
_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)

CREDANT Technologies, a leader in data security, offers advanced  
data encryption solutions.
Protect sensitive data on desktops, laptops, smartphones and USB  
sticks transparently
across your enterprise to ensure regulatory compliance.
http://www.credant.com/stopdataloss


_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)

CREDANT Technologies, a leader in data security, offers advanced data encryption solutions.
Protect sensitive data on desktops, laptops, smartphones and USB sticks transparently 
across your enterprise to ensure regulatory compliance.
http://www.credant.com/stopdataloss


Current thread: