BreachExchange mailing list archives

Re: OT? PCI Education Steak & Shake


From: blitz <blitz () strikenet kicks-ass net>
Date: Tue, 08 May 2007 16:32:44 -0400

Only a fool would let the fox guard the hen house...YES, there most certainly needs to be third party oversight. Just like the SEC watches the stock market, */AND/* with similar powers of enforcement.



Kehoe, Matt wrote:
Having just gone through this, the biggest gotcha is that tier 1
retailers need a "3rd party assessment" which means you cant just
execute compliance from within....

PCI standards still leave much to be desired, but it's a good step
forward for retailing in general...
-----Original Message-----
From: dataloss-bounces () attrition org
[mailto:dataloss-bounces () attrition org] On Behalf Of Al Mac
Sent: Tuesday, May 08, 2007 8:48 AM
To: Data Loss Incidents
Subject: [Dataloss] OT? PCI Education Steak & Shake


_______________________________________________
Dataloss Mailing List (dataloss () attrition org)
http://attrition.org/dataloss
Tracking more than 207 million compromised records in 649 incidents over 7 years.

Current thread: