Monday, July 13, 2009

Savvis is being dragged into court to defend their PCI DDS certification of CardSystems in 2004, which was subsequently responsible for losing a quarter of a million credit card numbers.

This is the first of potentially many legal actions against PCI auditors that certified organizations as compliant, when they were subsequently breached and responsible for the loss of consumer credit card information.

Personally, I think it is about time. I've long believed that the PCI certification process (as it has historically stood) is a farce, and only designed to make Visa and some information security consulting firms money by requiring certification.

Alister Macintyre I seem to remember that at the time of that breach, the issue came up about them just having completed a security audit that said they were secure, in the specific areas that they had asked to be security audited, which did not include the areas where they got breached, and were in violation of regulations.
