PCI Confusion Aggravating Retailers
August 11th, 2006Vague guidelines and conflicting audit firm interpretations—coupled with retailers that fall into multiple PCI categories—are making for some unhappy retailers. The problem is less one of how the PCI guidelines are phrased and more a matter of how they are being interpreted, particularly by audit firms the retailers are hiring to prove compliance.
"The guidelines are written fairly broadly and you sit there and say, 'How do we apply them?' One audit firm will tell you, 'No, you can't do this. It's prohibited by the guidelines' and another audit firm will say, 'This is perfectly fine,'" said security consultant Mark Rasch. Read more...
Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code.
-Marc
