Guest Columnist David Taylor questions how seriously most retailers take store-level security. At least that's a logical conclusion given the number of retailers that have passed PCI assessments without the assessors ever having visited any stores.
There are many causes for this, but jurisdiction is a big part. Some retailers have had Loss Prevention take on store-level PCI compliance as part of their regular audits, but most LP departments have very limited IT skill sets, so this rarely works. At other retailers, PCI is managed out of the IT department, and we all know how much IT people like going into "the field," so that rarely works, either. In still other cases, there's a separate Compliance function that owns SOX and PCI, HIPAA. Most of these people are lawyers or "wannabe lawyers" who rarely show up at meetings let alone visit the stores. Read more...