Attacking The Lack Of Wireless With Wireless, Just To Appease PCI
Written by Evan SchumanPCI conundrum of the week: How does a retailer that happens to not be using any wireless deal with the wireless requirements of PCI 2.0? We explore this issue in this week’s StorefrontBacktalk security podcast.
Aaron Reynolds, a Verizon business security consultant, summed up the apparent contradiction: “Let’s say you’re a retailer with 5,000 locations and you have no authorized wireless within that environment. And I have this PCI requirement in front of me and I’m going to address this requirement through a wireless solution. I’m actually introducing wireless into an environment that previously had no wireless. I’m also spending several hundred thousand dollars—if not millions of dollars—to address one requirement that, in my opinion, has a much smaller risk/reward in the event that somebody might plug in a rogue wireless device.” To hear the podcast, please click here.