PCI Nightmare Question Of The Week: How Many QSAs Read The Full Documents They Reference?
Written by Evan SchumanWhen the PCI 2.0 details started pouring out this summer, one of the more commented-on areas was a distinct increase in the number of support documents referenced. More background documents are fine. The concern, however, is that the Council is pointing to multiple standards for retailers to rely on. Variety is nice, but consistency is even better.
In the StorefrontBacktalk podcast this week, one QSA discusses a frightening question: How many retailers—or even their QSAs—truly do read the documents they are relying on? How many are relying on the summaries of others? How many chains are changing policies based on what amounts to Cliffs Notes research? The opening topic is the much beloved key change rotation discussion and how it impacted a three-part NIST standard, which runs more than 300 pages.