Trying To Protect Payment Data When You Can’t Even Find It All
Written by Evan SchumanThe IT struggle with knowing where all payment data is—let alone trying to enforce rules that pretty much try and keep it there—was the topic of a StorefrontBacktalk podcast this week with our own PCI columnist, David Taylor, and security specialist J.D. Oder, the chief technology officer at Shift4.
Oder said most payment data security problems start with an employee error. These are typically employees who truly thought they were doing everything right, but they were undercut by a failed corporate infrastructure. Taylor’s approach was more basic: Retailers must put much less payment data into the hands of employees and return to a centralized approach, as painful as it will be and as backward as it will feel. To listen to these folks argue it out, please click here.
Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code.
-Marc
