Q&A: No Alternative to PCI, Security Council Chief Insists
Robert Russo, the general manager of the Payment Card Industry Security Standards Council, fires back at critics of the PCI data security standard.
Why is PricewaterhouseCoopers reviewing end-to-end encryption, tokenization and chip and PIN technologies for the PCI Security Standards Council? What they are be doing is looking at these technologies and a couple of others as well and seeing what needs to be in these technologies for them to be considered for the standard. They are going to say [that] if you are using end-to-end encryption technology it must do these five or eight or 10 or 20 things. And you must do them this way in order to be considered compliant with the standard. We realize that technology is moving very quickly and certainly we want to make sure that we are giving everyone the opportunity to use these methods to protect (payment card) data if, in fact, they are good methods.
Have you been surprised by the criticism leveled against PCI of late? Or is it only to be expected with an effort this big? You hit the nail on the head. First of all, this is a very big effort. Second, regardless of who is responsible for the standard, in an economic environment like the one we are in now, when people can't afford to do the work, they don't want to do the work. But really there is no alternative. This is the best way to secure payment card data.
Security



