Analyst: PCI Security a Devil, 'Like No Child Left Behind'

By obsessing about PCI security compliance and spending money on overly complex and underperforming defenses, companies are ignoring risk management and making themselves a target of state-sponsored cyber villains.

By Bill Brenner

Wed, November 04, 2009CSO By obsessing about PCI security compliance and spending money on overly complex and underperforming defenses, companies are ignoring risk management and making themselves a target of state-sponsored cyber villains.

A Guide to Practical PCI Compliance

That was one of the main messages delivered by Joshua Corman, research director for enterprise security at The 451 Group, during that firm's 4th Annual Client Performance Conference Wednesday morning.

"Organizations have made PCI DSS and compliance in general the basis of their information security policies," he said. "They're basing security on sloppy logic from Visa and MasterCard and in the process are ignoring some very bad state-sponsored threats. As a community, we have not evolved at all."

He compared PCI DSS to No Child Left Behind, the education reform law championed by former President George W. Bush. The law has been criticized by some who believe it has stifled innovation in education and focused too much on standardized testing.

MORE ON THE PCI SECURITY DEBATE:

* PCI, QSAs, Hackers, and Slackers: Will the Real Enemy Please Stand Up?

* Unmasking DLP: The Data Security Survival Guide

* End-to-End Encryption: The PCI Security Holy Grail

It's a warning Corman has made before. In a recent interview with CSOonline, shortly before he left his previous job at IBM ISS, he outlined what he called 8 Dirty Secrets of the IT Security Industry, with compliance endangering security charting as the sixth dirty secret.

Compliance with such laws and industry standards as Sarbanes-Oxley and PCI DSS drives companies to spend far more on security than they might otherwise, he said. Security vendors have obviously seized upon this fact, offering products that do everything from offer PCI compliance out of the box to ultimate cure-alls for healthcare entities coping with the demands of HIPAA. Of course, this too leads to companies buying security tools that fail to properly address the particular risks they face.

"There are really bad people out there doing bad things and few pay attention to things like state-sponsored attacks and cyber warfare. This is because everyone's focusing on compliance," Corman repeated Wednesday.

He also warned that companies are driving over a cliff with obsessions over legacy security programs that are no longer effective and implementing the hottest new technology like cloud computing services.

See also: The Curse of Cloud Security

To the first point, he said, "Security professionals are the pack rats of IT. We hang on to the wooden shields -- firewalls and AV -- which don't really work against new threats."

Security

Loading...
Security MarketSpace
Smarter Protection For the Enterprise
Read this IDC paper for background on today's threat ecosystem with an overview of network security threats, the impact of the threats on enterprises, and the operational challenges faced by IT. Learn more »
Reduce Impact of Unplanned Downtime by 85%
Based on new research, IDC offers best practices to help identify vulnerabilities, "weak links" and mitigate external and internal risks. Learn more »
A Hidden Benefit of Desktop Virtualization?
This IDG eZine explores the many user benefits of desktop virtualization. Learn more »
Controlling E-Discovery: What stays in? What goes out?
You want to hold the cards as far as information management, but keeping large in-house teams doesn't make sense. Learn more »
Get Ahead of Your Data in Early Case Assessment
Need tools that provide cost savings today and fit into a long-term e-discovery strategy? Learn more »
The Challenges of Working with Keyword Search
There is a dangerous assumption that keyword search alone can sufficiently manage e-discovery. Learn more »
How In-House Technology Delivers Savings
Learn how companies can gain control of the e-discovery process and reduce costs by bringing software in-house. Learn more »
 
SPONSORED LINKS
 

Making Consumer Two-Factor Authentication Simple and Cost-Effective

Mining the Cloud to Ease the Enterprise Compliance Burden

Solve Five Key IT Security Challenges with Cloud-Based Authentication

White Paper: A Security Blueprint Delivered From within the Network

Maximizing efficiencies with unified communications.

Cut Costs & Green Your IT Operations with PC Power Management

White Paper: Next Generation Remote Infrastructure Management

Cloud-Based Email Management: Opinion Shifts In Favor

Achieving Business Agility with Application Grid

Seven Ways ITIL Can Help You in an Economic Downturn

A Clear View Toward Virtualization

Virtualization Technology as a Business Solution

Dark Fiber from Sunesys Save on Unlimited Bandwidth with Fixed Costs.

Forrester Webcast - Managing Desktop Support Costs

Be Prepared for Windows 7. Register for this Webcast Series.

Stay informed with custom newsletters from Tech Dispenser

Build your 1st app FREE with Force.com

Virtualization Technology as a Business Solution

eZine: A Roadmap to Reducing IT Complexity

What's Next for Enterprise Resource Planning?

Gartner Magic Quadrant, Application Delivery Controllers 2009

Five-Step Mobility Management Plan

Removing the Barriers to IT Governance: How On-Demand Software Changes the Game

SETLabs: The Impact of Performance Engineering

Cloud Computing--Latest Buzzword or a Glimpse of the Future?

Authentication as a Service by Forrester Research

Cloud-Based Authentication for Next-Generation Extranets

Mobile Security: The Essential Ingredient for Today's Enterprise

Efficiency goes up. Costs come down.

Verint Systems. Discover the Power of Intelligence in Action"

Global Research: CIOs Weigh In On Virtualization

Generation Remote Infrastructure Management - Changing the Paradigm

Lower IT Costs with Oracle Database 11g Release 2

Taking the Service Desk to the Next Level

Unified Communications: Thoughts, Strategies and Predictions. Join the discussion.

eZine: A Roadmap to Reducing IT Complexity

Build your 1st app FREE with Force.com

Secure & simplify your data center w/Juniper Networks.

Gartner ITxpo Panel Webcast: Real-world Early Adoption of Windows 7.

Masters of Virtualization and Cloud Computing - Daily News

Trend Micro ranked #1 against real-world malware. Read more.

The rules of infrastructure management just changed.

A Clear View Toward Virtualization

CRM Built for IT: The Executive Guide to Selecting CRM that Meets IT Needs

ROI of Application Delivery Controllers

SharePoint - Unchecked growth of content is unsustainable.

Enterprise Capture: Your Onramp to Business Process Automation

Focus Under Pressure: Why IT Governance Becomes Mission-Critical in a Down Economy

Cloud Computing--What is its Potential Value for Your Company?

Should Your Email Live In The Cloud? A Comparative Cost Analysis

 
 
RESOURCE CENTER