Spend an Hour Now…Earn Double That Later!
As I’ve been traveling the country lately, I’ve been learning more and more about how the PCI-DSS requirements are affecting businesses. There does still seem to be quite a bit of mis-informatin as well as a lot of questions. As a result, I’ve been changing the focus a bit.
I really do think companies should spend more time in training on PCI. There is no better training, in my opinion, than that provided by auditors who have actually been in the field conducting audits. By investing in training, staff and management can get a better understanding of security implications, the audit process, and why the PCI requirements are so important. As a bonus, doing so will also aid in meeting PCI-DSS requirement 12.6 - “Implement a formal security awareness program to make all employees aware of the importance of cardholder data security.” This training should be provided to everyone in the company, not just a select few. I’ve found that companies that take this approach get better cooperation from their employees and have an easier time making it through the audit.
Next, management should get involved regularly in user groups and public forums. Myself, and many other auditors like me, frequently respond to posts on sites such as the PCI Knowledge Base. The beauty of these public forums is that others can benefit from similar inquiries. In addition, we’ve all seen how different auditors have different points of view on various topics. This unfortunately feeds some of the misinformation. Public forums, like the PCI Knowledge Base, can help combat that as auditors will discuss their reasonings behind their points of view and challenge one another in hopes of coming to a more unified/educated approach.
I know time is valuable, but spending a few hours now on these suggestions will offer great returns in both the security of your data and offering a more pleasant experience during your audits.

