|
|
Security Requirements Beefed Up By MasterCard
MasterCard has made a recent change to their security arrangements that may have dire consequences for its merchants. They have changed an important security requirement for the company for merchants who handle about one to six million card transactions a year.
This rule will be implemented from December 31, 2010 where companies falling in this category will be called Level 2 companies. These companies will have a MasterCard approved assessor carry an onsite review of the company's security controls.
This is in contrast to the present ruling where these merchants need to complete a self test that evaluates their agreement with the requirements of MasterCard's Site Data Protection. At present, only Level 1 merchants, who carry out more than 6 million card transactions a year, have to carry out these onsite tests.
While all major credit card companies have all their merchants agree to a set rule of security requirements, each company has its own standards when it comes to assessing compliance with PCI rules.
This move made by MasterCard, where MasterCard had issued a security ruling before Visa is considered to be an aggressive proponent of PCI. This is why an independent consultant has mentioned that one has to see if this change is the start of a new trend of MasterCard leadership. If this is not the start of a trend, he wonders what had actually prompted MasterCard to make this change.
The reason analysts are wondering what prompted MasterCard to make this move is because of a shortage of assessors to make onsite security tests. He stated that this move will lead to an increase in the demand for quality security assessors and thus complicate matters further.
Another analyst also states that this move by MasterCard was done at the wrong time as there is a growing worry about the expertise of existing third party assessors of the payment industry.
He states that until measures are incorporated to give quality and better standardization of third party assessors and their testing practice, there is not much that will be gained by MasterCard's move of having Level 2 merchants have onsite tests.
He also mentions that there is no proof that with this new ruling, which will cost extra fees to about 3,000 level 2 merchants, is proven. He mentioned that if MasterCard had a group of set assessors, things would have also been different.
So far, it is not known what made MasterCard do these changes. Even requests for comments placed to MasterCard had no answers.
|
 |
Please Rate: |
 |
Rating: |
 Processing ...
|
(Average: Not rated) |
| Views: | 54 | |
 |
| More Articles from Security | |  |
| Top Articles in Security | |  |
|