[Dataloss] Feds seek to nab credit card thieves in La., Miss.
Arshad Noor
arshad.noor at strongauth.com
Tue Aug 19 03:52:12 UTC 2008
Hear, hear! I, overwhelmingly, agree with macwheel99.
When people start taking personal responsibility for the
proper execution of their jobs and business mandates, we
can then expect to see a reduction of such breaches.
However, based on the number of data-loss reports I get
on this forum weekly, I am not optimistic that there are
sufficient people who take this responsibility seriously.
Therefore, the only way for companies to take our personal
data seriously is through legislation that has serious
consequences for failure to protect that data.
Arshad Noor
StrongAuth, Inc.
macwheel99 at wowway.com wrote:
> A company can buy some computer system and not install, or manage, it
> properly.
> I am more interested in whether they had any PCI audits or other security
> audits, and what if anything the audits had to say about their state of
> security preparedness.
>
> Here's what went wrong at TJX Max (click on preview to see document filed by
> 5/3 bank auditor AFTER the mess.) http://www.box.net/shared/ieae3qfqj9
>
> This is quite an eye-opener ... they had perfectly good computer systems,
> but at some level of company leadership, there was no conception of their
> security responsibilities, what it meant to be PCI compliant.
>
> There were TWELVE cyber security standards applicable to TJX.
> They had met THREE of them.
>
> Buying and installing computer systems is not enough.
>
> There has to be informed management of that systems have been properly
> implemented, are doing the job they are intended to do, and continue to do
> so, after any upgrades to related systems.
>
> When that does not happen, we cannot blame the computer vendors. That's like
> blaming an auto manufacturer because a drunk is driving around, on a flat
> tire, with broken lights.
>
More information about the Dataloss
mailing list