Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

PCI And The Circle Of Blame: Page 6 of 11

PCI Merchant Compliance Levels
For merchants affected by PCI, size matters. Based on volume of transactions, a merchant is assigned a level from 1 to 4; placement affects PCI requirements. For example, all merchants need quarterly network scans, but only Level 1 merchants must have on-site assessments. All others are on the honor system.

LEVEL ANNUAL VISA/MASTERCARD TRANSACTIONS NO. OF ORGANIZATIONS AT THIS LEVEL IN COMPLIANCE WITH PCI WORKING TOWARD COMPLIANCE JUST BEGINNING PROCESS
Level 1 More than 6 million 326 77% 23% 0%
Level 2 1 million to less than 6 million 709 62% 30% 8%
Level 3 20,000 to 1 million 2,596 54% 20% 25%
Level 4 Less than 20,000 NA NA NA NA
Data: Visa, CyberTrust

GAMING THE SYSTEM

While many retailers use the PCI standard to improve their security postures, the spec has enough holes to let retailers demonstrate compliance without making significant changes to their security practices. A key issue is the number of retail locations that are physically audited by a QSA. The guidelines for Level 1 merchants require individual retail locations to be audited. This is a critical component of the standard, particularly in light of the TJX credit card theft, in which thieves first gained access to the company's systems through the weak wireless network of a single T.J. Maxx retail store.