Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Most Organizations Fall Short On PCI DSS, Verizon Reports: Page 2 of 2

  • Requirements 3 and 11 were at the bottom in the 2010 report, as well. The continued poor compliance with Requirement 11 is typical of the "set and forget" approach, as opposed to continuous compliance, the report observes, and the lack of security policies, which drive practice, is disturbing.

    The strongest requirements in terms of initial compliance were:

  • Requirement 4: Encrypt transmissions over public networks (72%)
  • Requirement 5: Use and update anti-virus (64%)
  • Requirement 7: Restrict access to need-to-know (75%)
  • Requirement 9: Restrict physical access (55%)

    The report notes that with anti-virus, some organizations may use acceptable compensating controls, such as whitelisting technology. The report also found that organizations analyzed in the Verizon Data Breach Investigations Report showed a generally lower rate of PCI compliance across most requirements, indicating a correlation between poor compliance and weak security.

    Although only a fifth of the companies were 100% compliant initially, more than a third passed between 90% and 99% of the tests. On the down side, one in five organizations passed fewer than 50% of the tests.

    See more on this topic by subscribing to Network Computing Pro Reports Strategy: Security via Compliance (subscription required).