In a country that's seen many regulatory compliance challenges this decade, the headaches of PCI security tend to be analyzed from a largely American perspective.
In the process, companies tend to forget that PCI compliance has been a recipe for international indigestion.
"Remember that credit cards are used abroad, and many American companies have personnel handling credit card transactions in offices all over the world," says Bruce Larson, security director at American Water, a major water utility that employs more than 10,000 people. "If you have a multinational organization, your data is not just sitting in the US."
There may be some irony in hearing that from someone whose concerns are mostly based on security threats inside the US. Larsen has to worry about everything from cyberattacks targeting computerized water filtration systems to terrorists who might try to bomb pipelines or poison the water supply. He also loses sleep whenever there's the chance of a natural disaster.
The inconvenience of online, global commerce
But more people are using credit cards to pay the water bill online, and he knows the credit card data is floating around in databases outside the US. Losing any of that data could be a body blow in terms of public confidence. Then there's the fact that American Water does business with vendors across the globe.
"I have a very geographically distributed network -- more than 1,500 locations where humans work, 150-200 of those are critical operations facilities," Larson told attendees during a PCI security seminar in September.
For Harshul Joshi, director of IT-risk and advisory services at CBIZ and Mayer Hoffman McCann P.C. (MHM), a professional business services company, doing business internationally can make for a lot of confusion regarding the PCI security ground rules.
"When we deal with non-US companies, there is often confusion over what PCI security requires," Joshi says. "We work with one of the largest magazine publishers with operations around the globe and if you dial an 800 number, chances are you'll be talking to someone in a call center in Vietnam. You give your credit card number and it is recorded somewhere outside the US."
On the outside looking in
If a company is based outside the US -- in Sweden or Ukraine, for example -- the problem is usually a lack of communication and money regarding PCI security needs.
Latest on Security
- Data breaches rose sharply in 2008, says study
- Researchers hack into Intel's vPro
- Security predictions for 2009
- The top tech resolutions for 2009
- Stephen Fry hit by Twitter ID hack
- 10 breakthroughs in IT security
- With Gaza conflict, cyberattacks come too
- Microsoft explains how it missed critical IE bug
- Auditor: IRS doesn't check cyberaudit logs
- The 7 deadly sins of IT management
Security Essentials
- Good security in recessionary times
- Security ROI: Fact or Fiction?
- NetWitness releases free version of security software
- Study: critical infrastructure often under cyberattack
- Crooks can make $5M a year shilling fake security software
- Sun exec: IT security should follow business needs
- Clumsy staff more dangerous than hackers: survey
- When the watchdog is the underdog
- Mafiaboy grows up; a hacker seeks redemption
- Ouch! Security pros' worst mistakes
TechWorld Jobs (beta)
Whitepapers
TechWorld Blogs
-

TalkingTech
The view from the top of IT with TechWorld Editor Rodney Gedda
-

Entrenched
Cooking up better code, IDG's developers reveal some of their secrets
-

Broadband Voice
Darren Pauli digs in from the front line of Australia's broadband battleground
Recent blog posts
- Telstra kicked out of NBN process
- Linux on the iPhone won’t change the world - yet
- A Novell approach to business
- An open storage stack? I like the sound of that
- The mobile clone wars: fighting for a better phone experience
- Stopping the "Clean Feed"
- Identifying web platforms
- Clean Feed ‘not technically possible’
- No Clean Feed - well duh!
- Conroy's content cops still on the cards
Recent comments
- video converter os x
12 hours 28 min ago - video converter os x
12 hours 33 min ago - video converter os x
12 hours 41 min ago - video converter os x
12 hours 41 min ago - video converter os x
12 hours 42 min ago - video converter os x
12 hours 42 min ago - video converter os x
12 hours 48 min ago - video converter os x
12 hours 49 min ago - video converter os x
12 hours 50 min ago - video converter os x
12 hours 52 min ago - video converter os x
12 hours 53 min ago - video converter os x
12 hours 55 min ago - video converter os x
12 hours 57 min ago - video converter os x
12 hours 59 min ago - video converter os x
13 hours 2 min ago - video converter os x
13 hours 3 min ago - video converter os x
13 hours 5 min ago - video converter os x
13 hours 5 min ago - video converter os x
13 hours 6 min ago - video converter os x
13 hours 6 min ago







