Surveys, surveys, surveys...
It seems that I can't read a blog or speak with a vendor about PCI without somebody saying "Let's do a survey!" A number of PCI surveys have come out in the past few weeks, and more are on the way (trust me on this one...). But the question I have is: What does it all mean?
I think the fact that there are all these surveys is a positive sign for PCI compliance. It shows awareness of PCI is high. That's good. Schools and businesses worldwide are figuring out that PCI really applies to them, and if they aren't compliant they better get compliant soon. Now everybody is scrambling to learn what the early adopters have learned so they can focus their efforts and avoid duplicating mistakes. Another positive outcome is that we are beginning to get a better grasp on best practices. That is, now that they are monitoring their logs or improving user training, they are wondering what is next.
I have a confession to make: I am not immune to this survey epidemic. Many of you recall the survey we did as part of the Treasury Institute's PCI Workshop in May. I presented the high-level findings at the workshop. Well, the Institute and NACUBO will be publishing the results in a week or so, and I believe you will find them interesting. We'll also be posting a less polished version of the findings on the Institute's website, so stay tuned.
What do all the surveys mean? I think they mean that PCI awareness has grown; that PCI is in the mainstream; that vendors are scrambling to figure out what you need; and that we all want to learn from each other.
These are good things.
I think the fact that there are all these surveys is a positive sign for PCI compliance. It shows awareness of PCI is high. That's good. Schools and businesses worldwide are figuring out that PCI really applies to them, and if they aren't compliant they better get compliant soon. Now everybody is scrambling to learn what the early adopters have learned so they can focus their efforts and avoid duplicating mistakes. Another positive outcome is that we are beginning to get a better grasp on best practices. That is, now that they are monitoring their logs or improving user training, they are wondering what is next.
I have a confession to make: I am not immune to this survey epidemic. Many of you recall the survey we did as part of the Treasury Institute's PCI Workshop in May. I presented the high-level findings at the workshop. Well, the Institute and NACUBO will be publishing the results in a week or so, and I believe you will find them interesting. We'll also be posting a less polished version of the findings on the Institute's website, so stay tuned.
What do all the surveys mean? I think they mean that PCI awareness has grown; that PCI is in the mainstream; that vendors are scrambling to figure out what you need; and that we all want to learn from each other.
These are good things.

