PCI Compliance: Implementing Effective PCI Data Security Standards

Generally speaking, the best approach to any industry or government regulatory requirement has been to find a middle ground in terms of effort and cost to meet the spirit of the requirement, and then work with the auditor ahead of audit time to see how you ve done. Generally, that approach reaps rewards that pay off in reduced patching of the effort. Obviously, meeting with the auditor before you start makes a lot of sense, but making certain the results meet with the auditor s approval is where your Return on Investment (ROI) will show up. If the auditor is happy, then the card issuer will be happy.
This is certainly true where Requirements 10 and 11 of the Payment Card Industry (PCI) requirements come into play Requirement 10, Monitoring, and Requirement 11, Testing, are easily capable of inflating PCI compliance costs to the point of consuming the small margins of card transactions. No one wants to lose money to be PCI compliant. Therefore, the ability to meet the requirements above all must make business sense. Nowhere else in PCI compliance does the middle ground of design philosophy more come into play than in the discipline of monitoring, but this is also where minimizing the risk can hurt most.
PCI Data Security Standard (DSS) Requirement 10 states: Track and monitor all access to network resources and cardholder data . The requirement around monitoring is potentially broad and far-reaching, but there are boundaries to be determined, and that...