<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!--Web 2.0 Content Powered by MyST Blogsite® (http://blogsite.com)-->
<!--A service of MyST Technology Partners, Inc. (http://myst-technology.com)-->
<?xml-stylesheet href="http://blog.solidcore.com/public/styles/etc/object.xsl" type="text/xsl"?>

<?myst-baseUrl http://blog.solidcore.com/public/?>

<MySmartChannels Public="true" UserID="183000" dT="55" t0="1227328061595">
     <GetChannelItem_Result>
      <Item>
       <Resource>
        <ObjectID>185466</ObjectID>
        <ObjectClass>Resource</ObjectClass>
        <OwnerID ObjectClass="Domain" Title="[Weblog] IT Compliance">183005</OwnerID>
        <CreatedByID ObjectClass="User" Title="erinswanson">183122</CreatedByID>
        <ModifiedByID ObjectClass="User" Title="erinswanson">183122</ModifiedByID>
        <CreateTime Title="2007-10-05 19:36:26 EDT">1191627386512</CreateTime>
        <ModifyTime Title="2007-10-07 16:49:32 EDT">1191790172337</ModifyTime>
        <SecurityModel>Controlled</SecurityModel>
        <Name>NRF Resists PCI Compliance Requirements</Name>
        <Summary>The National Retail Federation (NRF) resisting current PCI compliance requirements</Summary>
        <Description>&lt;p&gt;The PCI compliance debate is heating up between the NRF (National Retail Federation) and the credit card companies.&amp;nbsp; In a letter to the PCI Security Standards Council, the &lt;a title="Retail group takes a swipe at PCI, puts card companies 'on notice'" href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9040958&amp;pageNumber=1" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;CIO of the NRF, David Hogan, asked credit card companies to stop forcing retailers to store payment card data&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp; According to Hogan, retailers must &lt;strong&gt;&amp;ldquo;jump through hoops to create an impenetrable fortress&amp;rdquo;&lt;/strong&gt; to protect card data.&amp;nbsp; &lt;/p&gt;&lt;p&gt;Hogan goes on to make some interesting arguments about credit card information and privacy, such as &lt;a title="Retain lobby offers alternative to PCI standard" href="http://www.scmagazineus.com/Retail-lobby-offers-alternative-to-PCI-standard/article/35984/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;&amp;ldquo;... if the goal is to make credit card data less vulnerable, the ultimate solution is to stop requiring merchants to store data in the first place.&amp;quot;&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;p&gt;He is proposing a plan in which credit card companies would allow merchants to only store authorization codes and a truncated, or shortened, receipt of the sale. This would save them time and money associated with complex requirements such as encryption.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;This is a great idea and&amp;nbsp;one worthy of creating an entirely new market and/or business.&amp;nbsp; If I could &lt;strong&gt;store a digital authorization that would work only with a certain vendor for a certain period of time, I'd sign up immediately&lt;/strong&gt;.&amp;nbsp; No longer would I need to provide my credit card or bank account number for recurring payments.&amp;nbsp; Instead, I could potentially create specific authorizations through my online banking account and use it for online transactions.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;So, why are we not moving to such a model?&amp;nbsp; Even though the technology to do this is available, this requires, in Hogan's own words, &amp;quot;... &lt;a title="Retain group takes a swipe at PCI, puts card companies 'on notice'" href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9040958&amp;pageNumber=1" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;a very fundamental shift&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&amp;rdquo;.&amp;nbsp; &lt;/p&gt;&lt;p&gt;I concur because training hundreds of millions of users to digital authorization codes instead of credit cards is &lt;strong&gt;&lt;u&gt;not&lt;/u&gt; something that can be accomplished overnight&lt;/strong&gt;.&amp;nbsp; Even if a large vendor like RSA decides to push this aggressively, we are still looking at &lt;strong&gt;a few years&lt;/strong&gt; for such a vision to become reality.&amp;nbsp; &lt;/p&gt;&lt;p&gt;So, David Hogan, how are you planning to protect my credit card information until then?&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Please note: most regulatory initiatives are met with resistance from the affected parties.&amp;nbsp; Such a reaction is natural because of the high cost involved in becoming compliant and the fact becoming compliant does not contribute to any bottom line growth.&amp;nbsp; However, most regulatory initiatives have resulted in better governance and processes in the long-term and even though the results may not be tangible, they are by no means insignificant.&amp;nbsp; &lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Raj Rajamani, Product Management&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Raj@solidcore.com"&gt;&lt;strong&gt;&lt;u&gt;Raj@solidcore.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</Description>
        <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
        <ContentType>application/xml</ContentType>
        <ContentDocument>
         <ItemProperties>
               <CommonProperties>
                <Hidden>false</Hidden>

                <Keywords>
                 <Keyword>NRF</Keyword>

                 <Keyword>PCI compliance</Keyword>

                 <Keyword>PCI compliance requirements</Keyword>

       </Keywords>

                <Links>
                 <Link>
                  <Title>Retail group takes a swipe at PCI, puts card companies 'on notice'</Title>

                  <Synopsis>Stop forcing retailers to store payment card data, it warns card companies</Synopsis>

                  <URL>http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9040958&amp;pageNumber=1</URL>

        </Link>

                 <Link>
                  <Title>Retail lobby offers alternative to PCI standard</Title>

                  <Synopsis>SC Magazine article on an alternative to the PCI standard from the retail lobby</Synopsis>

                  <URL>http://www.scmagazineus.com/Retail-lobby-offers-alternative-to-PCI-standard/article/35984/</URL>

        </Link>

       </Links>

      </CommonProperties>

               <RemoteInfo>
                <UserAgent>Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)</UserAgent>

                <RemoteHost>127.0.0.1</RemoteHost>

                <RemoteAddr>127.0.0.1</RemoteAddr>

                <RemoteUser>erinswanson</RemoteUser>

      </RemoteInfo>

     </ItemProperties>
        </ContentDocument>
       </Resource>
       <Shares/>
       <Subjects/>
       <UserPermissions>
        <CanDelete>false</CanDelete>
        <CanDiscover>true</CanDiscover>
        <CanEdit>false</CanEdit>
        <CanEditPermissions>false</CanEditPermissions>
        <CanRead>true</CanRead>
       </UserPermissions>
       <CommentInfo>
        <CommentChannelRef AllowAnonymous="true" Inherited="true">
         <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">183020</ChannelID>
         <UserPermissions>
          <CanCreateChannelItem>false</CanCreateChannelItem>
          <CanDelete>false</CanDelete>
          <CanDiscover>true</CanDiscover>
          <CanEdit>false</CanEdit>
          <CanEditPermissions>false</CanEditPermissions>
          <CanPublish>false</CanPublish>
          <CanRead>true</CanRead>
         </UserPermissions>
        </CommentChannelRef>
        <Comments/>
       </CommentInfo>
       <Views>
        <SourceID ObjectClass="Channel" Title="[Weblog] IT Compliance">183005</SourceID>

               <View>
                <Name>blog</Name>

                <Model>blogsite/SolidCore/web</Model>

                <Style/>

                <Scheme/>

       </View>

      </Views>
        <Views>
         <SourceID ObjectClass="Channel" Shared="true" Title="[Public] What's New">183014</SourceID>

                <View>
                 <Name>blog</Name>

                 <Model>blogsite/SolidCore/whatsnew</Model>

                 <Style/>

                 <Scheme/>

       </View>

      </Views>
        </Item>
       </GetChannelItem_Result>
      </MySmartChannels>
