Why ISAs are Good for QSAs standard

The PCI Security Standards Council recently announced their Internal Security Assessor program (ISA) ((Side note… everyone seems to dog pile on the Standard when people reference it as a SECURITY standard, but nobody dog piles on the Council for using security in the assessor acronyms?)) and it seems like the response is overall positive. I have spoken to a few QSAs that are afraid this may contribute to a decline in the business as there is dissension in the ranks of those being assessed ((Quality in QSAs is a current problem being addressed by the Q/A program.)). ISAs are GOOD for QSAs, and as a QSA you should prefer to assess companies that have installed them in their teams. I ...
Continue Reading