Acceptable Losses, a Customer Perspective standard
I recently did some work for a customer that had an interesting perspective on the physical security of devices. We were talking about putting some specific controls in place to hold encryption keys, and when we mentioned that we could put them on little USB sticks (not an HSM, but think like that), they said “Oh, if we do that they will disappear from the stores.” Employee or customer theft of devices sure does not come up as something we deal with every day. This particular company ran largely a cash-based business, and had a very small group of customers that paid by credit card. They were actually considering completely dropping all credit card acceptance because of the added risk ...
Continue Reading