PCI SSC Launches Internal Security Assessor Program standard

The PCI Security Standards Council announced on Friday the creation of the Internal Security Assessor (ISA) program. If you recall, we had some fun with MasterCard last year when they floated and then retracted some changes in their SDP program. The one change that stuck will be causing a small subset of Level 1 merchants pain—the inability to self-assess. If you recall, Level 1 merchants have always been able to self assess IF they have a C-Level executive sign off on it. Self-assessing sounds attractive until that last part. While the vast majority of Level 1 merchants choose to use a QSA, there are a few that have been self assessing for years. In fact, one colleague in particular discussed ...
Continue Reading