Seven Deadly Sins of a QSA (Part 15), Be My Valentine? standard
Sin #6 – Q/A Tunnel Vision The Quality Assurance (Q/A) program is in full swing at the PCI Security Standards Council. After companies started taking PCI DSS seriously and retaining QSAs, merchants and service providers realized that not every QSA interpreted requirements the same. One of the biggest complaints about the QSA community is variance in interpretation on key items that could impact the cost of compliance—positive or negative. The Q/A program was announced at the 2008 PCI Community Meeting ((If you are a stakeholder in PCI DSS and are not going to these meetings, you are missing out.)) and began to take effect shortly thereafter. QSAs were put on the remediation list as early as 2009. Myopic Assessment Views The ...
Continue Reading