PCI FAQs When You’re Starting Your Compliance Program - Episode 230

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

Think PCI compliance is something you can outsource? Think again. Todd Coshow and Adam Goslin break down the biggest misconceptions about PCI DSS, from third-party payment processors and SAQs to merchant versus service provider responsibilities. Learn why outsourcing payment processing doesn't eliminate your compliance obligations, how scope really works, and why treating PCI as a one-time paperwork exercise creates unnecessary risk. This episode is essential listening for merchants, service providers, and anyone navigating PCI compliance for the first time.


Episode Transcript:

Now, Adam, a long time ago in a land far, far away, there was a time where you asked the question, “What is PCI?” So bring the listeners up to speed on that.

Adam Goslin:
Everybody gets their start somewhere, and PCI was definitely mine.

I had kinda made my way up the IT management ranks. Boss comes by. Don’t ask me why, he decided to print the entirety of the PCI standards, but literally drops a four-inch deck of paper on my desk and says, “Hey, we need to get compliant with this.”

I’m looking at the cover page, and it says PCI on it, and I literally said, “What’s PCI?”

So that was my entree into the land of security and compliance.

I sat there staring at this volume of information and wondering, “What the hell do I do with this? Where do I go? How do I start?” etc.

It’s part of why I decided to step into the space to help people, because I clearly remember just how overwhelming it felt to be looking at that much stuff, not having any clue what the hell it was, what it meant, what it’s for, does it even apply to us, etc.

All the way around, it was very overwhelming to step into the compliance arena not already having been initiated.

TCT has, both I and TCT have kinda specialized in PCI since our inception, and the consulting work that I was doing for folks in the space, the history of the consulting practice goes back even further than PCI’s existence.

As we were sitting there and contemplating the types of things that organizations new to the space are facing, we decided to put together this almost like a frequently asked questions when you’re getting a compliance program off the ground.

Frequently asked PCI questions when you’re getting a compliance program off the ground.

Todd Coshow:
Does PCI apply to merchants who outsource all payment processing?

Adam Goslin:
It’s one of the common questions that I’ll get.

They’ll be like, “Oh, well, we don’t touch anything. We go ahead and outsource all of our payment stuff to blabbity-blah. That’s not my problem, and PCI doesn’t apply to us.”

The answer is you’re wrong.

Companies that are not storing, processing, transmitting, or receiving cardholder data, they still are subject to the PCI DSS.

One of the biggest misunderstandings is, sure, there’s some technical elements of how you’ve done what you’ve done in terms of the connectivity. The devil’s always in the details.

If you have a merchant account that is in any way, shape, or form receiving payments via credit cards, then you too get to fill out your PCI paperwork.

That’s one of the biggest misunderstandings that organizations have.

Honestly, a lot of the big names that have come out in the space over time, the Stripes, the Squares, the Intuits, if you will, back in the day, it was like the Wild West.

“Well, I’ll just go get a Stripe account, so I don’t have to worry about this.”

“Go process my stuff through Intuit, that way I don’t have to worry about it.”

The unfortunate part is that those organizations were on this mad race to get people to jump over to their platform and process their stuff via their platform, but they weren’t really doing a great job with enforcing, mandating that people were actually following the PCI DSS.

That kind of became a problem for a while because they were able to go in and easily turn it on, etc., and there wasn’t any enforcement arm that was coming at them.




Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(233)

Join TCT at the PCI-NACM in Vancouver - Episode 233

Join TCT at the PCI-NACM in Vancouver - Episode 233

PCI has evolved from checkbox audits toward continuous assurance, but are organizations truly keeping pace? Todd Coshow and Adam Goslin explore how AI, cloud-native payments, software supply chain ris...

10 Sep 14min

PCI Engagement Masterclass - Episode 232

PCI Engagement Masterclass - Episode 232

On this week's Compliance Unfiltered, PCI engagement chaos doesn’t have to be the norm. Todd Coshow and Adam Goslin explore how smarter compliance workflows can eliminate repetitive evidence collectio...

3 Sep 33min

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

On this episode of Compliance Unfiltered, AI can speed up policy drafting, but it can also create hidden compliance risk when no one validates the result. Listen, as Todd Coshow and Adam Goslin discus...

27 Aug 25min

The Control Worked Yet The Company Still Got Breached - Episode 229

The Control Worked Yet The Company Still Got Breached - Episode 229

Passing an audit doesn't mean you're secure. In this episode of Compliance Unfiltered, Todd Coshow and Adam Goslin expose the critical gap between compliance and real cybersecurity. Learn why controls...

13 Aug 24min

Government AI Regulations That Could Impact Your Company - Episode 228

Government AI Regulations That Could Impact Your Company - Episode 228

AI regulation is no longer a future problem. It’s creating legal, financial, and product risk today. Todd Coshow and Adam Goslin break down the evolving AI regulatory landscape, from FTC enforcement a...

6 Aug 29min

Making Sure Your Compliance Program Keeps Up - Episode 227

Making Sure Your Compliance Program Keeps Up - Episode 227

Compliance is changing fast, and many organizations are already behind without realizing it. In this episode, Todd Coshow and Adam Goslin break down why AI, cybersecurity, privacy, and third-party ris...

30 Juli 21min

Ready to Get Serious About Compliance? - Episode 226

Ready to Get Serious About Compliance? - Episode 226

Compliance doesn't have to be expensive, slow, or overwhelming. In this episode, the CU Guys reveal the blueprint for building a successful compliance program from the ground up. Learn why the right p...

23 Juli 36min

Populärt inom Teknik

uppgang-och-fall
elbilsveckan
market-makers
rss-laddstationen-med-elbilen-i-sverige
rss-elektrikerpodden
rss-en-ai-till-kaffet
gubbar-som-tjotar-om-bilar
rss-veckans-ai
rss-technokratin
natets-morka-sida
bilar-med-sladd
skogsforum-podcast
bli-saker-podden
developers-mer-an-bara-kod
hej-bruksbil
rss-uppgang-och-fall
rss-sakerhetspodcasten
rss-digitala-influencer-podden
rss-it-sakerhetspodden
rss-nytankarna