<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Why PCI Has Not Reduced Fraud</title>
	<atom:link href="http://www.storefrontbacktalk.com/securityfraud/why-pci-has-not-reduced-fraud/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.storefrontbacktalk.com/securityfraud/why-pci-has-not-reduced-fraud/</link>
	<description>Techniques, Tools and Tirades about Retail Technology and E-Commerce</description>
	<lastBuildDate>Fri, 19 Mar 2010 23:24:36 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: joel weise</title>
		<link>http://www.storefrontbacktalk.com/securityfraud/why-pci-has-not-reduced-fraud/comment-page-1/#comment-61933</link>
		<dc:creator>joel weise</dc:creator>
		<pubDate>Thu, 18 Jun 2009 15:06:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=3190#comment-61933</guid>
		<description>I think this position is hard to quantify with respect to an actual security ROI - PCI s/b viewed within the context of a larger defense in depth strategy (and especially collectively for the community at large).  as such and with any batch of stats one can argue both ways - I for one see value in PCI - if and when it is applied correctly, i.e., when driven by a risk based approach.</description>
		<content:encoded><![CDATA[<p>I think this position is hard to quantify with respect to an actual security ROI &#8211; PCI s/b viewed within the context of a larger defense in depth strategy (and especially collectively for the community at large).  as such and with any batch of stats one can argue both ways &#8211; I for one see value in PCI &#8211; if and when it is applied correctly, i.e., when driven by a risk based approach.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Mahoney</title>
		<link>http://www.storefrontbacktalk.com/securityfraud/why-pci-has-not-reduced-fraud/comment-page-1/#comment-61894</link>
		<dc:creator>Tom Mahoney</dc:creator>
		<pubDate>Thu, 18 Jun 2009 02:26:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=3190#comment-61894</guid>
		<description>I&#039;m having a problem getting my head around the concept that PCI reduces fraud for the merchant in compliance.  Maybe in a remotely peripheral sense if a few of the hacked cards resulting from non-compliance are used against the merchant from whom they are stolen.  

I don&#039;t see any other ROI for an individual merchant unless they are breached and were not in compliance.  Then, the ROI in the form of avoided fines can be significant.

I&#039;m not against PCI compliance and I&#039;d agree that overall it can certainly reduce fraud collectively for the merchant community.  But to say that it will reduce fraud for the merchant in compliance is a stretch.

Tom Mahoney, Director
Merchant911.org</description>
		<content:encoded><![CDATA[<p>I&#8217;m having a problem getting my head around the concept that PCI reduces fraud for the merchant in compliance.  Maybe in a remotely peripheral sense if a few of the hacked cards resulting from non-compliance are used against the merchant from whom they are stolen.  </p>
<p>I don&#8217;t see any other ROI for an individual merchant unless they are breached and were not in compliance.  Then, the ROI in the form of avoided fines can be significant.</p>
<p>I&#8217;m not against PCI compliance and I&#8217;d agree that overall it can certainly reduce fraud collectively for the merchant community.  But to say that it will reduce fraud for the merchant in compliance is a stretch.</p>
<p>Tom Mahoney, Director<br />
Merchant911.org</p>
]]></content:encoded>
	</item>
</channel>
</rss>
