Quantcast StorefrontBacktalk - Full Text Of The Proposed PCI 1.2
E-Mail Us
Full Text Of The Proposed PCI 1.2
Written by StorefrontBacktalk Full Text Service
August 22, 2008
PCI DSS 1.2 CHANGES SUMMARY


FINAL


INTRODUCTION AND PURPOSE


The PCI Security Standards Council has announced that version 1.2 of the PCI Data Security Standards will be available for general use October 1, 2008. The purpose of this document is to provide high level guidance on the changes to be brought about with this key milestone standard revision. Version 1.2 is an update to the current version 1.1 and follows the established approved lifecycle process, which provides for revisions or new versions on a 24 month cycle. While version 1.2 will not introduce any major new requirements, it will include clarifying items designed to fulfill the following goals inherent to the PCI Data
Security Standard:
  • Provide greater clarity on PCI DSS requirements

  • Offer improved flexibility

  • Manage any evolving risks and threats

  • Incorporate best practices

  • Clarify scoping and reporting

  • Eliminate redundant sub-requirements

  • Consolidate documentation



  • SUMMARY OF CHANGES


    As noted above, the revisions to version 1.2 do not incorporate any new major requirements. Therefore the changes summarized below reflect the same six guiding principles and 12 requirements currently in force under version 1.1. Note that this summary of changes does not include all changes made in version 1.2. The PCI Security Standards Council reserves the right to make final revisions to version 1.2 prior to publication; this summary is for initial preview purposes only, and does not supersede PCI DSS v1.1. Once PCI DSS v1.2 is publicly released, PCI DSS v1.2 will be the official version and further guidance will be provided about effective and sunset dates.


    Build and Maintain a Secure Network


    Requirement 1: Install and maintain a firewall configuration to protect cardholder data
  • Clarified requirement to illustrate that all sub-requirements apply to both routers and firewalls

  • Combined requirements and sub-requirements to clarify requirement 1

  • Added flexibility in the time frame for review of firewall rules, from quarterly to every 6 months, based on Participating Organization feedback. Now the control can be better customized to the organization's risk management policies.




  • Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters
  • Clarified that the requirement applies to wireless environments "attached to cardholder environment or transmitting cardholder data.

  • Removed references to WEP in order to emphasize using strong encryption technologies for wireless networks, for both authentication and encryption

  • Removed requirement to disable SSID broadcast since disabling SSID broadcast does not prevent a malicious user from determining the SSID, as the SSID is broadcast over numerous other messaging/communication channels.



  • Protect Cardholder Data


    Requirement 3: Protect stored cardholder data
  • Emphasized use of consistent terms throughout, such as "PAN" and "strong
    cryptography"

  • Clarified requirement for disk encryption to emphasize local user account databases


    Requirement 4: Encrypt transmission of cardholder data across open, public networks

  • Wireless must now be implemented according to industry best practices (e.g., IEEE 802.11x) using strong encryption for authentication and transmission.

  • New implementations of WEP are not allowed after March 31, 2009.

  • Current implementations must discontinue use of WEP after June 30, 2010 Maintain a Vulnerability Management Program



  • Requirement 5: Use and regularly update anti-virus software
  • Clarified that requirement for use of anti-virus software applies to all operating system types
  • Clarified that anti-virus software must address all known types of malicious software



  • Requirement 6: Develop and maintain secure systems and applications
  • Added flexibility to the patching requirement by specifying that a risk-based approach may be used to prioritize patch installation



  • Requirement 6.6 is now mandatory. All public-facing web applications are subject to either 1) reviews of applications via manual or automated vulnerability assessment tools or methods, or 2) installing an application-layer firewall in front of public-facing web applications.


    Implement Strong Access Control Measures


    Requirement 7: Restrict access to cardholder data by business need-to-know
  • Clarified language around testing procedures




  • Requirement 8: Assign a unique ID to each person with computer access
  • Clarified that testing procedures must verify that passwords are unreadable in storage and transmission

  • Clarified user authentication by allowing both passwords and passphrases, and by combining previous bullets under "two-factor authentication" and providing examples



  • Requirement 9: Restrict physical access to cardholder data
  • Specified that offsite storage locations must be visited at least annually

  • Provided flexibility in the requirement for cameras to allow organizations to select other appropriate access control mechanisms

  • Clarified that the requirement to secure media applies to electronic and paper media that contains cardholder data

  • Clarified destruction requirements for media containing cardholder data Regularly Monitor and Test Networks



  • Requirement 10: Track and monitor all access to network resources and cardholder data
  • Clarified that logs for external facing technologies (for example, for wireless, firewalls, DNS and mail) must be copied to an internal log server

  • Provided flexibility and clarified that three months of audit trail history must be immediately available for analysis" or quickly accessible (online, archived or restorable from backup)



  • Requirement 11: Regularly test security systems and processes
  • Provided more guidance on use of wireless analyzers and/or wireless intrusion detection or prevention systems

  • Outlined that ASVs must be used for quarterly external vulnerability scans

  • Specified that both internal and external penetration tests are required and clarified that it is not required to use a QSA or ASV for penetration tests
  • Maintain an Information Security Policy


    Requirement 12: Maintain a policy that addresses information security
  • Expanded list of examples of critical employee-facing technologies to include "remote access technologies, wireless technologies, removable electronic media, email usage, internet usage, laptops, and Personal Data Assistants (PDAs)"

  • Updated timeframe that requires employees to acknowledge that they have read and understood the company's security policy and procedures to "at least annually"

  • Updated former "contract" and "connected entities" language to clarify that organizations must have policies and processes implemented to manage and monitor service providers.



  • VERSION 1.2 RELEASE SCHEDULE

    The entire PCI DSS version 1.2 (or "Security Assessment Procedures" version 1.2 that comprise the standard) along with supporting documentation will be made available to Participating Organizations the first week of September 2008. It will be discussed in further detail at the Council's Community Meeting in Orlando, Fla. September 23-25, 2008. Release of the standard will be made public October 1, 2008 and follow on discussions will take place at the Council's second Community Meeting, in Brussels, Belgium, October 22- 23, 2008. Please note that only representatives from Participating Organizations, QSAs,
    ASVs, and PED labs can attend the Council's Community Meetings and organizations interested in learning more about PCI DSS version 1.2 and related security standards are encouraged to join as a Participating Organization. Information can be found on the Council's Web site (www.pcisecuritystandards.org) or by emailing the Council at participation@pcisecuirtystandards.org."

    E-Mail StorefrontBacktalk Editor Evan Schuman at
    eschuman@storefrontbacktalk.com
    Search Through Blog Blurbs
    Search Through All Stories
    Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly newsletter, with urgent bulletins as news merits.
    StorefrontBacktalk will never sell your E-mail address to anyone at anytime.
    Evan Schuman is the former retail technology editor for eWEEK.com, PCMagazine, CIOInsight and retail reporter for RISNews and Consumer Goods Technology. Having covered IT issues for 21 years - and other stuff like legal affairs, politics, Wall Street and the environment for about eight years before that - Schuman is in a good position to gripe about technology trends and sometimes accidentally make a good point.
    Questions Surround Some 8,000 Macy's Debit Cards That Got Charged Repeatedly
    Questions dominate a Dec. 20 incident where some 8,000 Macy's customers had their debit cards charged as many as three times for the same transaction. One source said it involved a payment processor's slowdown.
    Did The Affluent Turn Their Back On E-Commerce This Season?
    Some of the latest stats pouring in from the 2008 holiday shopping season are raising some interesting trends, including a sharp (not-before-seen) increase in traffic right after Dec. 25 along with a much deeper cut in site visits from those earning more than $150,000/year.
    Amazon Cuts Off Bill Me Later
    Amazon.com issued a statement on Thursday (Dec. 30) giving its customers fewer than 12 hours' hours notice that it was cutting off Bill Me Later as a payment option as of Dec. 31. The highly anticipated move was a result of Ebay's purchase of Bill Me Later in October.
    E-Commerce Sales Dropped 3 Percent For Holiday Season '08, Worse Than Expected
    E-Commerce holiday purchases this year dropped 3 percent from the corresponding period last year, hitting $25.5 billion, according to ComScore.
    Did Melding With Sister Sites Sour Customer Perception of Gap.com?
    Allowing customers of Gap.com to easily jump to other Web sites in the Gap family, and put all their selections in one shopping cart, undermined perception of the brand and eroded user satisfaction, said the president of a company that tracks E-tail site satisfaction.
    E-tailers Lose Free Ride On Google Checkout
    For years, Google has given its Google Checkout service to retailers for free, as long as they bought ads on Google. Alas, no more. Explained one Google manager: "Why have it as a loss leader if it's doing OK? We saw very healthy results after we decided to charge for the service."
    E-Sales Up? Apparently. Is This Good News? That's A Big Maybe
    Amidst the avalanche of downright depressing retail economic news this holiday season, there are recurring hints that E-tailers—as a group—fared far better. But because we're starving for any sign of optimism, are we interpreting those signs unrealistically?
    Research Group Projects M-Commerce Sales To Hit $8.6 Billion In Five Years
    As retailers debate how much they truly want to embrace mobile payment efforts, the Mercator Advisory Group is reporting that the tide will soon become unavoidable.
    Will Next-Gen CRM Focus On Consumer Emotions?
    Extensive analysis of a consumer's Web interactions has been used for years to try and target sales pitches more effectively. But new research suggests that such analysis may pale in comparison to the next wave, where every digital comment made by consumers anywhere—in a product comment, an IM, on a social network site, in E-mail and via exchanges with a live chat tech support person, coupled with Web traffic analysis—can be mined for hints as to their emotions and other thoughts.
    Australian Retailers Resisting EPC
    Tracking global retail from the United States, it's clear that Canada is the country most similar to the United States when it comes to retail procedures. Surprisingly, the next closest region is not the United Kingdom but Australia, and then arguably South Africa. So it's always interesting to see the few technology areas where American and Australian retailers diverge, and EPC is shaping up to be one of them.
    Metro Group, Kraft, Nestle And P&G Hook Up In Russia With Data Sync Deal
    Kraft Foods, Nestle and Procter & Gamble are now able to synchronize item data with Metro Group stores in Russia, a collaborative effort being touted by the players as a "landmark" deal that illustrates the rapid expansion of the Global Data Synchronization Network (GDSN). Not all are convinced, though.
    From The Poker Table To Greeting Cards? The RFID Future
    The story of the technologist who crafted an elaborate RFID poker table, complete with an HD camera to stream real-time games globally, is interesting mostly in how he attached ultra-thin and extra-flexible RFID tags to each playing card in such a way as to make it not interfere with the way the cards felt. But does it have implications for the future of retail?
    J.Crew, OfficeMax, Blackwell To Get Coal In Their Uptime Stockings
    'Tis the season to be jolly. Unless you're in charge of uptime at upscale retailer J,Crew's Web site. Having suffered outages during Cyber Monday, J.Crew again became unavailable—to at least some prospective customers—for an extended period Wednesday (Dec. 17).
    Comparison Site Visits Down 15 Percent From Last Season
    Despite the putrid economy and the tightening of holiday shopping lists globally, the number of site visits logged in at comparison shopping sites has gone down sharply, some 15 percent lower than was recorded during last year's identical period, according to Hitwise. More logically, Hitwise found an even larger increase—25 percent—in the number of visits to Web coupon sites this year.
    Gartner: The Future Of Retail IT Is Mixed
    In a sharply down economy, retail IT budgets are going to go on a roller coaster ride in the need for greater efficiency. And given how small a percentage of corporate spending is typically represented by the IT capital expenditure budget, IT will probably feel less of the pain than many other divisions. But...
    Visa Mobile Moves On Android And Its One Phone
    Visa Mobile on Monday (Dec. 15) threw a major endorsement behind Google's Android mobile OS, pledging that its mobile payments offerings will run on any phone based on Android. As of this week, though, that's a total of one: the T-Mobile G1 phone.
    OfficeMax Hit With 30 Percent Out-Of-Stock Losses
    One of every three customers walking into an Office Max store to buy a consumer electronics product left empty-handed (and probably bitter) this year because the product was unavailable, according to new research by IHL Group. But Office Max certainly wasn't alone in the research company's hall of shame, with Office Depot and Circuit City keeping it company.
    Cyber Monday Deals Notwithstanding, Onerous Checkouts Deep Six Conversions
    On the one hand, many clicks on a retailer Web site indicate user engagement. And that's a good thing, unless cumbersome site design is forcing users to click unnecessarily. In its recent audit of Cyber Monday shopper activity, site-monitoring company ClickStream Technologies found that too many clicks during the checkout process prompt frustrated buyers to wriggle from the hook.
    In Down Times, Are Employees Approving Too Many Suspect Transactions?
    Online retailers are relying too little on automation to thwart online fraud, meaning too many employee hours are spent reviewing orders that shouldn't have raised any flags of suspicion.
    Gift Card Exchange Site Leverage Halts Payroll
    Gift card exchange site Leverage, which had pushed one of the more creative CRM ideas out there, has laid off its entire workforce and is hoping economic fortunes will improve next year, according to company CEO/Co-Founder Mark Edward Roberts.
    Five Trends That Will Change Retail Security
    Around this time of year, GuestView Columnist David Taylor starts to wax nostalgic about the good old days at Gartner when he used to make grand announcements about his vision for the future of technology.
    "Click-N-Ship" Becomes "Click-N-Curse" As Outages Riddle Postal Service
    "Unprecedented" problems with the United States Postal Service's popular Click-N-Ship service probably had many holiday shippers clicking and cursing throughout the week, but a USPS spokesman said the worst was over by December 12.
    Amazon's 105 Percent Misleading Solution
    Amazon.com this week jumped in with a clever gift card strategy that bordered on brilliant, a tactic that could simultaneously boost revenue and steal sales from multiple competitors. So with such a wonderful plan, what would possess Amazon to put a statement that, at the most charitable, could be described as a phrasing so deceptive that even a New Jersey or Illinois politician would find it too over the top?
    Is Amazon's iPhone Trial An Experiment In Futility?
    Amazon is far from alone this holiday season is pushing some new mobile efforts, standing alongside Walmart, Target, Gap and Sears in the popular holiday "let's fling random things at the cellular tower and see what sticks" game.
    Post Black Monday, Many E-Tail Sites Still Struggle With Uptime
    As the hoopla surrounding Black Friday and Cyber Monday mercifully subsided, some e-tailers were still struggling to keep their sites up, with Office Depot and Sephora suffering repeated outages while Walmart and Office Max—among others—experienced more sporadic mishaps.
    ComScore Finds "Unprecedented" Slowdown in U.K. E-tail Holiday Traffic
    The early holiday shopping season found fewer consumers hitting U.K. retail Web sites compared with last year's identical period, with some major sites seeing double-digit declines, according to Comscore.
    NFC Losing Ground, Reports ABI Research
    Payments for taxis, parking and movies may prove less patient in waiting for new technologies than E-Commerce, a move that could be a bad sign for once-promising mobile payment method Near Field Communication (NFC).
    Dollar General Agrees To Use POS For Visually-Impaired
    Dollar General, the $10 billion discount retail chain, on Wednesday (Dec. 10) agreed to install specially-designed POS units intended to safeguard the privacy of visually-impaired consumers in all of its 8,300 stores in the U.S. "in less than eighteen months." The intent is to give those shoppers an alternative to touchscreen interfaces by offering tactile keys.
    Surviving IT Security's Dark Ages
    The economy sucks so GuestView Columnist David Taylor suggests that this would be an ideal time to shift budget away from regulatory compliance and spend it on something that will actually make money for your company, like direct mail advertising. No, he doesn't actually believe that, but he has the feeling that some executives are on the defensive when it comes to maintaining a focus on their areas during these dark times.
    E-Commerce Avatars That Match A Consumer's Posture And Smile?
    E-Commerce avatars—computer-generated 3-D replicas of consumers with precise measurements to help purchase clothes that fit better—may soon use digital video to incorporate a consumer's posture, facial expressions and smile.
    Macys Pushing Its Merged Channel Efforts
    Macys went out of its way on Monday (Dec. 8) to tout to the world how much it embraces merged channel. The question, though, is why did it bother? The $26 billion owner of the 850-store Macys and Bloomingdale's chains attributed comments to their most senior exec that the two brands' customers "increasingly are multi-channel consumers" and that they have done various enhancements to their online and physical elements.
    Best Buy Technologist Has Technique For Finding New Ideas
    Best Buy Chief Technologist Bob Anderson has been talking lately about the value of lending an ear to young innovators in the company. "You don't need a big, honking server and lots of funding or 50 people to start something innovative."
    Humanity As Much As 50 Percent Off
    One columnist writes about the stampede death of a Wal-Mart assoiciate in New York when he was opening the doors for Black Friday shoppers. "No doubt," he wrote, "they were the same shoppers who complained bitterly about the ‘appalling lack of help' in the store." Indeed.
    Google's SLA Games: They Can Have 21 Hours Of Downtime In A Day And Still Claim 100 Percent Uptime
    A service level agreement (SLA) is a guarantee from a site that its uptime will be as promised, n'est pas? Actually, quite the opposite. It's more likely a complicated document designed to protect the site (not the retailer) in case of any problem.
    Walmart.com Seeks To Unclarify Outage
    Walmart.com is saying that they want to clarify that position, but then E-mailed a statement that, well, doesn't clarify much of anything. But it does do a nice job of hinting at something without actually saying it.
    Cyber Monday '08: The Butterfly Effect In Action
    Whether the wing flapping of a bug can eventually cause a tornado is debatable, but Cyber Monday 2008 should serve as a warning to E-tailers to avoid the lesson learned by Staples and Dell on Monday (Dec. 1): Don't ignore the butterfly effect.
    What Was Wal-Mart Thinking When It Made Key Site Changes On Black Friday?
    At about 6 AM New York time on Black Friday (Nov. 28), Wal-Mart's site went down for about an hour and then came back up. But this time, the company had moved its content pages to an outside service. Wal-Mart said this was a scheduled change, a concept that Gareth Evans, head of client services at Web tracking firm Sitemorse, finds unlikely.
    Visa Card Holograms Shut Down POS Terminals
    In a trial of new holographic magnetic stripes for its payment cards, Visa found the cards "emitted an electrostatic discharge that caused POS terminals to shut down," according to a report in The Nilson Report, a respected credit card industry newsletter.
    Microsoft's Live Search Program Crashes On Black Friday
    Microsoft's Live Search cashback program—which gives rebates to those who comparison shop online and choose stores that are part of the program—was a bit too popular on Black Friday (Nov. 28) and crashed for several hours, leaving consumers with no cashback and a lot of anger.
    Sears.com Melts Down On Black Friday, But Costco, Walmart, Saks and Kmart Have Issues, Too
    Sears.com suffered the worst Web problems on Black Friday (Nov. 28), experiencing a series of complete site crashes for much of the day. Although no other major retailer came close, according to preliminary reports, many of the industry's largest merchants suffered site slowdowns or other Web problems, including Walmart, Kmart, Saks, Overstock, Amazon, Target, Kohl's, Costco and Buy.com.
    Visa Europe Testing A Reciprocal Authentication Card
    In a trial initially limited to the United Kingdom, Switzerland, Israel and Italy, Visa Europe is starting a trial this month of a card with an 8-digit alphanumeric display, 12-button keyboard and a long-life battery. The card has the ability to offer reciprocal authentication, which is designed to allow consumers "making transactions via phone or the Web a way to identify the party on the other end before transmitting identifying credentials."
    Black Friday Cyber Sales Up A Mere One Percent
    Black Friday (Nov. 28) E-Commerce sales hit $534 million, reflecting a one percent increase from last year's Black Friday, ComScore reported Sunday (Nov. 30).
    JCPenney Adds Merged Channel Twist, Including Wake-Up Calls
    A Web-generated wakeup phonecall to get customers to in-store early morning sales may not have a material impact on quarterly sales, but it's a creative touch for the E-Commerce site JCPenney relaunched right before Black Friday (Nov. 28). Even if the system's in-store inventory update isn't quite accurate.
    CRM Chutzpa: Best Buy Credit Card Thief Sought Loyalty Rewards
    A group of credit card thieves in Seattle tried to maximize their profits by using their stolen credit card data to open a loyalty card account with Best Buy, where they could get could extra benefits along with their stolen products, according to a federal indictment filed Nov. 19. One had tried a similar rewards scam with a Home Depot reward card and a Sears gift card.
    Tracking How Many Consumers Flee During A Site Meltdown
    Following a site meltdown by a major U.K. retailer this month, Internet traffic tracking firm Hitwise was able to document and make concrete what has always been assumed: Consumers abandon a retail site when it melts down faster than politicians vote for a tax cut.
    How Bleak Is The E-Commerce Picture? Mixed Messages
    Recently released numbers raise questions as to whether online will be much of a savior at all. New figures from eMarketer project that E-Commerce sales will top last year's numbers by some $5.6 billion, a 4.1 percent increase from $136.8 billion to $142.4 billion.
    PCI Fines: Nuisance Or A Ticket To ROI?
    Eduardo Perez of Visa has called its fines for non-compliance "nuisance" fines. In other words, the fines are not large enough to be a big financial burden to retailers but are large enough to get the CFO pissed off about having to pay them and maybe large enough to get a CEO to at least show up for a meeting to discuss PCI.
    Trying To Protect Payment Data When You Can't Even Find It All
    The IT struggle with knowing where all payment data is—let alone trying to enforce rules that pretty much try and keep it there—was the topic of a StorefrontBacktalk a podcast this week with our own PCI columnist, David Taylor, and security specialist J.D. Oder, the chief technology officer at Shift4.
    Is Price Comparison Dead? And, If So, Should We Celebrate?
    A Supreme Court decision from back in June 2007—intended to give consumer goods manufacturers greater control over their products' pricing—is fueling confusion, mistrust and runarounds among E-tailers trying to compete on price.
    Wal-Mart To Pay $1.4 Million Fine Because Of Price Change Database Problem
    Wal-Mart has agreed to pay $1.4 million to settle complaints that it overcharged customers in California. The Nov. 24 deal involved the mispricing of some 1,043 items over four years. Some of the problems happened because associates would make pricing changes to items in the store's register database but not in the aisle.
    PayPal To Use Cellphones To Authenticate Payments
    PayPal has come up with yet another payment-related use of a cellphone: to authenticate a non-mobile E-Commerce transaction. Customers of the payment giant "can now choose to receive a unique six-digit security code via text message to their mobile phones prior to logging in to their accounts," PayPal said.
    American Patriots Finding They Can't Rely On Barcodes
    There's an E-mail campaign that says consumers can identify American products by the first three digits of the barcode. In theory, this would allow people who only want to buy American products an easy way to do that. The only problem is that the trick doesn't always work, which means it could have the opposite effect.
    HP Finds Cutting Back Related Items Shown Boosts Sales
    When are related product lists helpful and when are they distracting? Is it an obviously useful upsell or is it doomed to the fate of the salesperson who shows a customer one too many choices? HP thinks it's often the latter and has sharply trimmed the number of related items it shows. And the company is claiming a 30 percent sales increase as a result.
    Amazon's Gift Card Future: Personal, But Not Too Personal
    Amazon.com, which arguably has one of the most extensive retail CRM databases and purchase recommendation engines, envisions a Catch-22 future for gift cards. The key is making them more personalized, more customized. And yet, anything that hints of privacy violations is off-limits. It's like a starving man being given the keys to a well-stocked food locker as long as he agrees not to eat anything.
    TiVo And Domino's Try E-Commerce Without The PC Or Phone
    As more retailers try to go where the customers are rather than getting them to come to the retailer, TiVo and Domino's are taking the next logical step with a TV-as-E-Commerce-Device approach.
    O, Kiosk, How Doth I Differentiate Thou?
    We make calls on PCs and surf the Web on our phones. The lines of separation are blurring fast. But in the world of retail technology, the difference between a kiosk and digital signage is one of the more difficult distinctions to make. How to describe that difference? To one CFO, the answer was obvious: A poem. In rhyming verse. Rhyming verse that is so bad it's almost good.
    Do You Have a Mobile Blindspot?
    The further employees get from corporate, and from corporate networks, the more likely they are to do things with their computer that security managers would rather they didn't. GuestView Columnist David Taylor asks if these people might be doing things (e.g., downloading malware) that could bring down your company?
    All Web Meltdowns Are Not Created Equal
    When file transfer site YouSendIt—with more than 100,000 paid users bringing in some $10 million this year—crashed on Monday (Nov. 17), it illustrated the kind of crash that should make retailers very concerned.
    Security Podcast: 12-Year-Old Data And Publishing Encryption Keys
    Podcast panelists debate card replacement problems, including inadvertently printing encryption keys on customer receipts and the refusal of the card brands to shorten how long expiration dates are valid. "We now have to worry about data that's been there as many as 12 years."
    Will Consumers Punish Retailers That Misuse CRM Data?
    A loyalty card that consumers can turn on and off could potentially usher in a consumer revolution of sorts, allowing the majority to punish merchants they see as misusing CRM data that has been entrusted to them. At least that's one scenario painted by the president of the company that is pushing the card.
    NRF Says Gift Card Spending To Drop
    Amidst an avalanche of hype about the desirability of gift cards this holiday season, the National Retail Federation on Tuesday (Nov. 18) predicted a six perfect drop in gift card sales this season, from $26.3 billion spent during last year's holiday season to a projected $24.9 billion for this season.
    What A Bond Villain's Datacenter Would Look Like
    Some 30 meters below solid bedrock underneath Stockholm, an abandoned nuclear bunker has been transformed into what could only be described as the world's coolest datacenter.
    E-Commerce Site Crashes To Soar This Holiday Season, With Upgrades, Partners And Discount Traffic The Likely Culprits
    Several factors are lining up—including rushed technology upgrades, more site handoffs for everything from mobile to social networking widgets and a surge in traffic from bargain hunters—that could easily make this holiday shopping season one of the crashiest in years, if not the crashiest. (Note to copydesk: I don't care if crashiest is not a word. It should be.)
    Sears Mobile Move Illustrates The Mobile E-Tail Challenge
    When Sears rolled out its mobile effort (Sears2go) this month, it illustrated the challenges for a retailer trying to craft a clean and stable mobile strategy at a time of extreme flux for the mobile space.
    "Store Locator" The Unsung Hero Of Web Analytics
    When E-Commerce execs try and understand abandoned shopping carts, they often overlook concrete clues. One of the best is whether shoppers clicked on the store locator link right before leaving. But deciding what to do about abandoned carts, that gets complicated. The innocuous-looking store locator is akin to waving a red cape in front of the face of an E-Commerce manager bull.