From: Computerworld
Antone Gonsalves
Despite several high-profile security breaches at major retailers, the government should let the private sector continue to set the rules for protecting credit- and debit-card data, a standards body says.
Bob Russo, general manager for the Payment Card Industry (PCI) Security Standards Council, was scheduled to tell a congressional committee Wednesday that it’s unlikely any government agency could duplicate “the expansive reach, expertise and decisiveness of PCI,” referring to the standards set by the council.
“High profile events such as the recent breaches are a legitimate area of inquiry for the Congress, but should not serve as a justification to impose new government regulations,” Russo said in an advance copy of his prepared remarks.
“Any government standard in this area would likely be significantly less effective in addressing current threats, and less nimble in protecting consumers from future threats, than the constantly evolving PCI standards.”
Leave a Reply