<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A Sample Policy for PCI-DSS</title>
	<atom:link href="http://www.pcidssguru.com/pci-dss/a-sample-policy-for-pci-dss/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pcidssguru.com/pci-dss/a-sample-policy-for-pci-dss/</link>
	<description>Payment Card Industry Data Security Standard</description>
	<lastBuildDate>Wed, 21 Jul 2010 14:56:30 -0700</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Tom Cornelius</title>
		<link>http://www.pcidssguru.com/pci-dss/a-sample-policy-for-pci-dss/comment-page-1/#comment-41</link>
		<dc:creator>Tom Cornelius</dc:creator>
		<pubDate>Mon, 15 Sep 2008 20:20:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/pci-dss/a-sample-policy-for-pci-dss/#comment-41</guid>
		<description>The interesting thing most people do not understand is that without the ability to document due care and due diligence on behalf of the company, the company can be found negligent for failing to adhere to known standards.

The PCI DSS is a non-regulatory requirements, so the government does not have a play. However, being a legally-binding document, the PCI DSS can bring a Merchant into a courtroom. If one requirement from the PCI DSS is not met, the Merchant is technically non-compliant. If the Merchant is non-compliant, the Merchant is technically negligent.

Where most business owners do not realize the risk is that insurance does not cover acts of negligence and the entire cost of the data breach, from fines to lawsuits and chargebacks will be completely left to pay by the Merchant. This could spell immediate bankruptcy for most Level 3 or Level 4 merchants.

In simple terms, everyone needs robust policies and ensure those standards are being met. The cost of prevention is immensely less than that to clean up after a breach.</description>
		<content:encoded><![CDATA[<p>The interesting thing most people do not understand is that without the ability to document due care and due diligence on behalf of the company, the company can be found negligent for failing to adhere to known standards.</p>
<p>The PCI DSS is a non-regulatory requirements, so the government does not have a play. However, being a legally-binding document, the PCI DSS can bring a Merchant into a courtroom. If one requirement from the PCI DSS is not met, the Merchant is technically non-compliant. If the Merchant is non-compliant, the Merchant is technically negligent.</p>
<p>Where most business owners do not realize the risk is that insurance does not cover acts of negligence and the entire cost of the data breach, from fines to lawsuits and chargebacks will be completely left to pay by the Merchant. This could spell immediate bankruptcy for most Level 3 or Level 4 merchants.</p>
<p>In simple terms, everyone needs robust policies and ensure those standards are being met. The cost of prevention is immensely less than that to clean up after a breach.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
