> Home > Privacy Studies
An organisation experienced a data breach relating to credit card processing hardware; it was alleged by the organisation that the manufacturer and installer of its point of sale system never informed them at the time of installation that there was a more current version or updates were available, that default user logins and passwords were never changed, the firewall had “excessive” ports open and the hardware was no longer PCI DSS compliant. The manufacturer alleged that its product was PCI certified, card processors have added provisions to their contracts with merchants that require them to secure cardholder data, that the merchants were responsible for stolen card numbers; installing PCI compliant software was only one small piece of the merchant’s responsibility to meet their contracted obligation with their card processor - merchants were expected to secure their computer system’s network with commercial grade firewalls, use properly supported operating systems, have vigorous password controls and clean data accumulated from the pre-PCI era.
Background Facts:
Relevance to Business Activities:
Source Documents:http://www.databreaches.net/?p=11932http://www.databreaches.net/?p=11943
Copyright © 2002-2010 Nymity
Privacy Statement · Legal notice