Clearly, RSA's marketing has received a serious shot in the arm since the merger. Billing themselves nowadays as the "security division of EMC", they've been sending out all sorts of email invitations over the past few weeks: invitations to view their blog entries, invitations to listen to their podcasts, and most recently, an invitation to attend a live seminar about PCI. Now, normally this kind of thing wouldn't be blog-worthy, but their statistical lead-in caught my eye. Check it out and see if anything about it strikes you as unusual:
FACT: Over 85% of Payment Card Industry (PCI) Data Security Standard audit failures are in the area of data security.
Since it is the "data security standard", I have to confess that it doesn't really surprise me that the lion's share of the issues are related to data security. But the part that does really make me curious is what the other 15 percent are related to...
The PCI standard enforces that you should ask your workers which handle CC Numbers for a criminal record ... so not to secure that is maybe a part of the 15%...
Posted by: Johannes Jäger at October 5, 2006 03:51 PM