Posted by:
admin
17 years, 1 month ago
In an interesting twist in the continuing PCI story, the Texas legislature may mandate PCI compliance:
According to the language of the bill, "A business that, in the regular course of business, collects, maintains, or stores sensitive personal information in connection with an access device must comply with payment card industry data security standards." The bill would allow a financial institution in the state to request a breached entity to provide certification of its compliance with PCI specified controls. HB 3222 would require the certification to be issued by a PCI-approved auditor no earlier than 90-days before the breach.It sounds like retailers would have to be audited every 90 days! Is this bill the work of the financial institutions or the auditors? Share on Twitter Share on Facebook
