Home > Ask the Information Security Experts > Questions & Answers > Are there any references that discuss the cost of PCI DSS compliance?
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

Are there any references that discuss the cost of PCI DSS compliance?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 23 October 2007
Are there any published benchmarks on how much enterprises are spending (per size, customer count, etc.) or should expect to spend in order to comply with the Payment Card Industry (PCI) Data Security Standard?

>
EXPERT RESPONSE

The short answer is no, there aren't any published benchmarks specific to PCI DSS. There has been some survey work done (most recently by Nemertes Research) to try to pinpoint how much organizations are spending on compliance. They interviewed about 100 companies and drew the conclusion that most don't necessarily break out compliance as a budget item anymore. Nor are companies specific about what they spend for PCI versus Sarbanes-Oxley, HIPAA or GLBA.

I remember when I was with a private company that was considering a public offering, and we budgeted about 8-10% of revenue for compliance costs. Of course, that will scale way back for large companies, which shouldn't spend more than 1%. But like all other numbers and benchmarks, it depends a lot on how the numbers are counted.

Yet I would be negligent in not mentioning that I believe trying to budget specifically for compliance is a fool's errand. The reality is that the focus should be on protecting data and building a manageable and documented security program. If that's done well, regulations like PCI and HIPAA will be a walk in the park.

Compliance is not something that's bought; it's a process. It never ends, and it needs to stay in lock step with the changes happening in a dynamic business. Understanding direct costs will probably require additional headcount to pull proper reports and document the program. It also may require investment in some software tools to mine through all the data that is generated by systems, networks and applications.

So I'm not a big fan of budgeting for compliance. But if you already have a line item in your budget for "compliance" expenditures, then try to figure out what's really needed for security and pay for it using the compliance money.

For more information:

  • Learn why many corporations are underestimating the costs associated with PCI DSS compliance.
  • A Ponemon Institute study indicates the costs associated with data breaches have increased, and they will continue to skyrocket unless companies do more.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Compliance Regulations
    The power of the ICO: Liabilities for a data security breach
    Privacy, data protection must be built into system design, says ICO
    Using ISO 27000 to comply with Data Protection Act principles
    Latest U.K. data security laws get tough on fines, PETs and policies
    Will the Data Handling Review improve government security practices?
    The 'appropriate' way to comply with Data Protection Act 1998
    Best practices: Handling compliance during a corporate merger
    Information Commissioner turns up the heat on data breach culprits
    Email confusion could look bad in court
    Firms aim to achieve PCI compliance deadline, despite the cost

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Basel II  (SearchSecurityUK.com)
    EU Data Protection Directive  (SearchSecurityUK.com)
    Financial Services Authority  (SearchSecurityUK.com)
    UK Identity Cards Act  (SearchSecurityUK.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts