A tale of two PCI security audits

27.10.2008

His experience is that the auditors are fair and genuinely helpful.

Don't believe what they say

During a , Duran suggested merchants learn as much as they can about the standard so they'll know when an auditor is sending them in the wrong direction.

"You need to understand PCI yourselves, because the auditors will tell you things that you may not like and probably shouldn't believe," he said. "The more you understand, the more you can challenge them."

Duran's department has to deal with two auditors - one in the U.S. and one in Europe. They often give different answers to the same questions because they are looking at it from different perspectives. He has also come across people who lack the proper understanding of such technical matters as firewall and VLAN configuration.