<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Look to the acquiring banks, not the PCI Security Council</title>
	<atom:link href="http://www.mckeay.net/2008/05/30/look-to-the-acquiring-banks-not-the-pci-security-council/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mckeay.net/2008/05/30/look-to-the-acquiring-banks-not-the-pci-security-council/</link>
	<description>The views of one man on security, privacy and anything else that catches his attention</description>
	<lastBuildDate>Sat, 20 Mar 2010 10:00:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: PCI Blog - Compliance Demystified &#187; Blog Archive &#187; Definaitions, Roles and Responsibilities of PCI</title>
		<link>http://www.mckeay.net/2008/05/30/look-to-the-acquiring-banks-not-the-pci-security-council/comment-page-1/#comment-2448</link>
		<dc:creator>PCI Blog - Compliance Demystified &#187; Blog Archive &#187; Definaitions, Roles and Responsibilities of PCI</dc:creator>
		<pubDate>Mon, 30 Jun 2008 04:16:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/05/30/look-to-the-acquiring-banks-not-the-pci-security-council/#comment-2448</guid>
		<description>[...] Martin McKeay aptly noted, we must first understand who is in charge of what before asking questions or making [...]</description>
		<content:encoded><![CDATA[<p>[...] Martin McKeay aptly noted, we must first understand who is in charge of what before asking questions or making [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://www.mckeay.net/2008/05/30/look-to-the-acquiring-banks-not-the-pci-security-council/comment-page-1/#comment-2437</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sun, 29 Jun 2008 22:47:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/05/30/look-to-the-acquiring-banks-not-the-pci-security-council/#comment-2437</guid>
		<description>Martin, I am happy you&#039;re educating others about the roles and responsibilities of the PCI SSC and the card brands.  It&#039;s important that people understand who sets the standards and who enforces them. 

One point of clarification, Visa and MasterCard will never fine merchants directly because they work through their Members (Issuing and Acquiring banks), but the other card brands: American Express, Discover, and JCB go either way.  Another words, AmEx, Discover, and JCB can act as the issuer and acquirer - which would be able to fine merchants directly.</description>
		<content:encoded><![CDATA[<p>Martin, I am happy you&#8217;re educating others about the roles and responsibilities of the PCI SSC and the card brands.  It&#8217;s important that people understand who sets the standards and who enforces them. </p>
<p>One point of clarification, Visa and MasterCard will never fine merchants directly because they work through their Members (Issuing and Acquiring banks), but the other card brands: American Express, Discover, and JCB go either way.  Another words, AmEx, Discover, and JCB can act as the issuer and acquirer &#8211; which would be able to fine merchants directly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.mckeay.net/2008/05/30/look-to-the-acquiring-banks-not-the-pci-security-council/comment-page-1/#comment-2040</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Sat, 31 May 2008 17:06:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/05/30/look-to-the-acquiring-banks-not-the-pci-security-council/#comment-2040</guid>
		<description>Do the banks share information with one another concerning their fines/fees?  It smells like an anti-trust violation if they do, but if they do not, why wouldn&#039;t a merchant switch acquirers when faced with a large enough fine or a fee increase?  Do merchants have to disclose their loss/breach history to acquirers?  If not, you have a situation akin to being able to switch auto-insurance companies right after you get in an accident.  I note that insurance companies can and do share data to prevent this strategy from succeeding.</description>
		<content:encoded><![CDATA[<p>Do the banks share information with one another concerning their fines/fees?  It smells like an anti-trust violation if they do, but if they do not, why wouldn&#8217;t a merchant switch acquirers when faced with a large enough fine or a fee increase?  Do merchants have to disclose their loss/breach history to acquirers?  If not, you have a situation akin to being able to switch auto-insurance companies right after you get in an accident.  I note that insurance companies can and do share data to prevent this strategy from succeeding.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
