Conclusion: The Payment Card Industry Data Security Standard (PCI DSS) is concise and promotes many effective controls – most of which can be achieved through business process reengineering or redesign. Software and hardware vendors talk about fines for non-compliance, but unlike the US, these fines are almost non-existent in Australia. As such, PCI DSS has no stick but there is the possibility of a carrot: a lower risk profile.

Many organisations confuse receiving credit card payment with handling cardholder data1. These are not the same thing and CIOs should challenge the assumption that it is necessary to handle the cardholder data. Only organisations that absolutely must handle cardholder data should become PCI DSS compliant. Otherwise, organisations should reduce their risk profile by not handling cardholder data at all.

Register to

Free Research

Subscribe to monthly insights and analysis from our team of experts
Subscribe Now


Get in-context advice from our experts about your most pressing issues or areas of interest
Make an Inquiry


There are no up-coming events


Learn more about our pragmatic, in-context advice.
Learn More