Who Does A Better Job Auditing PCI?
The motivation behind MasterCard’s QSA mandate was almost certainly driven by some pretty shoddy self-assessments by some name-brand companies. After all, just because a company has a brand name, doesn’t mean its senior management believes all the consultant hype that you have to spend money on data security to protect your brand by avoiding a security breach. But my experience with Internal Audit departments tells me that once that department agrees to take on PCI compliance assessments, they spend more time, effort and money on assessments and generally do a better job than most QSAs. Why? Cost is a huge factor in QSA selection, so QSAs often have to minimize the assessment scope in order to win business. I know many QSAs who are thoroughly ticked off that some of their clients would prefer a less-than-thorough assessment. Many merchants like QSAs who are “easy graders,” which is not a shock. But these same “cheap ass” (to quote one notable QSA) managers have a hard time sitting acro