« Thoughts on penetration testing | Main | What merchants want from the PCI DSS »

Wednesday, 04 November 2009

The birth of X9.119

Standardization is crushing the heart and soul, the blood and guts, out of humanity and the eventual result will be either complete and unrelieved slavery or the destruction of civilization and return to barbarism.

Robert E. Howard, letter to H. P. Lovecraft, October 31, 1931

At the recent ASC X9 meeting, we learned that the designation X9.119 had been assigned to the new standard that will be called Protection of Sensitive Data between Device and Acquiring System. At this meeting, it actually took over an hour for the X9F6 working group to decide that this document should be a standard instead of something else, like a technical guideline (TG).

The most amazing part was the fact that after over an hour of loud and bitter debate over this, it was actually unanimously decided that the document should indeed become a standard! In other words, we spent over an hour arguing over a point over which there was total and complete agreement. That might give you some idea of how long it takes to resolve points over which there is actually some disagreement.

I should also mention that I was impressed by the people from Heartland Payment Systems during this hour-long discussion. While people from other organizations were willing to spend lots of time talking about things that weren't really related to the issue at hand, Heartland did their best to keep the discussion on track. Unfortunately, their efforts weren't quite enough to do this, but I hope that they won't be discouraged by this experience. We need more of that type of contribution at standards meetings instead of less.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00e55375ef1c88330120a6680288970c

Listed below are links to weblogs that reference The birth of X9.119:

Comments

Martin125


Hello,
We facilitate the provision of independent analysis to support expert testimony, regulatory or legislative engagements.http://www.stlouisbridal.com

buy kamagra

There is an argument that bigger is better. Bigger schools have bigger alumni networks, graduates have more networking opportunities, etc. Adjusting for class size is not obviously right and really hurts big schools like Georgetown. Really, it depends on where you want to work. If you want to work on Wall Street, go to Harvard or Yale. If you want to work in DC, Georgetown. If you want to work in Tallahassee, go to University of Florida. If you want to work in Maui, go to University of Hawaii. These one-size-fit-all rankings have limited value. If you are really smart, don't go to law school.

Post a comment

If you have a TypeKey or TypePad account, please Sign In.

Voltage Data Breach Index

  • Grab the Voltage Data Breach Index

February 2012

Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29