ROI: What departments of a retail organization need to be involved in the planning process to prevent future data breaches?
CS: On the surface, both security teams and compliance teams need to be in lockstep. This would include the POS security team, the IT security team, the compliance team, (which could included the QSA or ISA) and, of course, CISO or CSO, to ensure that IT decisions and directives are disseminated all the way up to the board. Also, all stakeholders within the IT security policy as well as the compliance policy must understand their respective obligations to ensure that retail systems are kept secure. It's imperative that all the players who have a responsibility to the IT security policy have complete awareness of their parts.
- Companies:
- Target
- People:
- Chris Strand