More on Heartland breach
CEO Bob Carr of Heartland gave a webinar on the September 15th stating that you should be very careful when choosing QSA. "Don't just go out and grab the cheapest one", is the message (discussion during Q&A in the webinar). He is probably right, but what should the criteria be when choosing the QSA? Obviously you can't go by pricing. Is there any sites "classifying" QSA's? Carr states he paid $15k for a QSA to do their audit before the breach, and got a "go-ahead" from them after their audit. Apparently they didn't do their job too well. So after the breach Carr took in another QSA and said, "Just do your job, whatever it takes, find whatever vulnerabilities there are". Sorry to say, no pricetag for that kind of work has been disclosed... I'd really like to know!!!
Comments
Post a Comment