PSD: Clear responsibility
Dec 3rd, 2007 by Jesper Kråkhede
To be able to comply with PSD there are quite a lof of criterias that has to be fullfilled. One is the fourth point of article 10: Granting of authorization. It states that there has to be a clear chain of responsibility for all parts of the payment service business. It all breaks down to implementing ITIL or some other framework to be able to handle such compliance. The biggest issue is to set a information owner and a system owner on all parts of the chain. Without this and without a clear organization it is not possible to handle security incidents. This is in essence not any different from any other compliance scheme. Same thing is stated in PCI DSS but with other wordings. It is all about mitigating risks, nothing else.