Why does PCI-DSS (and other standards) suck?
From: The Six Enemies of Greatness (and Happiness) - Forbes
Just check item number #3:
3) Committees
Nothing destroys a good idea faster than a mandatory consensus. The lowest common denominator is never a high standard.
Standards like PCI are always created by Committees. Unfortunately, as this nice article says, "the lowest common denominator is never a high standard".