Feeds

Qualys: When rules finally meet technology

Automating credit card compliance

Securing Web Applications Made Simple and Scalable

Rumour has it that TJX, the embattled US retailer trying to recover its reputation following the loss of 45 million credit and debit card details, is dishing out free ice creams to entice shoppers back in to their stores in major US cities.

This may appear desperate but the hit the company has taken has been significant. Factor in the $5–$7 per card cost of reissuing a replacement piece of plastic and the sheer scale of the security breech can be seen.

Credit card fraud is prevalent, but at least we have one of those rare occasions when legislation, compliance and technology is converging to give consumers better support in the form of the Payment Card Industry (PCI) initiative.

Unlike the vague machinations of Sarbanes-Oxley, where each auditor can interpret the "appropriate financial controls" implemented by each company, PCI details very precise security requirements for credit card merchants.

This in turn is backed up by a comprehensive network of checks, balances and controls that all go to make the implementation of the regulations a lot easier than almost any other similar legislation.

Failing an organisation for lack of PCI compliance is a transparent, objective process.

Having accountable rules and regulations is vital for promoting commerce and the use of credit cards. Both merchants and customers need the confidence to undertake trades without worrying if the card has been ripped off or the merchant is allowing your credit card data to leak.

Qualys has embraced the PCI regulations from the start, and was one of the companies that contributed to the original specification.

It's only when you look at the size of the payment card problem you start to realise the challenge organisations face.

Take a multinational such as Disney Corporation. It will be taking payments from thousands of merchant points across its stores, theme parks and other outlets which all need to be managed according to PCI rules. Simply trying to determine what falls into the scope of the regulations can be tough.

Ultimately compliance checks need to be automated, which is where the Qualys appliance-lead approach comes into its own. Using web-driven management interfaces an administration team can set up appropriate scans and validation checks across a corporate to ensure that card usage falls within the rules of the PCI regulations. In fact, the Qualys approach has been so successful that the company has become a large provider of PCI-scanning technology to other third-party PCI security auditors. In addition, Qualys claims to have 150 million production scans - from both its PCI and non-PCI compliance products - under its belt across its 3,000 customers.

Qualys scans a wide variety of customers and collects that data on a global basis - so its knowledge base of the latest threats and problems likely to hit a credit-card merchant is pretty extensive and in-depth. This is vital when a previously compliant merchant suddenly fails the next day as their system has become subject to an attack - up-to-date threat data is crucial.

What we have seen with the acceptance of PCI is one of those rare moments when a consumer-focused industry acknowledges that there is a clear and obvious need for rules and regulations. This in turn has attracted vendors such as Qualys that are able to convert these regulations into practical solutions available off the shelf which are relatively easy to implement.

Unfortunately PCI is a rarity, in that its requirements are clear, obvious and relatively easy to implement. Legislators need to take a long hard look at PCI and learn how to write clear rules so that we can all be assured of securing our businesses.

Copyright © 2007, IT-Analysis.com

The smart choice: opportunity from uncertainty

More from The Register

next story
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.