Feeds

E-commerce smackdown as PCI standards revised

Comply or die pay fines

Providing a secure and efficient Helpdesk

Virtual reality

Other vendors welcomed the recognition for the increased use of virtualisation and cloud-based technologies in revised standards. Sumedh Thakar, director of engineering at vulnerability assessment firm Qualys, welcomed this attempt to align payment industry security standards with 21st century IT infrastructure realities.

Thakar explained: "The standards were not keeping pace with advances in technology, especially the use of virtualisation in a card holder data environment. The existing standards talk about the notion of having 'One primary function per sever'. In a virtualised environment, this becomes a problem because the environment can be pretty dynamic and you could have virtual servers with different primary functions, like web servers and database servers, on the same physical server."

Merchants sometimes hold back on introducing virtualisation in their PCI environments for fear of being deemed non-compliant, according to Qualys. The revised regulations remove that uncertainty but are likely to have a knock-on effect on other requirements - such as firewalls, pen testing and performing vulnerability scans - that need to be factored into testing regimes.

Rafe Pilling, PCI Consultant at SecureWorks, agreed that the approach to virtualisation in the e-commerce regulations remains somewhat unclear.

Pilling said: "Although there are no groundbreaking changes to PCI 2.0, there have been some clarifications made to the standards and some developments on how companies using virtualisation must comply with the PCI Data Security Standards (DSS).

"However, organisations looking for clear guidance on storing PCI and non-PCI systems in a virtualised environment might be disappointed, as the boundaries are not clearly defined."

Compliance conundrum

The previous version (1.2.1) of the PCI DSS guidelines was released in July 2009. The council has now settled on a three-year release cycle, which means that PCI DSS 3.0 can be expected in October 2013. Merchants have the choice of applying either version 1.2.1 or 2.0 throughout 2011 before the older standard is pensioned off at the end of next year and version 2.0 becomes the only game in town.

Log management and regulatory compliance specialist LogRhythm notes that many organisations have yet to meet the PCI SSC’s previous recommendations. A survey by Redshift Research back in March revealed that just 11 per cent of UK organisations were PCI DSS compliant, an observation LogRhythm holds true even after September’s PCI compliance deadline for level one merchants

"Some of the anticipated changes by the PCI SSC can’t come too soon," said Ross Brewer, VP and MD of international markets at LogRhythm.

"Reports show high rates of non-compliance, a fact often viewed as a reflection of the lack of clarity which has negatively affected the standard in the past. Guidance on virtualisation and the alignment between PCI DSS and the Payment Application Data Security Standard will also be welcome, while the evolving requirement for centralised logging of payment transactions is a definite plus."

Brewer added that complaints about the clarity of PCI DSS are nothing new and sit alongside a much larger compliance headache many firms face. ®

New hybrid storage solutions

More from The Register

next story
Google recommends pronounceable passwords
Super Chrome goes into battle with Mr Mxyzptlk
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Reddit wipes clean leaked celeb nudie pics, tells users to zip it
Now we've had all THAT TRAFFIC, we 'deplore' this theft
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
TorrentLocker unpicked: Crypto coding shocker defeats extortionists
Lousy XOR opens door into which victims can shove a foot
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.