Skip Links

Network World

  • Social Web 
  • Email 
  • Close

New payment application security standard on deck

PCI Security Standards Council set to bolster transaction security
By Ellen Messmer , Network World , 11/07/2007

The PCI Security Standards Council today said it intends to add a new standard to cover payment-application software.

The council, which defines the data-security standards required by businesses processing credit and debit cards, was formed two years ago by payment-card associations, including American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa. The council has already established the PCI Data Security Standard 1.1 that merchants and service providers must comply with as requested by their banks and the card associations. The new standard will be called the Payment Application Data Security Standard (PA-DSS) which will be largely based on Visa’s existing “Payment Application Best Practices.”

“We will ensure that payment-application providers and their products are subject to data-security requirements consistent with the current PCI Data Security Standard.”said Bob Russo, the council’s general manager.

Although Russo was not immediately available to discuss PA-DSS, the council published on its Web site a set of frequently-asked questions (FAQ) about what the new PA-DSS is intended to be.

“PA-DSS applies to software vendors and others who develop payment applications that store, process or transmit cardholder data as part of authorization or settlement where these payment applications are sold or distributed by third parties,” the council said in its FAQ.

The council did not publish a draft of the proposed new standard, noting that it’s necessary to be a member of the council in order to see an advance copy of it.

In the FAQ on the council’s Web site, the council states, “Once the standard is finalized, the Council will be certifying PA-DSS specific Qualified Security Assessors (QSA) to validate the payment applications and the Council will ultimately publish a list of validated payment applications.”

There are already more than 60 QSAs that have been certified under the council’s procedures to perform audit reviews of businesses to determine whether they comply with the PCI DSS 1.1 standard of today. The FAQ indicates that the council is likely to establish a similar program to certify QSAs to review payment applications used by merchants.

“PA-DSS validated payment applications will minimize the potential of security breaches leading to compromise of full magnetic stripe data, card validation codes and values, PINs and PIN blocks,” the council stated in its FAQ.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

In all of these letters that you have posted, Chuck, I have yet to see one that apologizes to PZ Myers...- bullet

Join the Discussion