Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Companies get checklist on PCI security rules

By Jaikumar Vijayan, Computerworld
March 16, 2009 02:10 PM ET
  • Share/Email
  • Tweet This
  • Comment
  • Print

The organization that administers the credit card industry's data security rules has released a new set of compliance guidelines -- a move that reinforces the widespread perception that efforts to comply are going slowly at many companies.

PCI Security Standards Council LLC, which was set up by Visa, MasterCard, American Express and other credit card companies in 2006, this month issued a 15-page document that details a "prioritized approach" for complying with the rules.

The new framework maps the 12 security controls mandated by the Payment Card Industry Data Security Standard (PCI DSS) to a list of six milestones. Bob Russo, the council's general manager, said the goal is to help companies that have yet to start on their PCI DSS compliance efforts and are wondering where to begin.

The first version of the security standard, which applies to all entities that accept credit and debit card payments, went into effect nearly four years ago. But many businesses still aren't fully compliant, said Jim Huguelet, a PCI consultant in Bolingbrook, Ill.

"I think there are a lot of merchants who feel overwhelmed at the amount of remediation [work] they need to undertake," Huguelet said. That, he added, has led to a state of "paralysis" in which companies either are doing nothing or are only implementing the easier PCI requirements, which by themselves do little to reduce the overall threat of data breaches. The milestone-based framework finally gives those companies a template for moving forward, Huguelet said. "The journey of a thousand miles begins with a single step," he noted. "And the PCI [council] has now officially announced what those first steps should be."

Russo said the milestones are meant to provide an organized compliance methodology that ensures that the highest-risk issues are addressed first. In addition, a spreadsheet-based tool released with the framework can be used to plot progress against the milestones and to give auditors a snapshot of a company's compliance status.

The first milestone focuses on purging sensitive card-authentication data from systems and limiting the amount of information that companies collect and retain. Others revolve around network and application security, user access control and the protection of stored data.

This version of this story originally appeared in Computerworld's print edition.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Partner Content

Gartner 2009 Magic Quadrant for Job Scheduling

Gartner has positioned BMC CONTROL-M in the Leaders Quadrant of their "2009 Magic Quadrant for Job Scheduling." The report assesses the ability to execute and completeness of vision of key vendors in the marketplace. Read a full copy today, courtesy of BMC Software.

Download whitepaper

Dell's SMART Approach to Workload Automation

Read a compelling case study by EMA, Inc. to learn how Dell uses BMC CONTROL-M to cut cost and increase productivity with workload automation.

Download whitepaper

Workload Automation Cost Savings 2 Minute Video

A major computer manufacturer uses BMC CONTROL-M and just four people to schedule and run over 85,000 jobs every month. By switching to BMC CONTROL-M, they more than quadrupled the workload without adding a single staff member.  See how in this 2-minute video overview.

Go to video

Comments (1)
Login
Forgot your account info?

Tierd of covering the big boys assesBy SimpleTruth on March 17, 2009, 12:39 pmPCI is just a method the big boys (Visa, MC, AMX) are using to hide their own failings and poor planning. Hardware/Software Development is expensive, especially...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed