abednarz
Executive Editor

Online businesses face credit card security deadline

News
Jun 13, 20056 mins

The deadline is fast approaching for companies that conduct business online to have to comply with a common set of security requirements outlined last year by major credit card companies.

In an effort to combat fraud, identity theft and other security issues, American Express, Discover, MasterCard, Visa and others created the Payment Card Industry (PCI) data security standard. PCI, which goes into effect June 30, consists of 12 technology requirements for securing networks and applications, protecting cardholder data, maintaining a vulnerability management program, and regularly validating compliance via a third-party assessment.

For e-commerce merchants, including retailers, payment processors and financial institutions, the standard could make life easier by consolidating what in the past have been a bunch of different security guidelines from credit card companies. However some merchants are ill-prepared to meet the compliance deadline, experts say.

The PCI rules apply to retailers, payment processors and financial institutions – essentially any business that stores, processes or transmits cardholder data. The card associations have laid out varying enforcement policies and penalties for non-compliance, depending on the volume of transactions a merchant or service provider processes. The largest players could face up to $500,000 in fines per incident if cardholder data is compromised and the merchant or service provider is not PCI-compliant. In addition, the card associations can cut off non-complying companies’ credit card processing privileges.

The June 30 deadline came as something of a surprise for Jelly Belly Candy Company, admits Gary Praegitzer, network administrator and security specialist at the Fairfield, Calif., candy maker. But the company is in good shape to comply. Over the last few months it has used security scanning services from Qualys to find and fix a few encryption-related vulnerabilities – such as making a minor server configuration adjustment to disallow low-level encryption settings. But Jelly Belly has not had to make any expensive IT investments to comply with the PCI standard, Praegitzer says.

Jelly Belly is fortunate. For many online businesses, coming into compliance could be costly, depending on the conditions of their existing systems. David Glaser, director of professional services at electronic payment and risk management vendor CyberSource, estimates that as of April or so, the majority of U.S. merchants were only about 30% prepared for a PCI compliance audit. “There can be a lot of work to do,” Glaser says.

Particularly for smaller merchants, PCI compliance might require purchasing security products, such as encryption, access control, and activity monitoring and logging devices. There are also procedural mandates – such as the need to implement formal security policies and vulnerability management programs – that will require IT resources.

Once the security systems and policies are in place, companies will need to submit to annual or quarterly audits by a PCI-certified assessor to validate compliance.

What makes compliance particularly tough is that the retail industry historically hasn’t emphasized security as strongly as other industries, such as financial services, says Jim Cowing, managing director at security assessment firm Digital Resources Group.

“Database encryption is probably the most difficult technical component” of the PCI standard, Cowing says. The most difficult IT administrative component is getting a comprehensive set of security policies in place and documenting those policies, he says.

New rules of the game

The 12-step Payment Card Industry data security standard lays out unified requirements for securing networks, protecting cardholder data, and regularly certifying the adequacy of security systems and processes.
1. Install and maintain a firewall configuration to protect data.
2. Do not use vendor-supplied defaults for system passwords and other security parameters.
3. Protect stored data.
4. Encrypt transmission of cardholder data and sensitive information across public networks.
5. Use and regularly update anti-virus software.
6. Develop and maintain secure systems and applications.
7. Restrict access to data by business need-to-know.
8. Assign a unique ID to each person with computer access.
9. Restrict physical access to cardholder data.
10. Track and monitor all access to network resources and cardholder data.
11. Regularly test security systems and processes.
12. Maintain a policy that addresses information security.

Over the long term, having a unified data security standard instead of several disparate programs will make life easier for merchants and payment processors. Visa has had its own Cardholder Information Security Program since 2001, and MasterCard last year launched its Site Data Protection program. Achieving compliance with the PCI standard covers each of the distinct programs and takes away the headache of separate certifications. “Now they’re all playing from the same hymn book,” Cowing says.

Meanwhile, a number of vendors have announced products and services to help companies achieve PCI compliance:

  • Ingrian Networks last week announced a program designed to help merchants comply with the PCI standard’s encryption rules. The program includes an assessment of a company’s current methods for securing data; design recommendations; tutorials for achieving compliance; compliance validation from service provider AmbironTrustWave; and a 30-day trial of Ingrian’s appliance-based DataSecure encryption platform.

  • Qualys recently added PCI-specific scanning tests to its subscription-based vulnerability management platform, which is designed to detect, identify and report vulnerabilities common to flawed Web site architectures and configurations. With the QualysGuard service, merchants can scan their payment systems, follow a blueprint for correcting found vulnerabilities, and generate a compliance report as required by PCI rules.

  • CyberSource launched a PCI assessment and readiness program recently that combines a review of existing systems, policies and processes; identification of compliance gaps; and remediation efforts. CyberSource also offers compliance maintenance services for conducting quarterly vulnerability scans, assessing scan results, monitoring changes in PCI requirements and managing associated readiness efforts.

The PCI standard takes effect as the number of high-profile thefts of consumer data continues to rise. Data broker ChoicePoint and retailer BJ’s Wholesale Club are among companies that have been stung by electronic theft of consumers’ personal information in recent months.

“The motivation of the credit card industry is to try to enforce some discipline into merchants, or anyone who handles credit card data, to be more scrupulous about the way they handle that data,” says Philippe Courtot, chairman and CEO of Qualys.

In today’s environment, many retailers will welcome the incentive to shore up security, Cowing says.

“There are a lot of smart merchants out there who realize that they’re holding a database that has a bunch of plain-text credit card numbers in it, and they’ve been meaning to fix that,” he says. “IT managers have been asking for money for years to protect these things.”

abednarz

Ann Bednarz is the executive editor of Network World. Ann is a longtime IT journalist and has spent 26 years writing and editing for Network World, where she has worked as a news reporter, managed product testing and reviews, and developed features and how-to articles for an audience of network professionals and data center managers. Over the last two years, she has conceived and edited award-winning content for Network World that includes 2025 Jesse H. Neal Award finalists, 2025 Azbee Award regional winners and national finalists, and 2024 Eddie & Ozzie Award finalists.

Ann holds a bachelor’s degree in architecture and spent the early part of her journalism career writing about architectural design and construction. In her free time, she keeps those skills alive through DIY projects.

More from this author