The i-Technology Media!
Register | Log in
   
 
.NET  ·  AJAX  ·  CLOUD  ·  ECLIPSE  ·  FLEX  ·  OPEN WEB  ·  iPHONE  ·  JAVA  ·  LINUX  ·  OPEN SOURCE  ·  ORACLE  ·  PBDJ  ·  SEARCH  ·  SILVERLIGHT  ·  SOA  ·  VIRTUALIZATION  ·  WEB 2.0  ·  WIRELESS  ·  XML
YOUR FEEDBACK
Upstart Seeks To Overthrow OpenOffice
Gregor Rosenauer wrote: well, not what's your take on this? Did I miss a second page of this article or...
Oct. 6, 2008 02:45 PM
AJAXWorld RIA Conference
Early Bird Savings Expire Friday Register Today and SAVE !..
Did you read today's front page stories & breaking news?
Live Google News by SYS-CON!

TOP THREE LINKS YOU MUST CLICK ON


From the Wires
Payment Card Industry Data Security Standard -- a Great Start but Not a Security Panacea, Says Burton Group
Analyst Firm Recommends More Robust Practices for Protection of Cardholder Data
Mar. 19, 2007 06:50 PM

SALT LAKE CITY, UT -- (MARKET WIRE) -- 03/19/07 -- Burton Group, an IT research firm, released a research report that contains a list of recommendations to help merchants and payment service providers get the most out of the payment card industry (PCI) data security standard (DSS) compliance work.

According to Diana Kelley, vice president and service director for Burton Group's Security and Risk Management Strategies service, PCI DSS does a good job helping companies understand how to prevent and detect a cardholder data security breach, but does not go into detail regarding how to address a breach.

Kelley points out PCI DSS is not the only set of practices companies must consider when handling cardholder data. She recommends a full-spectrum approach including the following steps:

Get the Facts

For detailed readiness work, the PCI DSS Security Audit Procedures is required reading. Both documents are available from the PCI SSC website at www.pcisecuritystandards.org. These are the same documents the PCI auditors and the payment-card brands use to assess compliance and will help an organization prepare for compliance attestation.

Segment the Scope

Segmenting servers and networks reduces the scope of PCI audited systems, thus reducing compliance work. Technologies that provide segmentation include firewalls, routers with access control lists (ACLs), and physical security.

Don't Store What You Don't Need

Applications architected with PCI DSS compliance in mind are designed to prevent storage of unnecessary data. Point of sale (POS) applications that store full magnetic strip data are out of compliance with PCI DSS. So, before purchasing a payment application, or creating one in-house, carefully review what can and cannot be stored. Application security and controls can help here.

Be Prepared and Be a Partner

Success comes from merchants and providers who work with auditors in a noncontentious, partnership model to achieve compliance. If there are gaps in compliance, the auditor can mark a control as either "not in place" or "not in place" with a "target date" for remediation. Showing there is a plan with a target date for remediation lets the payment-card brands know that actions are being taken to correct the problem.

Get Involved

There were a number of changes between version 1.0 and 1.1 of the PCI DSS. Members of the payment community helped drive these changes. If your organization thinks a requirement in the DSS is unfeasible, talk with your auditor to determine if compensating controls or an alternative can be found. If not, talk to the SSC.

Build a Compliance Program

New regulatory mandates and industry standards are introduced all the time. Avoid "fire drill" mode and take a comprehensive approach to compliance by utilizing re-usable frameworks which are built on generally accepted control and risk-management frameworks (such as COSO, CobiT, ISO 27001, and NIST SP800-30).

Click here for a Burton Group Take 5 -- a complimentary 5 minute, audio-enhanced presentation, with more information to help merchants and payment service providers get the most out of PCI DSS compliance work.

About Burton Group

Burton Group (www.burtongroup.com) helps technologists make smart enterprise architecture decisions in increasingly complex environments. Burton Group's research and advisory services focus on technical analysis of infrastructure technologies relating to security, identity management, web services, service-oriented architecture, collaboration, content management, and network and telecom.

Add to DiggBookmark with del.icio.usAdd to Newsvine

Contact:
Amie Johnson
PR Manager
801-304-8136
Email Contact

Published Mar. 19, 2007
Copyright © 2008 SYS-CON Media. All Rights Reserved.
SUBSCRIBE TO THE WORLD'S MOST POWERFUL NEWSLETTERS
SUBSCRIBE TO OUR RSS FEEDS & GET YOUR SYS-CON NEWS LIVE!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021


SYS-CON FEATURED WHITEPAPERS

ADS BY GOOGLE

ADVERTISE   |   MAGAZINE SUBSCRIPTIONS   |   FREE BREAKING-NEWSLETTERS!   |   SYS-CON.TV   |   BLOG-N-PLAY!   |   WEBCAST   |   EDUCATION   |   RESEARCH

.NET Developer's Journal - .NETDJ   |   ColdFusion Developer's Journal - CFDJ   |   Eclipse Developer's Journal - EDJ   |   Enterprise Open Source Magazine - EOS
Open Web Developer's Journal - OPENWEB   |   iPhone Developer's Journal - iPHONE   |   Virtualization - Virtualization   |   Java Developer's Journal - JDJ   |   Linux.SYS-CON.com
PowerBuilder Developer's Journal - PBDJ   |   SEO / SEM Journal - SJ   |   SOAWorld Magazine - SOAWM   |   IT Solutions Guide - ITSG   |   Symbian Developer's Journal - SDJ
WebLogic Developer's Journal - WLDJ   |   WebSphere Journal - WJ   |   Wireless Business & Technology - WBT   |   XML-Journal - XMLJ   |   Internet Video - iTV
Flex Developer's Journal - Flex   |   AJAXWorld Magazine - AWM   |   Silverlight Developer's Journal - SLDJ   |   PHP.SYS-CON.com   |   Web 2.0 Journal - WEB2
Apache   |   CMS   |   CRM   |   HP   |   Oracle Journal   |   Perl   |   Python   |   Red Hat   |   Ruby on Rails   |   SAP   |   SaaS

SYS-CON MEDIA:   ABOUT US   |   CONTACT US   |   COMPANY NEWS   |   CAREERS   |   SITE MAP
SYS-CON EVENTS:   |  AJAXWorld Conference & Expo  |  iPhone Developer Summit  |  OpenWeb Developer Summit  |  SOA World Conference & Expo  |  Virtualization Conference & Expo
INTERNATIONAL SITES:   India  |  U.K.  |  Canada  |  Germany  |  France  |  Australia  |  Italy  |  Spain  |  Netherlands  |  Brazil  |  Belgium
 Terms of Use & Our Privacy Statement     About Newsfeeds / Video Feeds
Copyright ©1994-2008 SYS-CON Publications, Inc. All Rights Reserved. All marks are trademarks of SYS-CON Media.
Reproduction in whole or in part in any form or medium without express written permission of SYS-CON Publications, Inc. is prohibited.
 
close this window