two
Volume 4, Number 6 -- February 14, 2007

Security Vendors Form PCI Alliance

Published: February 14, 2007

by Alex Woodie

Compared to the mysterious and daunting nature of Sarbanes-Oxley, the technical steps that companies must take to comply with the Payment Card Industry (PCI) data security standard are crystal clear. Just the same, questions on PCI remain. As of last month, thanks to the creation of the PCI Security Vendor Alliance, there's an organization dedicated to providing answers.

In 2005, the card payment industry started implementing minimum security guidelines that companies must follow to ensure the safety of sensitive data included in credit, debit, gift, and point of sale (POS) transactions. A vendor that failed to adopt the guidelines--first implemented by Visa with its Cardholder Information Security Program (CISP) and later adopted industry-wide via PCI--would face fines ranging into the hundreds of thousands of dollars, and eventually banishment from the electronic payment network for continued negligence.

Luckily for systems administrators, the PCI group outlined relatively clear technical goals for achieving compliance, including having basic network security such as a firewall and antivirus software, encrypting data in transit, implementing tight user-access controls, and tracking and monitoring mechanisms.

However, there's still a lack of awareness of PCI, says Jon Oltsik, a senior analyst with the Enterprise Strategy Group, an IT analyst group focused on storage issues. "Even with all the press on data security breaches and the corporate and personal costs that accrue from them, there is still only limited awareness of the PCI data security standards," Oltsik says.

That's where the PCI SVA comes in. The group was founded by eight security software companies last month to educate technology users about PCI, and to spread the PCI gospel to technology and solution providers as well.

The eight co-founders--including ConfigureSoft, Cyber-Ark, Modulo Security, Proginet, Protegrity, Reflex Security, SafeNet, and Verisign--say they plan to create a series of case studies, seminars, return-on-investment analyses, and white papers showing how organizations may achieve compliance with the PCI DSS requirements efficiently and on-budget.

Two things that the PCI SVA will not do is certify security products or services, or certify companies PCI remediation activities. Any product certification for the PCI's Data Security Standard (DSS) is handled by the PCI Security Standards Council itself, whereas the final determination of compliance is made by the individual credit card brands or by certified auditors.

For more information about the PCI SVA, including an application form for vendors wishing to join the group, go to www.pcialliance.org.



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
VIBRANT TECHNOLOGIES

HP, IBM and Sun Server Deals via RSS

                                                  · Subscribe to our Specials via RSS
                                                  · Up to 80% off manufacturer's list price
                                                  · Multi-million dollar inventory

We Buy & Sell new and remarketed servers,
upgrades, peripherals and parts.

HP Proliant, IBM xSeries, IBM pSeries, RS6000,
HP Integrity, Sun Microsystems, Cisco, more…
888-443-8606

View or Subscribe to:
Special Offers on Servers and Upgrades


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

Vision Solutions:  Get facts on managed availability and business continuity to eliminate downtime
Wolf Computer Consulting:  Reliable service and affordable rates for business computing needs
COMMON:  Join us at the Spring 2007 conference, April 29 - May 3, in Anaheim, California

 

The Four Hundred
Faster i5 595 Rumored to Be Imminent

IBM Moves OS/400 V5R3 Towards the Door, Rejiggers i5 Prices

Zend Upgrades Commercial Add-Ons for Its PHP Engine

As I See It: The Elusive Leader

The Linux Beacon
Chip Makers Strut Their Stuff at ISSCC

AMD Delivers Faster and Cooler Rev F Opteron Chips

Zend Upgrades Commercial Add-Ons for Its PHP Engine

As I See It: Measuring What Counts

Four Hundred Stuff
Lawson Brings Former Intentia ERP Suite Closer to Landmark

iSeries Web Adventures Call with iSafari

Valid Tech Assimilates Biometric Authentication Into the Enterprise

Gumbo's Dumpster Dives Into i5/OS Spool Files

Big Iron
IBM Previews Future z/OS, z/VM Mainframe Operating Systems

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Opportunities, Not Problems!

SQL Cross Platform Interoperability: The Proper Function

Admin Alert: Selectively Sending Break Messages to Active Users

System i PTF Guide
February 3, 2007: Volume 9, Number 5

January 27, 2007: Volume 9, Number 4

January 20, 2007: Volume 9, Number 3

January 13, 2007: Volume 9, Number 2

January 6, 2007: Volume 9, Number 1

December 30, 2006: Volume 8, Number 50

The Unix Guardian
HP Puts Solaris on More X64 Servers, Partners for Solaris Emulation

Sun Details Server Chip Roadmaps at Analyst Summit

AMD Delivers Faster and Cooler Rev F Opteron Chips

The X Factor: One Socket to Rule Them All

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

IOUG
MKS
Lakeview Technology
Gabriel Consulting Group
Vibrant Technologies



TABLE OF CONTENTS
Microsoft Moves Forward on Post Vista Windows OSes

Microsoft Issues a Dozen Security Patches, Fixes Security Tools

Chip Makers Strut Their Stuff at ISSCC

Microsoft Launches Windows Mobile 6

But Wait, There's More:


IBM Challenges Microsoft Lock-In with 'Open Client Solution' . . . Microsoft Promises Not to Sue Over XPS Implementations . . . Microsoft and Novell Tout Technical Collaboration Efforts . . . IBM Brings Drive-Based Encryption to Midrange Tape Library . . . Security Vendors Form PCI Alliance . . . EMC's VMware IPO Spin Off: The Birth of a New Bubble? . . .

The Windows Observer

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement