Vendor alliance wants PCI certification program

Article

Vendor alliance wants PCI certification program

Michael S. Mimoso, Editor, Information Security magazine
Enterprises clamoring for PCI-certified products and services are a somewhat closer to having their wish fulfilled.

RSA Conference 2007

Can't make it to the show? SearchSecurity.com staff members are on the RSA floor, on hand to deliver the latest RSA Conference 2007 news and updates.
The Payment Card Industry Security Vendor Alliance was announced this week at RSA. The mission of its five founding members--Configuresoft, Protegrity USA, SafeNet, Proginet and Cyber-Ark--is to provide guidance on the products and services that can be used to achieve compliance with the PCI

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Data Security standard(PCI), and ultimately get a PCI certification program off the ground.

PCI is a standard that dictates how credit card merchants must protect cardholder information. It applies to merchants that store, process or transmit cardholder information. Merchants that don't live up to the standard's 12 requirements run the risk of not being able to do business with the leading credit card companies, Visa, MasterCard and American Express.

By educating the community about the technology and services available to automate compliance, merchants will be able to achieve compliance sooner.
David Taylor
VP of Data Security StrategiesProtegrity USA
PCI SVA member Chris Farrow, director of Configuresoft's Center for Policy and Compliance, said merchants are struggling to comply, in part because the PCI Security Standards Council has not invited vendors to join its ranks, nor does it certify products.

The council was founded by the leading credit card providers. Farrow hopes the formation of the SVA, which made a full call for participation this week at RSA, earns vendors a seat on the council. The council currently certifies PCI assessors and scanning vendors, and Farrow said that framework is a good start for a product and services certification program.

"We realize that's the tougher part of the mission. But customers have no guidance in picking vendors," Farrow said. "We'd like some endorsement--a warm-and-fuzzy--that says 'we've seen your work and it's viable if implemented.' "

The founding members said SVA will provide educational and advisory services to the payment card industry via its site www.pcialliance.org, analyst briefings, conference presentations and live seminars.

"By educating the community about the technology and services available to automate compliance, merchants will be able to achieve compliance sooner, and therefore receive the overall business benefits of compliance earlier in the process," said David Taylor, VP of Data Security Strategies at Protegrity USA.

<< Return to our special coverage of RSA Conference 2007


Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.