Home > Security News > Vendor alliance wants PCI certification program
Security News:
EMAIL THIS

Vendor alliance wants PCI certification program

By Michael S. Mimoso, Editor, Information Security magazine
05 Feb 2007 | SearchSecurity.com and Information Security magazine

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Enterprises clamoring for PCI-certified products and services are a somewhat closer to having their wish fulfilled.

RSA Conference 2007

Can't make it to the show? SearchSecurity.com staff members are on the RSA floor, on hand to deliver the latest RSA Conference 2007 news and updates.
The Payment Card Industry Security Vendor Alliance was announced this week at RSA. The mission of its five founding members--Configuresoft, Protegrity USA, SafeNet, Proginet and Cyber-Ark--is to provide guidance on the products and services that can be used to achieve compliance with the PCI Data Security standard(PCI), and ultimately get a PCI certification program off the ground.

PCI is a standard that dictates how credit card merchants must protect cardholder information. It applies to merchants that store, process or transmit cardholder information. Merchants that don't live up to the standard's 12 requirements run the risk of not being able to do business with the leading credit card companies, Visa, MasterCard and American Express.

By educating the community about the technology and services available to automate compliance, merchants will be able to achieve compliance sooner.
David Taylor
VP of Data Security Strategies, Protegrity USA
PCI SVA member Chris Farrow, director of Configuresoft's Center for Policy and Compliance, said merchants are struggling to comply, in part because the PCI Security Standards Council has not invited vendors to join its ranks, nor does it certify products.

The council was founded by the leading credit card providers. Farrow hopes the formation of the SVA, which made a full call for participation this week at RSA, earns vendors a seat on the council. The council currently certifies PCI assessors and scanning vendors, and Farrow said that framework is a good start for a product and services certification program.

"We realize that's the tougher part of the mission. But customers have no guidance in picking vendors," Farrow said. "We'd like some endorsement--a warm-and-fuzzy--that says 'we've seen your work and it's viable if implemented.' "

The founding members said SVA will provide educational and advisory services to the payment card industry via its site www.pcialliance.org, analyst briefings, conference presentations and live seminars.

"By educating the community about the technology and services available to automate compliance, merchants will be able to achieve compliance sooner, and therefore receive the overall business benefits of compliance earlier in the process," said David Taylor, VP of Data Security Strategies at Protegrity USA.

<< Return to our special coverage of RSA Conference 2007



Tags: PCI Data Security StandardSecurity Awareness Training and Internal ThreatsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
PCI Data Security Standard
PCI management: The case for Web application firewalls
MasterCard increases PCI compliance requirements for some merchants
PCI compliance requirement 1: Firewalls
PCI compliance requirement 2: Defaults
PCI compliance requirement 5: Antivirus
PCI compliance requirement 4: Encrypt transmissions
PCI compliance requirement 3: Protect data
PCI compliance requirement 6: Systems and applications
PCI compliance requirement 8: Unique IDs
PCI compliance requirement 10: Auditing

Security Awareness Training and Internal Threats
Twitter risks, Facebook threats trouble security pros
Social engineering training could disrupt botnet growth
How to write a risk methodology that blends business, security needs
Risk management must include physical-logical security convergence
Tabletop exercises sharpen security and business continuity
Security policies need simplifying, expert says
Microsoft IE 8 security only benefits educated users
Security book chapter: The Truth About Identity Theft
How to integrate the security of both physical and virtual machines
Laid off workers likely to steal company data, survey warns

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
PCI DSS (Payment Card Industry Data Security Standard )  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts