No thanks, stay here.  

  We notice you are visiting from a U.S. Internet provider. Switch to our U.S. website.

Industry News

QSA: PCI compliance not possible in the public cloud - yet

By Lauren Lindberg

02/02/2010 - With the recent explosion of cloud computing, many companies have wondered how the technology fits with their payment processing compliance and security initiatives.

Unfortunately, the verdict has not been a favorable one so far, and Qualified Security Assessor Phil Cox recently added to the skepticism.

In an article for Search Cloud Computing, Cox - who provided the caveat that his position as a QSA does not make his opinion representative of that of the PCI Security Standards Council - reported that "if you do store or process cardholder data in a public cloud, however, then it is my opinion that it would not be possible to currently achieve PCI DSS compliance."

The only way a company could maintain PCI security while still using a public cloud is by using the cloud only for securely transmitting cardholder data, which is essentially the equivalent of the internet.

"Until cloud providers are willing to open up and show us (i.e., customers and auditors) what the insides look like, PCI DSS compliance for storing and processing of cardholder data remains a pipe dream," he wrote.

This issue is of increasing importance as cloud computing continues to grow rapidly - a recent survey from Mimecast found that 70 percent of companies currently using cloud computing have plans to increase their cloud deployments, ChannelWeb reported.
ADNFCR-2514-ID-19593887-ADNFCR

Related News - Security and Fraud

Study: PCI compliance a no-brainer among Level Four merchants

10/01/2012

A recent survey by research firm Gartner found nearly one-fifth of retailers and credit card processing services are not compliant with Payment Card Industry Data Security Standards.

Full Article

Tracking spending can be made easy with credit cards

06/12/2011

Many people feel that plastic payment processing options can lead to overspending, but a recent article published by Forbes explains that making payments with credit cards is actually a great way to control costs and track expenses.

Full Article

Keeping business bank accounts safe and secure

11/10/2011

The internet has provided consumers with many new and convenient ways to access their account information, but these advances have also created the need for thorough security measures.

Full Article

Personalized payment chips get fraud prevention upgrade

10/10/2011

Payment chips made by Fiserv will now be further personalized using the Europay MasterCard Visa (EMV) standards, a global credit card payments technology that helps prevent fraud from lost, stolen or counterfeit cards.

Full Article