PaymentsJournal
SUBSCRIBE
  • Analysts Coverage
  • Truth In Data
  • Podcasts
  • Videos
  • Industry Opinions
  • News
  • Resources
No Result
View All Result
PaymentsJournal
  • Analysts Coverage
  • Truth In Data
  • Podcasts
  • Videos
  • Industry Opinions
  • News
  • Resources
No Result
View All Result
PaymentsJournal
No Result
View All Result

PCI in the Cloud

Mercator Advisory Group by Mercator Advisory Group
February 11, 2013
in Analysts Coverage
0

pay taxes design, vector illustration eps10 graphic

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

Bankinfosecurity.com has an audio interview with Bob Russo of the Payment Card Industry Security Standards Council that highlights the Council’s recent guidance on cloud computing services and payment card data security.

The need for the guidance relates to the nature of cloud services and the presence in the market of so-called “public clouds,” where the cloud services provider offers its cloud as a shared service between multiple customers. Many segments of the payments industry are relying more and more on cloud services; consequently, Russo indicates, the responsibility for securing card data in the cloud (especially public clouds) is not so clear-cut.

From Bank Info Security:

“Cloud services provide an attractive opportunity for outsourcing,” says Russo, general manager of the Payment Card Industry Security Standards Council. “But from our perspective, we want to be sure organizations are aware of all of the risks before they entrust payment data and processing to a third party.”

On Feb. 7, the council released its PCI DSS Cloud Computing Guidelines Information Supplement , a set of best practices and guidelines developed by the PCI Cloud Special Interest Group.

Russo highlights the main point of the guidance: Know where card data is stored at all time. The challenge organizations face when storing card data in the cloud is that they lose an element of control. And sometimes card data can wind up being stored in multiple locations or in environments that are not well protected, he warns.

“Cloud is a shared responsibility,” Russo says. “Outsourcing the management of these security controls really doesn’t equate to outsourcing your responsibility to be PCI-DSS compliant. Cloud services are not all created equally, so you need to understand what PCI-compliant cloud service really means.”

Click here to read more from Bank Info Security.

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

    Analyst Coverage, Payments Data, and News Delivered Daily

    Sign up for the PaymentsJournal Newsletter to get exclusive insight and data from Mercator Advisory Group analysts and industry professionals.

    Must Reads

    eCommerce On Social Media, social commerce

    The Rise of Social Commerce and Social Payments

    February 3, 2023
    Electroneum AnyTask; ETN Crypto, sales enablement

    Ethical Financial Selling: The Role of Compliance Technology and Sales Enablement

    February 2, 2023
    direct deposit

    Nacha Launches Campaign to Reach Millennials on the Benefits of Direct Deposit

    February 1, 2023
    Equinix Helps UK-Based Payments Provider Enable Faster, More Reliable Payments Processing

    Equinix Helps UK-Based Payments Provider Enable Faster, More Reliable Payments Processing

    January 31, 2023
    credit card tumbling

    How to Detect, and Prevent, Credit Card Tumbling

    January 30, 2023
    Why Businesses Need to Adopt Real-Time Payments as a Competitive Differentiator

    Why Businesses Need to Adopt Real-Time Payments as a Competitive Differentiator

    January 27, 2023
    faster payments

    Faster Payments Are Set to Revolutionize Modern Digital Payments

    January 26, 2023
    How AI can Help Manage Payments Risk in 2023

    How AI can Help Manage Payments Risk in 2023

    January 25, 2023

    • Advertise With Us
    • About Us
    • Terms of Use
    • Privacy Policy
    • Subscribe
    ADVERTISEMENT
    • Analysts Coverage
    • Truth In Data
    • Podcasts
    • Videos
    • Industry Opinions
    • News
    • Resources

    © 2022 PaymentsJournal.com

    • Analysts Coverage
    • Truth In Data
    • Podcasts
    • Industry Opinions
    • Faster Payments
    • News
    • Jobs
    • Events
    No Result
    View All Result

      Register to download the Equinix report - Dojo Delivers Fast, Reliable and Secure Card Payments to Businesses on Platform Equinix