PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

PCI in the Cloud

By Mercator Advisory Group
February 11, 2013
in Analysts Coverage
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
pay taxes design, vector illustration eps10 graphic

pay taxes design, vector illustration eps10 graphic

Bankinfosecurity.com has an audio interview with Bob Russo of the Payment Card Industry Security Standards Council that highlights the Council’s recent guidance on cloud computing services and payment card data security.

The need for the guidance relates to the nature of cloud services and the presence in the market of so-called “public clouds,” where the cloud services provider offers its cloud as a shared service between multiple customers. Many segments of the payments industry are relying more and more on cloud services; consequently, Russo indicates, the responsibility for securing card data in the cloud (especially public clouds) is not so clear-cut.

From Bank Info Security:

“Cloud services provide an attractive opportunity for outsourcing,” says Russo, general manager of the Payment Card Industry Security Standards Council. “But from our perspective, we want to be sure organizations are aware of all of the risks before they entrust payment data and processing to a third party.”

On Feb. 7, the council released its PCI DSS Cloud Computing Guidelines Information Supplement , a set of best practices and guidelines developed by the PCI Cloud Special Interest Group.

Russo highlights the main point of the guidance: Know where card data is stored at all time. The challenge organizations face when storing card data in the cloud is that they lose an element of control. And sometimes card data can wind up being stored in multiple locations or in environments that are not well protected, he warns.

“Cloud is a shared responsibility,” Russo says. “Outsourcing the management of these security controls really doesn’t equate to outsourcing your responsibility to be PCI-DSS compliant. Cloud services are not all created equally, so you need to understand what PCI-compliant cloud service really means.”

Click here to read more from Bank Info Security.

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    scams

    The Future of Same Day ACH, RTP, and Virtual Cards  

    June 15, 2026
    payment api

    Open Banking Has Made Payment APIs a Burgeoning Revenue Stream

    June 12, 2026
    payment card innovation

    Serving a Segment of One: The Race to Stay Top of Wallet

    June 11, 2026
    healthcare payments

    The Healthcare Payments Industry Has a Perception Problem

    June 10, 2026
    continuous KYC

    The Future of KYC Is Layered—and Data-Driven

    June 9, 2026
    tokenized deposits

    As Crypto Challengers Emerge, Banks Turn to Tokenized Deposits

    June 8, 2026
    physical digital debit

    Whether Physical or Digital, Debit Cards Are a Payments Mainstay

    June 5, 2026
    agentic commerce

    Separating Hype from Reality in Emerging Payment Trends

    June 4, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result