PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

PCI Isn’t an IBM Mainframe Issue; It’s in the Application and the Applications Environment

By Tim Sloane
July 27, 2021
in Analysts Coverage, ATM, Compliance and Regulation, Debit, Digital Assets & Crypto, Fraud & Security, Security
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
PCI Isn’t an IBM Mainframe Issue; It’s in the Application and the Applications Environment

PCI Isn’t an IBM Mainframe Issue; It’s in the Application and the Applications Environment

This article claims mainframes have problems adhering to PCI and shouldn’t be used to drive ATMs, but this is a huge oversimplification. The IBM Z systems are explicitly called out but the IBM Z will run a range of operating systems including Linux, z/OS, z/VSE, z/TPF, and z/VM. So who is responsible for PCI compliance when the application is in Linux?

The article suggests that the senior management might fail to audit the mainframe, which is then entirely on that company, not the mainframe hardware. PCI compliance is not technology-specific it requires system architects and programmers to consider how PCI compliance will be implemented as the system is developed, regardless of hardware or operating system:

“Late last year, the PCI Security Standards Council and ATM Industry Association jointly issued a bulletin warning about cash-out attacks on ATMs in which fraudsters manipulated fraud detection mechanisms and stole money from ATMs. In a blog, the organizations recommended that banks operating ATMs through a mainframe use software designed to monitor any unusual changes in files that could indicate unauthorized access or malicious behavior. Such software is referred to as file integrity monitoring. File integrity monitoring became part of PCI regulation updates two years ago to address new needs as technology advances.

But though banks continue to lean on mainframes to process most transactions, including payments, experts wonder whether they are paying enough attention to this PCI recommendation. According to IBM, 44 of the top 50 banks use the IBM Z mainframe and 86% of all credit card transactions run through the Z mainframe.

PCI compliance efforts can slip past a bank security team for any number of reasons, one being the belief that the mainframe has been within PCI scope all along, another that upcoming changes will make mainframe compliance a moot point.”

Overview by Tim Sloane, VP, Payments Innovation at Mercator Advisory Group

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: ATMCompliance and RegulationIBMPCI Compliance

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    samsung p2p

    Making Zelle Work Better for Users—and Banks

    April 10, 2026
    fraud escalate

    As Fraud Escalates, Taking a Beat Becomes a Critical Defense

    April 9, 2026
    privacy open banking

    As Open Banking Fuels Interconnectivity, Privacy Matters More

    April 8, 2026

    ACH Is Thriving, and Banks Are Struggling to Keep Pace

    April 7, 2026
    stablecoins, Klarna

    How Stablecoins Emerged as a Key Element of Cross-Border Payments

    April 6, 2026
    Cross-Border Payments

    How the U.S. Built Its Faster Payments Ecosystem

    April 3, 2026
    Young Latin woman applying powder on her face for beauty blog. Smiling woman sitting at table in cosy room holding powder box and brush looking at phone camera recording video. Make up and cosmetics blogging concept

    TikTok Aspires to Fintech Status with Payments, Credit Bids in Brazil

    April 2, 2026
    small business credit card

    What Banks Get Wrong About Small Business Credit Cards

    April 1, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result