R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

PCI council sets payment security standard

New rules on the storage of payment details

Ian Williams, vnunet.com 16 Apr 2008
ADVERTISEMENT

The Payment Card Industry Security Standards Council (PCI SSC) has announced the release of version 1.1 of the Payment Application Data Security Standard (PA-DSS).

PA-DSS is designed to help software vendors and others develop secure payment applications that do not store prohibited data, such as full magnetic stripe or Pin data, and ensure that payment applications support compliance with the standard.

The requirements apply to payment applications that are sold, distributed or licensed to third parties.

They do not apply to in-house payment applications developed by merchants or service providers that are not sold to a third party, but these applications must still be secured in accordance with the PCI DSS.

The new standard was unveiled at the Electronic Transactions Association Annual Meeting and Expo.

The PCI SSC will also roll out a programme this autumn to include maintenance of a list of validated payment applications.

This list will enable buyers to identify the payment applications that have been recognised by the PCI SSC and meet the new standard.

Criminals are increasingly targeting vulnerabilities in payment applications to steal payment card data, according to the PCI, and some software may be storing sensitive card data on a user's system unknowingly.

"Many merchants and retailers rely on third-party software vendors for applications that run payment processing," said Joseph Finizio, executive director of the Retail Solutions Providers Association.

"Having the PCI SSC manage a globally-recognised list of validated payment applications will make it easier for merchants of all sizes to select validated payment applications that are accepted by all the major payment brands, ensuring that cardholder data continues to be secure."

Furthermore, over the coming months, the PCI SSC will be qualifying companies to become Payment Application Qualified Security Assessors (PA-QSAs).

Approved companies will be recognised in a PCI SSC maintained and published list and can begin conducting PA-DSS assessments in accordance with Security Audit Procedures.

"The issuance of the PA-DSS and a defined process for PA-QSAs is another key milestone for the PCI SSC," said Bob Russo, general manager of the PCI SSC.

"Having a single source of information on approved payment applications and security assessors provides business value to merchants and service providers, and allows them to make informed choices regarding the security of their payment application."

See also:

HackingEasy-to-use crime-ware toolkits on the rise  08 Apr 2008
Computer theftPCI compliance does not guarantee security  04 Apr 2008
NetEvents panel warns of ambiguity in PCI compliance  28 Sep 2007
Council takes over from credit card companies  13 Sep 2007

All Ecommerce
Tags: Pci, Dss, Security, Ecommerce, Integration, Security, Strategy

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Greythorn IT
Leading Mobile Network vendore is currently seeking a Process consultant for a positions based either in the Middle east or Africa. We are looking for around 10 years experience with at least 5 years business ... more >
| Greythorn IT
Tier 1 Network solutions provider is currently seeking an experienced Telecommunications sales manager to work in their Abu Dhabi office. There is a brilliant benefits package as well as an attractive salary available for the ... more >
| Greythorn IT
Leading network solutions provider in Egypt is currently seeking and experienced Egyptian Network Operation /Supervision Engineer. There are competitive packages and attractive benefits package on offer for the right candidate. You will be responsible to ... more >
| Greythorn IT
A leading network Solutions vendor is currently seeking an Egyptian national to act as a Service Assurance manager out of their Egyptian office. Ideally we are looking for someone with Vendor based experience however other ... more >
More job opportunities