Company claims industry's first end-to-end
solution for PCI compliance.
IBM have released a new program that provides products and services
to help customers achieve compliance with the Payment Card Industry Data
Security Standard (PCI DSS). Unlike similar offerings, the comprehensive
program is designed to take companies through the entire PCI compliance
process, from assessment to compliance to certification, helping them
meet all 12 PCI requirements for safeguarding customer payment card
data.
PCI is a global standard that applies to any company that
processes, transmits or stores credit card information. The standard was
created by credit card companies to help organisations prevent security
breaches. Any company that processes credit card data today could be
threatened by cyber-crime attacks, resulting in customer identity theft.
Those companies that do not achieve PCI compliance could have their
ability to process credit cards revoked, or could face increased
processing costs. Given the far-reaching impacts security threats can
have on organisations, non-compliant companies risk significant
financial and customer losses and damaging effects on brand reputation.
Despite the threats of fines and a recent rash of high-profile data
breaches, the rate of PCI compliance is estimated to be less than 50
percent. In fact, according to a report by industry analyst firm
Gartner, Inc., Visa USA indicates that, as of July 2007, 39 per cent of
level-one merchants (defined as those that process more than 6 million
transactions annually) and 33 per cent of level-two merchants (defined
as those that process between 1 million and 6 million transactions
annually) are compliant with the PCI Data Security Standard. (1)
"As many merchants have learned in recent years, meeting some
or even most of the mandated PCI requirements is no longer
sufficient," said IBM.
The Requirements
The PCI Data Security Standard is a set of 12 requirements for
safeguarding payment card data. These requirements range from installing
and maintaining firewall configurations to encrypting transmission of
cardholder data and maintaining proper policies and testing procedures.
To help customers meet all 12 of these requirements, the PCI
solution includes consulting services for compliance gap analysis,
remediation, validation, ongoing testing and reporting, as well as a
range of products that help organisations with each aspect of security
planning, management and compliance reporting. These include security
process assessment, security information and event management, storage
management, encryption, identity and access management, change and
configuration management, intrusion prevention systems, application
layer testing and user activity monitoring software.
Additionally, IBM claims to be one of only three companies in the
world that is globally certified to perform PCI Assessments, PCI
Quarterly Network Scanning, PCI Payment Application Assessments and PCI
Incident Response Services.
The five-phase program includes:
- Assessment -- This includes an overall "security health
check" to understand areas for remediation and how to become and
remain compliant.
- Design -- This phase involves development of security strategy,
policies, standards and procedures, as well as incident response
planning, security architecture design and implementation planning.
- Deployment -- This phase focuses on implementation and
optimisation of security software and hardware to help secure customer
data, both in motion and at rest, as well as on migration services and
vulnerability remediation.
- Management -- Providing ongoing support on this phase with
security monitoring and management software solutions, as well as staff
augmentation and emergency response, forensic analysis and
threat-analysis services.
- Education -- Ongoing product courses, training and security
awareness programs so customers can appropriately train personnel to
maintain PCI compliance over the long term.
IBM has also sdded specific PCI compliance capabilities to its IT
Governance and Risk Management portfolio.
(1) -- Gartner, Inc., "PCI Questions Are Often Clearer Than
Their Answers," by Avivah Litan and John Pescatore, August 7, 2007
www.ibm.com
COPYRIGHT 2007 A.P. Publications
Ltd. Reproduced with permission of the copyright holder. Further reproduction or distribution is prohibited without permission.
Copyright 2007, Gale Group. All rights
reserved. Gale Group is a Thomson Corporation Company.
NOTE: All illustrations and photos have been removed from this article.