More Resources

Company claims industry's first end-to-end solution for PCI compliance.

Software World • Nov, 2007 • SECURITY VIEWPOINT

IBM have released a new program that provides products and services to help customers achieve compliance with the Payment Card Industry Data Security Standard (PCI DSS). Unlike similar offerings, the comprehensive program is designed to take companies through the entire PCI compliance process, from assessment to compliance to certification, helping them meet all 12 PCI requirements for safeguarding customer payment card data.

PCI is a global standard that applies to any company that processes, transmits or stores credit card information. The standard was created by credit card companies to help organisations prevent security breaches. Any company that processes credit card data today could be threatened by cyber-crime attacks, resulting in customer identity theft. Those companies that do not achieve PCI compliance could have their ability to process credit cards revoked, or could face increased processing costs. Given the far-reaching impacts security threats can have on organisations, non-compliant companies risk significant financial and customer losses and damaging effects on brand reputation. Despite the threats of fines and a recent rash of high-profile data breaches, the rate of PCI compliance is estimated to be less than 50 percent. In fact, according to a report by industry analyst firm Gartner, Inc., Visa USA indicates that, as of July 2007, 39 per cent of level-one merchants (defined as those that process more than 6 million transactions annually) and 33 per cent of level-two merchants (defined as those that process between 1 million and 6 million transactions annually) are compliant with the PCI Data Security Standard. (1)

"As many merchants have learned in recent years, meeting some or even most of the mandated PCI requirements is no longer sufficient," said IBM.

The Requirements

The PCI Data Security Standard is a set of 12 requirements for safeguarding payment card data. These requirements range from installing and maintaining firewall configurations to encrypting transmission of cardholder data and maintaining proper policies and testing procedures.

To help customers meet all 12 of these requirements, the PCI solution includes consulting services for compliance gap analysis, remediation, validation, ongoing testing and reporting, as well as a range of products that help organisations with each aspect of security planning, management and compliance reporting. These include security process assessment, security information and event management, storage management, encryption, identity and access management, change and configuration management, intrusion prevention systems, application layer testing and user activity monitoring software.

Additionally, IBM claims to be one of only three companies in the world that is globally certified to perform PCI Assessments, PCI Quarterly Network Scanning, PCI Payment Application Assessments and PCI Incident Response Services.

The five-phase program includes:

- Assessment -- This includes an overall "security health check" to understand areas for remediation and how to become and remain compliant.

- Design -- This phase involves development of security strategy, policies, standards and procedures, as well as incident response planning, security architecture design and implementation planning.

- Deployment -- This phase focuses on implementation and optimisation of security software and hardware to help secure customer data, both in motion and at rest, as well as on migration services and vulnerability remediation.

- Management -- Providing ongoing support on this phase with security monitoring and management software solutions, as well as staff augmentation and emergency response, forensic analysis and threat-analysis services.

- Education -- Ongoing product courses, training and security awareness programs so customers can appropriately train personnel to maintain PCI compliance over the long term.

IBM has also sdded specific PCI compliance capabilities to its IT Governance and Risk Management portfolio.

(1) -- Gartner, Inc., "PCI Questions Are Often Clearer Than Their Answers," by Avivah Litan and John Pescatore, August 7, 2007

www.ibm.com


COPYRIGHT 2007 A.P. Publications Ltd. Reproduced with permission of the copyright holder. Further reproduction or distribution is prohibited without permission.
Copyright 2007, Gale Group. All rights reserved. Gale Group is a Thomson Corporation Company.
NOTE: All illustrations and photos have been removed from this article.


Browse by Journal Name:
Today on Entrepreneur
Related Video

e-Business & Technology
Franchise News
Business Book Sampler
Starting a Business
Sales & Marketing
Growing a Business
E-mail*:
Zip Code*: