Everything Has Changed

See how Intel developed the cure for deskside help visits in this video directed by Christopher Guest of Spinal Tap fame. Click here.
 
Cross-client Centrino® and  Core™2 processor with vPro™ Processor Technology Technical White Paper
A deeper technical dive on how vPro usage models work on both desktop and notebook PCs. Click here.
 
Intel® vPro Technology ROI Estimator
Intel® Core2™ Duo and Centrino® with vPro™ Processor technology cross-client ROI estimator. Click here.
 
WiPro Intel® Centrino® Pro with vPro™ Processor Technology
The Benefits of Intel® Centrino® Pro Processor Technology in the Enterprise. Click here.
 
Workstations Products Platforms Brief
Intel’s family of workstation platforms gives you the tools to move from serial to parallel workflows and enables you to iterate through alternatives faster and innovate more. Click here.
 
Itanium Solutions
Learn how Itanium®-based solutions are changing the way enterprises do business. Click here.


Select a newsletter and click Join to sign up!
Internet Daily
InternetNews

Business Report

Boston News
DC News
NY News
SiliconValley News




Whitepaper: Using Storage Virtualization & Thin Provisioning to add Capacity. HP continues to deliver on its promise of improving the efficiency of already installed storage assets. Read the financial case study results.





The Tangled Web of PCI Compliance

New e-commerce security requirements are vague enough to leave everyone wondering what to do.

May 2, 2008
By Richard Adhikari: More stories by this author:

PCI Compliance

Fear and loathing will dominate when Best Practice 6.6 of the PCI Data Security Standard becomes a requirement June 30.

The regulation requires that merchants dealing with debit and credit cards tighten up their security by both conducting application code reviews and installing Web application firewalls.

It was put forth by the PCI Security Standards Council, which issues, maintains and enforces the PCI security standards that govern payment account data security to which all corporations that deal with payment cards must adhere.

However, while stating that "proper implementation of both options would provide the best multi-layered defense", the Council says, in essence, that some merchants won't be able to implement both. The solution: select the best option for their needs. This is leading to compliance problems.

"We're addressing the problem in two ways," said Bob Russo, general manager of the PCI Security Standards Council. "If you have custom application code, it needs to be reviewed for common vulnerabilities, either by yourself or by a company that does application code reviews by a standard like OWASP. The Open Web Application Security Project, OWASP, is a worldwide free and open community focused on improving the security of application software whose materials are available under an open source license.

For off-the-shelf software, "installing an application layer firewall in front of a Web facing app will work as well," Russo explained. "You need security in the application itself if you can do it but that's not necessarily the way you need to look at this; either way will suffice."

In essence, it's going to have to be a business decision. And which option merchants choose depends on how much money they have.

"Bigger merchants have more budget and can afford to do both; but when you get into Level 4 merchants, which Visa describes as "any merchant processing fewer than 20,000 Visa e-commerce transactions per year," margins tend to be thin. (By contrast, Level-1 merchants have more than 6 million transactions a year.) Level 4 merchants "don't have lots of staff," said Ryan Barnett, director of application security at Breach Security and an instructor at the training-focused SANS Institute. "They're forced to choose between the two options."

Next page: Tough choices thanks to costs

Go to page: 1  2  Next