Find White Papers
Home
About Us
List Your Papers
    
> Tripwire > PCI Compliance: Are You Onboard?

PCI Compliance: Are You Onboard?

White Paper Published By: Tripwire

This paper covers the basic requirements of PCI, with a focus on the administrative and technical elements of the program. It also reviews the validation requirements of the standard and potential sanctions for failure to comply.



Tags : 
pci, pci compliance, payment card, credit card, credit cards, payment card industry, cisp, privacy

Tripwire
Published:  Nov 30, 1999
Type:  White Paper
Length:  5 pages

Solution Brief
PCI Compliance: Are You Onboard?
In 2005, high-profile credit card PCI establishes stringent standards on Member financial institutions are and credit data loss and how merchants process, store or transmit responsible not only for their own compromise became so common- cardholder data. These standards are a set compliance, but also for ensuring place that the Washington Post of comprehensive security requirements the compliance of their Merchants dubbed it "the year of the data that combine technology, policies, educa-and Service Providers for all payment channels, including breach." Long before that rash of tion, and awareness as well as industry best in-store, mail/telephone-order, events, however, Visa had developed practices into an integrated framework.and e-commerce. the first major commercial standard for protection of cardholder data. Adding to the compliance burden is the presence of "double jeopardy." Members Created in 2001, Visa's Cardholder are not only responsible for their own PCI Information Security Program (CISP, DSS compliance, but also the compliance also known as AIS (Account status of their Merchants and Service Information Security) internationally) Providers across all payment channels, defined a standard for securing Visa including in-store, mail/telephone-order, cardholder data for U.S. customers, and e-commerce. wherever that data was located. PCI is a technical standard (not a regula-In 2004, Visa and MasterCard collab- tion) that offers strong recommendations orated to develop common security conforming to long-established security requirements. Based on CISP, the best practices. Complying with PCI makes result was the Payment Card Industry good business sense in that it can result Data Security Standard (PCI DSS). All in a more reliable, streamlined IT infra-Merchants and Service Providers structure, improve service delivery, (including international Visa increase availability, and reduce risk-members) that handle, transmit, leading to improved customer confidence store or process information and loyalty, simplified auditing, and more concerning either of these cards, or effective cost controls.related card data, were required to be compliant as of June 30, 2005. In September 2006, the PCI Security Standards Council released PCI Data Security Standard v1.1. Solution?Brief
How Tripwire Helps Companies regulations. Not only is this insurance Achieve PCI Compliance against the financial impact of fines, but also the time and resources needed to The PCI requirements help Members, prepare for audits is reduced.Merchants, and Service Providers protect their information assets and meet the Change Visibilityobligations to the credit card companies' Even if the IT infrastructure is perfectly in payment structure. The requirements compliance with PCI, one small change include making certain that firewalls, to a server or network device can result in Complying with PCI makes good routers, database servers and other critical negative impacts if it's not properly business sense in that it can result systems assets adhere to the PCI DSS. detected and reported. Change can be in a more reliable, streamlined IT accidental, benign, malicious, intentional infrastructure, improve service Tripwire software can help organizations in nature, and originate from inside or delivery, increase availability, and comply with these requirements (specifi- outside an organization. But without a reduce risk-leading to improved cally in the area of file integrity way to know when change occurs, and customer confidence and loyalty, simplified auditing, and more monitoring, firewall/router security whether it is desired or undesired, IT effective cost controls. compliance monitoring, and change teams have few options for minimizing control) by monitoring critical files and damage. By exposing unauthorized or alerting appropriate personnel of any unintended changes, Tripwire can unauthorized changes. Section 10.5.5 provide the information necessary to requires "file integrity monitoring/change validate internal processes-and enable detection software on logs to ensure that rollback to compliant status.existing log data cannot be changed without generating a... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search