Tuesday | 2 December, 2008
Visa's security best practices to become payment standard
Aggressively touted guidelines are apparently everywhere you want to be
Jaikumar Vijayan 09/11/2007 05:54:07

The PCI Security Standards Council, the body managing the Payment Card Industry data security initiative, on Wednesday announced that it will anoint a set of best practices developed by Visa as the new security standard for third-party application software in the payment industry.

The new standard is called the Payment Application Data Security Standard (PA-DSS) and is based on Visa's Payment Application Best Practices (PABP).

Over the next few months, the PCI Security Standards Council, together with participating organizations, security auditors, and vulnerability scanning vendors, will offer comments and suggestions relating to the PA-DSS.

The security council will then incorporate this feedback and publish a final version of the application security standards in the first quarter of 2008, said Bob Russo, general manager of the security standards council.

The application security standards are designed to address growing security concerns related to the third-party payment applications used by retailers and other companies accepting credit card transactions. Many of these applications are old and lack many of the security controls mandated by the credit card companies under the PCI data security standard.

For instance, older payment application software products are designed to capture and store certain kinds of cardholder data by default, even though the practice is explicitly banned under PCI guidelines. Similarly, older payment applications seldom have the transaction-logging capabilities that are required by PCI.

Visa, which has been by far the most aggressive of the credit card associations in pushing PCI, has for some time now tried to address such issues by leaning on software vendors to adopt its set of payment application best practices. Though Visa cannot contractually require the software vendors to adopt these best practices, it has been pressuring them into doing so anyway, by making it mandatory for merchants to use only PABP-compliant third-party payment software.

Just two weeks ago, for instance, it announced formal schedules for companies to ensure that all of their third-party payment applications are PABP-compliant.

With the moved announced yesterday, the PCI council has taken Visa's requirements and forged them into a broader industrywide mandate -- meaning that soon it won't be just Visa that's pressuring payment software vendors to adopt security controls, but MasterCard, Discover Financial Services, American Express Co. and JCB International Credit Card Co. as well.

Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Sign up for our Computerworld newsletters!
RSS Feeds
Market Place

 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Everything you need to know about email and web security (but were afraid to ask)

What you don’t know can destroy your business. It’s hard to imagine modern business without the internet but in the last few years it has become fraught with danger. Read on to discover how internet security can give your business a competitive advantage.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links