Saturday | 30 August, 2008
Computerworld
Auditor warns: Beware of security vendors selling PCI compliance
Cybertrust and Cisco jump on the bandwagon
Michael Crawford 22/01/2007 14:31:20

Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Strategies for Dealing With IT Complexity 24/12/2007 10:30:47

    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
  • +

    What Price Innovation? 05/11/2007 13:44:31

    CIOs say they want more than the traditional “your mess for less” relationship with their outsourcing providers. And the providers want to market themselves as partners in innovation. So why isn’t it happening?
    CIOs say they want more than the traditional "your mess for less" relationship with their outsourcing providers. And the providers want to market themselves as partners in innovation. So why isn't it happening?
  • +

    Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15

    Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
    Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Customers beware when buying an approved Payment Card Industry Data Security Standard (PCIDSS) solution. It may be approved but implementing the solution doesn't mean customers are immediately compliant, according to a PCIDSS accredited auditor.

Drazen Drazic, managing director of auditing firm Security-Assessment.com, said customers shouldn't assume they are compliant simply because they have purchased an approved PCIDSS solution.

The standard was introduced in 2004 to ensure retailers are responsible for cardholder data or risk facing fines of more than $500,000.

Drazic's comments follow the launch of a number of merchant retail solutions that address PCI compliance.

It is the selling point for a new retail solution jointly released by security heavyweights Cybertrust and Cisco Systems last week.

According to a press release, Cisco will provide audited network architectures tailored to individual stores under the mandate and Cybertrust will validate the gear as PCI compliant.

Cybertrust is an approved assessor for the PCI DSS for American Express, MasterCard and Visa. Cisco provides approval under the Cisco Secure Store Program, which offers both the PCI Solution for Retail and a Digital Video Surveillance solution.

According to Cisco, the Digital Video Surveillance solution includes "human and automated video surveillance, and reduces retail shrink through improved loss prevention capabilities".

However, Cisco did not confirm whether the surveillance solution is part of the accreditation for PCI compliance, or an additional feature.

Cisco did not respond to repeated attempts by Computerworld to clarify how its solution complies with PCIDSS.

Drazic said using a solution from an approved assessor doesn't automatically make a company compliant.

He said some vendors are using PCI compliance to try and sell product.

"Like products from any other reputable vendor, it's how you implement, manage and maintain those systems that is the key; simply implementing this product doesn't make you compliant," Drazic said.

"Do you need to throw away what you have now? No way if it is working. Do you need to consider these offerings? Possibly, but it shouldn't be different to any other purchase.

"This is an interesting approach by Cisco and CyberTrust to make inroads into what is becoming a potentially lucrative market, and the PCI name is becoming a selling point. Is there anything really new about this solution aside from the PCI name? I doubt it."

Despite repeated attempts to get Cisco and CyberTrust to respond to these claims and clarify their partnership, both companies did not respond.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

Using EMC Celerra IP Storage with Vmware Infrastructure 3 over iSCSI and NFS

Learn to tie virtualized computing to virtualized storage, to offer a dynamic set of capabilities within the data centre and create improved performance and system reliability. Discover how best to utilize EMC Celerra in a VMware ESX environment.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links