Skip the navigation
News Analysis

Changes to PCI Data Security Standard leave questions unanswered

PCI DSS 2.0 mostly about minor tweaks, analysts say

By Jaikumar Vijayan
August 13, 2010 06:00 AM ET

Computerworld - A new version of the PCI Data Security Standard scheduled for release later this year is likely to attract more attention for what it leaves unaddressed rather than what it changes, analysts say.

That assessment is based on a preview of proposed changes to the standard that was released today by the PCI Security Standards Council, the body that administers the Payment Card Industry Data Security Standard (PCI DSS).

The preview suggests that most of the changes in PCI DSS 2.0, which is scheduled for release in October, are going to be incremental in nature and unlikely to cause major headaches for companies covered by PCI.

Much of the emphasis in the new version appears to be on fleshing out and clarifying existing guidelines rather than on introducing new ones.

But the new standard appears to leave largely untouched several issues where companies are looking for more guidance from the PCI council, analysts said.

"The standard's revisions seem like a positive step and don't seem to impose a lot of extra work and unreasonable requirements on complying organizations," said Avivah Litan, an analyst at Gartner.

"But what is glaringly lacking is progress on the hard and most important issues, including the implications of adopting alternative technologies" on PCI compliance requirements, she said.

According to Litan, many Gartner clients are trying to understand whether their adoption of new technologies such as chip cards, tokenization and end-to-end encryption will limit the scope of their compliance requirements, Litan said.

But most of the clarifications around such issues have been left for special interest groups to figure out, she said. "These SIGs are not being held to any particular deadlines, and it's still unclear how their reports will fold into PCI requirements," she said.

The PCI Security Standards Council's guidance around virtualization technologies is another area that is going to be closely watched, said James Paul, senior vice president of delivery at Trustwave, which provides PCI assessment services for many of the largest retailers in the country.

"Overall, there are no big surprises here. There is certainly nothing in the proposed list that our clients will have a lot of heartburn addressing," Paul said.

Today's preview indicates that the new standard will offer new guidance on how the use of virtualization technologies will impact PCI compliance requirements, he said. But a lot will depend on the amount of detail that is provided in the new version of the standard, he added.

"I'm encouraged that they are giving some additional guidance around virtualization," Paul said. "But we just can't get enough concrete details fast enough."

Many Trustwave customers want to know today if their use of virtualization technologies will increase the scope of their PCI requirements, he noted. "It's an emerging technology. There are a lot of questions around it," Paul said. "There are a lot of people somewhat hesitant to dive into it until they see some guidance."



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security Hardware and Software White Papers
DLP Solutions and Strategies Reviewed
According to the 2011 Verizon Data Breach Report, 96% of data compromises were avoidable and 86% were discovered by someone other than the...
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
All Security Hardware and Software White Papers
Security Hardware and Software Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Security Hardware and Software Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs