Latest Comments
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM

PCI council unveils payment application standard

  • Email a Friend
  • Print Page
PCI council unveils payment application standard
By Dan Kaplan
Apr 17, 2008 10:07 AM
Tags: PCI | council | unveils | payment | application | standard
The council announced on Tuesday that is making available version 1.1 of the PA-DSS (Payment Application Data Security Standard) to complement two other standards it already administers - the well-known PCI-DSS, a 12-step mandate for safeguarding credit card information, and the PCI PIN Entry Device (PED) standard, which governs devices that accept Visa or MasterCard PINs.

All five major card brands have agreed to the new payment application standard, which lays out 14 separate requirements for software developers that build programs that process credit card payments, said Bob Russo, general manager of the PCI council.

"It's the weakest link out there," Russo told SCMagazineUS.com on Wednesday. "The application is always the way they get in and if they don't get in that way, they always try to get in that way."

By taking over control of the standard, the council will be responsible for training qualified security assessors (QSAs), who will be responsible for vetting and approving payment applications that live up to the requirements.

The guidelines include protecting wireless transmissions and prohibiting the retention of magnetic stripe data , Russo said.

Currently, Visa is the only card brand that requires its member merchants to deploy applications that comply with the standard, he said. That may change now that the council is taking the lead role.

A Visa spokesman said the company could not comment on the announcement but planned to post information related to the standard on its website this week.

Even though the council oversees all three standards related to credit card security, the card brands are responsible for penalising any offenders.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Breaches & Exposures Whitepapers