More regulation for online retail arrives

A new PCI-DSS regulation requires online retail firms to perform code reviews and use a web application firewall

Written by Dave Bailey

Firms who process payment card industry data online, have another regulation to deal with. They must now become 'PCI-Compliant', after section 6.6 of the Payment Card Industry - Data Security Standard (PCI-DSS) standard came into force throughout Europe on 30 June.

The PCI-security standards council (PCI-SCC) said that PCI-DSS section 6.6 is intended to secure public Internet-facing web applications through two methods – reviewing code for Web applications and installing an application-level firewall. “Whilst proper implementation of both options would provide the best multi-layered defence PCI SSC recognises that the cost and operational complexity of deploying both options may not be feasible,” added the PCI-DSS,.

Andrew Clarke, senior vice president at Lumension Security’ said that adhering to the standard extends beyond compliance. “About half of all account compromises are a result of web-application data breaches and of this, and about 90 per cent of the data compromises are a result of the top 5-10 web-application vulnerabilities, so being PCI-compliant also becomes a competitive differentiator for those that adhere,” he explained.

Tags:

reader comments

related articles

Barracuda launches web site firewall

Could help firms achieve PCI compliance 08 Apr 2008

 

Security top priority for hosting customers

Elinia’s James Carnie says compliance with standards is key in gaining the trust of clients 18 Feb 2008

IBM offers firms PCI compliance

New five-point program designed to give organisations full PCI compliance 02 Nov 2007

Visa relaxes PCI stance

Card giant says it will give firms more time to comply with the data security standard 16 Aug 2007

PCI standard 'ignores' insider threat

Database security firm warns of gaping holes 23 Jun 2008

Security expert slams PCI auditing

PCI compliance does not guarantee security 04 Apr 2008

Retailers struggle to meet PCI deadline

Quick fixes not good enough, warn experts 19 May 2008

related whitepapers

today's top stories

Rules of convergence

While moving to a converged communications platform can bring greater efficiency and flexibility to business dealings, there are also potential legal complications related such matters as data retention and disclosure, as Jon Fell explains 18 Nov 2008

Examining the IT skills challenge

Watch a BCS roundtable debate on the issues affecting IT professionals - the last of a four-part series 17 Nov 2008

Will poor integration derail smart tickets?

Next year could prove to be make or break for plans to have a nationwide smart ticketing scheme in place in time for the 2012 Games, writes Angelica Mari 13 Nov 2008

Charity puts relief work on the map

MapAction is using the latest in geographic information technology to bring speedy relief to disaster victims, writes Tom Young 12 Nov 2008

Computing podcast: Defra's green leadership; and integrated transport problems

Defra is making headway with its green IT strategy; and experts warn integration issues could derail smart tickets 13 Nov 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Has the state of the economy forced to re-evaluate your IT purchasing options?

Has the state of the economy forced to re-evaluate your IT purchasing options?

Are you re-thinking your IT spending?

Previous poll results

Latest audio and video articles

crowd of peopleVideo

Examining the IT skills challenge

Watch a BCS roundtable debate on the issues affecting IT professionals - the last of a four-part series 17 Nov 2008

Audio

Computing podcast: Defra's green leadership; and integrated transport problems

Defra is making headway with its green IT strategy; and experts warn integration issues could derail smart tickets 13 Nov 2008

Latest in-depth articles

Woman wearing a headsetFeatures

How to ensure a smooth converged comms transition

Convergence strategies must be planned carefully, implemented gradually, and follow a clear business plan, writes Josie Sephton 18 Nov 2008

Arriva bus driver and mobile ticketing systemAnalysis

Will poor integration derail smart tickets?

Next year could prove to be make or break for plans to have a nationwide smart ticketing scheme in place in time for the 2012 Games, writes Angelica Mari 13 Nov 2008

Advertisement

Primary Navigation