PCI council sets payment security standard

New rules on the storage of payment details

Written by Ian Williams

Many merchants and retailers rely on third-party software vendors for applications that run payment processing

Joseph Finizio Retail Solutions Providers Association

The Payment Card Industry Security Standards Council (PCI SSC) has announced the release of version 1.1 of the Payment Application Data Security Standard (PA-DSS).

PA-DSS is designed to help software vendors and others develop secure payment applications that do not store prohibited data, such as full magnetic stripe or Pin data, and ensure that payment applications support compliance with the standard.

The requirements apply to payment applications that are sold, distributed or licensed to third parties.

They do not apply to in-house payment applications developed by merchants or service providers that are not sold to a third party, but these applications must still be secured in accordance with the PCI DSS.

The new standard was unveiled at the Electronic Transactions Association Annual Meeting and Expo.

The PCI SSC will also roll out a programme this autumn to include maintenance of a list of validated payment applications.

This list will enable buyers to identify the payment applications that have been recognised by the PCI SSC and meet the new standard.

Criminals are increasingly targeting vulnerabilities in payment applications to steal payment card data, according to the PCI, and some software may be storing sensitive card data on a user's system unknowingly.

"Many merchants and retailers rely on third-party software vendors for applications that run payment processing," said Joseph Finizio, executive director of the Retail Solutions Providers Association.

"Having the PCI SSC manage a globally-recognised list of validated payment applications will make it easier for merchants of all sizes to select validated payment applications that are accepted by all the major payment brands, ensuring that cardholder data continues to be secure."

Furthermore, over the coming months, the PCI SSC will be qualifying companies to become Payment Application Qualified Security Assessors (PA-QSAs).

Approved companies will be recognised in a PCI SSC maintained and published list and can begin conducting PA-DSS assessments in accordance with Security Audit Procedures.

"The issuance of the PA-DSS and a defined process for PA-QSAs is another key milestone for the PCI SSC," said Bob Russo, general manager of the PCI SSC.

"Having a single source of information on approved payment applications and security assessors provides business value to merchants and service providers, and allows them to make informed choices regarding the security of their payment application."

Further reading

Cyber-crooks turn to managed services

Easy-to-use crime-ware toolkits on the rise   More...

Security expert slams PCI auditing

PCI compliance does not guarantee security   More...

Experts call for regulation of PCI assessors

NetEvents panel warns of ambiguity in PCI compliance   More...

PCI SSC takes on Pin Entry Device security

Council takes over from credit card companies   More...

Related articles

PCI SSC takes on Pin Entry Device security

Council takes over from credit card companies   More...

Online banking fraud on the decline

But credit card fraud abroad pushing up overall losses   More...

Barclaycard deals OnePulse three-in-one

Londoners to get Oyster-embedded credit and contactless payment card   More...

OSI approves Microsoft open source licences

Redmond now officially an open source vendor   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement