Company claims industry's first end-to-end solution for PCI compliance.
PCI is a global standard that applies to any company that processes, transmits or stores credit card information. The standard was created by credit card companies to help organisations prevent security breaches. Any company that processes credit card data today could be threatened by cyber-crime attacks, resulting in customer identity theft. Those companies that do not achieve PCI compliance could have their ability to process credit cards revoked, or could face increased processing costs. Given the far-reaching impacts security threats can have on organisations, non-compliant companies risk significant financial and customer losses and damaging effects on brand reputation. Despite the threats of fines and a recent rash of high-profile data breaches, the rate of PCI compliance is estimated to be less than 50 percent. In fact, according to a report by industry analyst firm Gartner, Inc., Visa USA indicates that, as of July 2007, 39 per cent of level-one merchants (defined as those that process more than 6 million transactions annually) and 33 per cent of level-two merchants (defined as those that process between 1 million and 6 million transactions annually) are compliant with the PCI Data Security Standard. (1)
"As many merchants have learned in recent years, meeting some or even most of the mandated PCI requirements is no longer sufficient," said IBM.
The PCI Data Security Standard is a set of 12 requirements for safeguarding payment card data. These requirements range from installing and maintaining firewall configurations to encrypting transmission of cardholder data and maintaining proper policies and testing procedures.
To help customers meet all 12 of these requirements, the PCI solution includes consulting services for compliance gap analysis, remediation, validation, ongoing testing and reporting, as well as a range of products that help organisations with each aspect of security planning, management and compliance reporting. These include security process assessment, security information and event management, storage management, encryption, identity and access management, change and configuration management, intrusion prevention systems, application layer testing and user activity monitoring software.
Additionally, IBM claims to be one of only three companies in the world that is globally certified to perform PCI Assessments, PCI Quarterly Network Scanning, PCI Payment Application Assessments and PCI Incident Response Services.
The five-phase program includes:
- Assessment -- This includes an overall "security health check" to understand areas for remediation and how to become and remain compliant.
- Design -- This phase involves development of security strategy, policies, standards and procedures, as well as incident response planning, security architecture design and implementation planning.
- Deployment -- This phase focuses on implementation and optimisation of security software and hardware to help secure customer data, both in motion and at rest, as well as on migration services and vulnerability remediation.
- Management -- Providing ongoing support on this phase with security monitoring and management software solutions, as well as staff augmentation and emergency response, forensic analysis and threat-analysis services.
- Education -- Ongoing product courses, training and security awareness programs so customers can appropriately train personnel to maintain PCI compliance over the long term.
IBM has also sdded specific PCI compliance capabilities to its IT Governance and Risk Management portfolio.
(1) -- Gartner, Inc., "PCI Questions Are Often Clearer Than Their Answers," by Avivah Litan and John Pescatore, August 7, 2007