PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

PCI in the Cloud

By Mercator Advisory Group
February 11, 2013
in Analysts Coverage
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
pay taxes design, vector illustration eps10 graphic

pay taxes design, vector illustration eps10 graphic

Bankinfosecurity.com has an audio interview with Bob Russo of the Payment Card Industry Security Standards Council that highlights the Council’s recent guidance on cloud computing services and payment card data security.

The need for the guidance relates to the nature of cloud services and the presence in the market of so-called “public clouds,” where the cloud services provider offers its cloud as a shared service between multiple customers. Many segments of the payments industry are relying more and more on cloud services; consequently, Russo indicates, the responsibility for securing card data in the cloud (especially public clouds) is not so clear-cut.

From Bank Info Security:

“Cloud services provide an attractive opportunity for outsourcing,” says Russo, general manager of the Payment Card Industry Security Standards Council. “But from our perspective, we want to be sure organizations are aware of all of the risks before they entrust payment data and processing to a third party.”

On Feb. 7, the council released its PCI DSS Cloud Computing Guidelines Information Supplement , a set of best practices and guidelines developed by the PCI Cloud Special Interest Group.

Russo highlights the main point of the guidance: Know where card data is stored at all time. The challenge organizations face when storing card data in the cloud is that they lose an element of control. And sometimes card data can wind up being stored in multiple locations or in environments that are not well protected, he warns.

“Cloud is a shared responsibility,” Russo says. “Outsourcing the management of these security controls really doesn’t equate to outsourcing your responsibility to be PCI-DSS compliant. Cloud services are not all created equally, so you need to understand what PCI-compliant cloud service really means.”

Click here to read more from Bank Info Security.

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    Startups: Fintechs Data Streaming Technology in Banking, corporates Enriched Data vs Faster Payments

    Fighting Fraud in the Era of Faster Payments

    February 13, 2026
    cross-border payments

    Solving for Fraud in Cross-Border Payments Requires Better Counterparty Verification

    February 12, 2026
    agentic commerce

    Demystifying the Agentic Commerce Enigma

    February 11, 2026
    payment gateways

    How Payment Gateways for Businesses Can Help You Offer Your Customers More Options

    February 10, 2026
    Reserve Bank of India (RBI) Extends Mandate for Tokenization to June '22

    Late Payments? Governments Are Taking Action

    February 9, 2026
    ai phishing

    The Fraud Epidemic Is Testing the Limits of Cybersecurity

    February 6, 2026
    stablecoins b2b payments

    Stablecoins and the Future of B2B Payments: Faster, Cheaper, Better

    February 5, 2026
    Payment Facilitator

    The Payment Facilitator Model as a Growth Strategy for ISVs

    February 4, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2024 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result