PCI Compliance in the Cloud with Qualys

執筆者
Brian Prince
Brian Prince
Published: Dec 21, 2007
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Qualys’ in-the-cloud strategy for helping businesses face compliance requirements took a new turn this week with QualysGuard PCI 2.0 and its new network scanning and reporting capabilities.

With the new global scanning functionality, merchants can segment their network by business units and scan a select number of hosts at any given time or simultaneously, reducing the amount of time it takes a large organization to scan its network. When every segment of the network has passed the scan, users can create a single report to send to credit card issuers and acquiring banks.

“We look basically for any type of form or vulnerability or misconfiguration that can lead to an exposure or a hack,” said Amer Deeba, vice president of product marketing at the Redwood Shores, Calif., company. “So it can be application-level vulnerabilities, system vulnerabilities, network-level vulnerabilities, Web browser type of vulnerabilities.”

Confusion reigns among retailers over the details of PCI compliance. Read why.

According to a report from Visa issued on Oct. 24, 65 percent of the nation’s largest retailers are compliant with the PCI (Payment Card Industry) Data Security Standard. That number is an increase of 81 percent from December 2006 and 63 percent since July. But the statistic is hardly a cause for celebration—it means 35 percent of large retailers were still out of step with the requirements a month after the Sept. 30 deadline. The challenges of achieving compliance have given birth to countless numbers of tools from vendors looking to address security and auditing concerns posed by the standard.

“The way we differentiate ourselves really is our model; everything is delivered over the Internet as an application software as a service,” Deeba said. “You get an account, you log on, and you have full access and full capability to do the entire PCI process.”

In the latest version of its service, which the company announced Dec. 17, Qualys allows merchants to get quick access to the latest compliance summary of their entire PCI-scoped network and run reports with specific, advanced search criteria, including host name, IP address and vulnerability severity. Version 2.0 also provides multiple questionnaires to be generated for separate business units that can be submitted to up to five different acquiring banks at any one time.

Advertisement

QualysGuard PCI 2.0 is available now for an annual subscription starting at $495.

Check out eWEEK.com’s Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK’s Security Watch blog.

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。