Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cloud
    • Cloud
    • Cybersecurity
    • Virtualization

    PCI Council, Cisco Provide Guidance on PCI-Compliant Virtual Systems

    Written by

    Fahmida Y. Rashid
    Published June 14, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The PCI Security Standards Council issued a new guidance to help IT administrators deploy and manage cloud environments and virtual data centers while ensuring PCI compliance where necessary.

      The PCI DSS Virtualization Guidelines Information Supplement, released June 14, covers a number of virtualization areas, including different types of virtualization, specific notes on cloud computing and how to ensure “mixed” virtual environments are compliant, Bob Russo, the general manager of the PCI Council, told eWEEK. The guidance does not contain new requirements or standards but is intended to be a primer on how to ensure virtual environments comply with the existing PCI-DSS 2.0 standard.

      Virtualization technology introduces new risks that may not have existed in the physical environment, Kurt Roemer, chief security officer at Citrix Systems and chairman of the Virtualization Special Interest Group, told eWEEK. The Virtualization SIG is comprised of 33 PCI-member organizations and drafted the latest guidance.

      Data stored in virtual environments are already covered by PCI DSS 2.0, which went into effect in January. PCI-compliant organizations don’t have to start from scratch when looking at this guidance, Russo said.

      Merchants and vendors “asked for additional clarity,” and the guidance provides the explanation and details for the requirement in the context of virtualization, Russo said.

      The Virtualization SIG looked at each requirement in PCI DSS and examined it within the context of the virtual environment. The guidance provides additional details around each requirement, Roemer said.

      For example, a PCI DSS requirement specifies that administrators have to segment PCI workloads from other workloads. The guidance applied the requirement to the virtual environment to note that firewalls must segment virtual machines with different “trust zones” in a single environment, according to the document. This is especially important in a multi-tenant public cloud environment, Roemer said.

      Virtual hosts are now subject to the requirement that administrators “limit access to system components and cardholder data to only those individuals whose job requires such access,” according to the guidance document, suggesting that organizations will need to implement access controls on the hypervisor, host and other components.

      The PCI Council avoids endorsing any type of technology or technique in its guidance, leaving the actual implementation to the individual enterprise. Numerous areas will evolve, such as storage, virtual networking and cloud computing, but the requirements to manage the technology should not change, Troy Leach, PCI Council’s chief standards architect, told eWEEK. Future guidance and standards will address evolving risks, Leach said.

      “There is no single method for securing virtualized environments,” Russo said.

      The SIG originally started out looking at server virtualization because that was what most members were focusing on as part of their virtualization efforts, Roemer said. However, the group discovered there were other usages, such as for applications, desktops and storage servers.

      The guidance affirms that if virtualization technologies are being used in the cardholder data environment, PCI DSS requirements must be applied. A key finding from this guidance was that even if the organization was running the application, database or storage system on a virtual machine, the merchant needed to treat is as if it was on a physical server, Russo said.

      At the same time, Cisco announced it will be releasing a Cisco PCI Solution for Retail Design and Implementation Guide at the end of the month to help enterprises and retail customers with an in-depth guide on how organizations can achieve PCI compliance. The document provide guidance for different types of “store footprints,” such as size of the retail organization and the type of services provided, Lindsay Parker, global retail industry director at Cisco, told eWEEK..

      The PCI implementation guide is “comparable to a cookbook, a how-to manual” on securing the organization’s systems, including virtual and wireless infrastructure, Parker said. Unlike the guidance from the PCI Council, Cisco’s document is unabashedly promoting Cisco’s and its partners’ products, including HyTrust, RSA Security and EMC, according to Parker.

      “While it would be nice” if the customers bought the full range of products in order to deploy PCI-compliant virtual environments, Cisco is hoping customers can use the detailed instructions to figure out what needs to be done to achieve compliance, Parker said.

      Many retail companies and enterprises tend to view PCI compliance as a “point in time exercise,” one that is done once the audit is completed, according to Parker.

      At least four other industry sectors, including government, education, health care and financial services, are taking the retail guide and modifying with industry-specific information to create customized guides for those areas, Parker said.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×