{"id":25868,"date":"2014-09-09T11:44:24","date_gmt":"2014-09-09T15:44:24","guid":{"rendered":"http:\/\/www.opensource.im\/?p=25868"},"modified":"2014-09-09T11:44:24","modified_gmt":"2014-09-09T15:44:24","slug":"cloudexpo-pci-dss-encryption-requirements","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/encryption\/cloudexpo-pci-dss-encryption-requirements.php","title":{"rendered":"@CloudExpo | PCI-DSS Encryption Requirements"},"content":{"rendered":"<p><p>        Significant money is at stake and in need of protection in    the Payment Card Industry (PCI). The global payment card    industry covers several sectors: banks and financial    institutions (acquirers), issuers, processors, service    providers, merchants carrying out transactions online and via    point of sale terminals in bricks and mortar stores, large and    small.  <\/p>\n<p>    PCI SecurityThe PCI Security Organizations Data    Security Standard (DSS) applies to your business if you store,    process or transmit cardholder data (CHD). The PCI supply chain    is not an isolated entity. It needs to protect itself well    beyond its own  <\/p>\n<\/p>\n<p>    perimeter fences. This is because business entities also need    to protect the billions of people every day that key in their    Personal Identity Numbers (PINs) and other personal data as    they trade or carry out transactions in store or over the    Internet, from fixed and mobile devices using payment cards.    Increasingly, commerce takes place via mobile devices over    wireless networks, with the card itself rarely being physically    present at the store.  <\/p>\n<p>    As credit and debit cards are used more and more, checks are    disappearing in many economies. In a mobile, electronic, global    world, the payment card industry continues to grow. In May    2014, for example, 47.1 billion was spent in the United    Kingdom on cards of all types (credit and debit), a 7.5% annual    growth in spending rates over May 2013, at a time where the    countrys economy is a long way from recovery.  <\/p>\n<p>    Its not surprising therefore that the payment card industry    attracts people of malicious intent.  <\/p>\n<p>    PCI-DSS Encryption RequirementsIn this reality, if    your business occupies any of the nodes in the payment card    supply chain, you must comply with the 12 core requirements of    PCI-DSS to keep perpetrators of payment card fraud at bay. You    will need to ensure you have the same levels of protection, and    thus of PCI-DSS compliance, in the cloud and in your data    centers. In addition, you must make sure that all third-party    service providers you use are fully PCI-compliant.  <\/p>\n<p>    Several of the 12 PCI-DSS requirements are relevant for cloud    security. However, on this occasion, well single out those    sections of requirement number 3, which relate specifically to    the protection of stored cardholder data. As youll see below,    you can comply with these requirements by using Porticors data    encryption and cloud key management system.  <\/p>\n<p>    PCI-DSS Encryption: Requirement 3Requirement 3.4,    for example, states that you must make sure that Primary    Account Numbers (PANs) are unreadable, wherever they are    stored. Our solution ensures your compliance here thanks to    strong hashing (SHA-2) and AES-256 encryption, augmented by    robust encryption key management.  <\/p>\n<p>    You must not tie decryption keys to user accounts, regardless    of whether you encrypt at the disk, file- or column-level of    the database, nor must you allow access to the cryptographic    key by native operating systems. Your compliance is assured on    both points with Porticors key management algorithm, which by    default splits the key. This keeps it independent of the OS, as    well as administrators and service providers in your supply    chain. In other words, access is limited to very few custodians    and, always acting together, rather than any one on their own,    ensures your compliance with requirements 3.5.1 and 3.5.2.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Continued here:<br \/>\n<a target=\"_blank\" href=\"http:\/\/linux.sys-con.com\/node\/3163800\/RK=0\/RS=kX3vF.6AEYhbTx1WZnPaeaqoQIg-\" title=\"@CloudExpo | PCI-DSS Encryption Requirements\">@CloudExpo | PCI-DSS Encryption Requirements<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Significant money is at stake and in need of protection in the Payment Card Industry (PCI). The global payment card industry covers several sectors: banks and financial institutions (acquirers), issuers, processors, service providers, merchants carrying out transactions online and via point of sale terminals in bricks and mortar stores, large and small. PCI SecurityThe PCI Security Organizations Data Security Standard (DSS) applies to your business if you store, process or transmit cardholder data (CHD)<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[],"class_list":["post-25868","post","type-post","status-publish","format-standard","hentry","category-encryption"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/25868"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=25868"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/25868\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=25868"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=25868"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=25868"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}