IBM Announces Industry's First End-to-End Solution for PCI Compliance
Market Wire, November, 2007
IBM (NYSE: IBM) today announced a new program that provides products and services to help customers achieve compliance with the Payment Card Industry Data Security Standard (PCI DSS). Unlike competitive offerings, the comprehensive program is designed to take companies through the entire PCI compliance process, from assessment to compliance to certification, helping them meet all 12 PCI requirements for safeguarding customer payment card data.
PCI is a global standard that applies to any company that processes, transmits or stores credit card information. The standard was created by credit card companies to help organizations prevent security breaches. Any company that processes credit card data today could be threatened by cyber-crime attacks, resulting in customer identity theft. Those companies that do not achieve PCI compliance could have their ability to process credit cards revoked, or could face increased processing costs. Given the far-reaching impacts security threats can have on organizations, non-compliant companies risk significant financial and customer losses and damaging effects on brand reputation.
Hughes, the world's leading provider of broadband satellite networks and services, selected IBM to take its HughesNet® broadband network service through the PCI compliance process.
"As a leading managed services provider to major enterprises, Hughes strives to provide a wide range of services and applications to our customers," said Mike Cook, senior vice president, Hughes. "PCI DSS compliance is critical to our customers' operations, and it is imperative that the network services we provide meet those requirements. IBM's comprehensive program took us successfully through the entire process, from assessment through to certification."
Despite the threats of fines and a recent rash of high-profile data breaches, the rate of PCI compliance is estimated to be less than 50 percent. In fact, according to a report by industry analyst firm Gartner, Inc., Visa USA indicates that, as of July 2007, 39 percent of level-one merchants (defined as those that process more than 6 million transactions annually) and 33 percent of level-two merchants (defined as those that process between 1 million and 6 million transactions annually) are compliant with the PCI Data Security Standard.(1)
"As many merchants have learned in recent years, meeting some or even most of the mandated PCI requirements is no longer sufficient," said Kristin Lovejoy, director of strategy for Governance and Risk Management at IBM. "As a global leader in security technology and consulting services, IBM has the knowledge and expertise to provide a comprehensive solution for helping merchants comply with the PCI standard."
Only IBM Helps Organizations Address All 12 Requirements
The PCI Data Security Standard is a set of 12 requirements for safeguarding payment card data. These requirements range from installing and maintaining firewall configurations to encrypting transmission of cardholder data and maintaining proper policies and testing procedures.
To help customers meet all 12 of these requirements, the IBM PCI solution includes consulting services for compliance gap analysis, remediation, validation, ongoing testing and reporting, as well as a range of products that help organizations with each aspect of security planning, management and compliance reporting. For example, IBM can offer security process assessment, security information and event management, storage management, encryption, identity and access management, change and configuration management, intrusion prevention systems, application layer testing and user activity monitoring software. Additionally, IBM is one of only three companies in the world that is globally certified to perform PCI Assessments, PCI Quarterly Network Scanning, PCI Payment Application Assessments and PCI Incident Response Services.
IBM implements its PCI solution through a five-phase program that includes the following elements:
-- Assessment - This includes an overall "security health check" to
understand areas for remediation and how to become and remain compliant.
-- Design - This phase involves development of security strategy,
policies, standards and procedures, as well as incident response planning,
security architecture design and implementation planning.
-- Deployment - This phase focuses on implementation and optimization of
security software and hardware to help secure customer data, both in motion
and at rest, as well as on migration services and vulnerability
remediation.
-- Management - IBM provides ongoing support on this phase with security
monitoring and management software solutions, as well as staff augmentation
and emergency response, forensic analysis and threat-analysis services.
-- Education - IBM provides ongoing product courses, training and
security awareness programs so customers can appropriately train personnel
to maintain PCI compliance over the long term.
Most Recent Business Articles
- Multiple criteria evaluation and optimization of transportation systems
- Multi-criteria analysis procedure for sustainable mobility evaluation in urban areas
- A two-leveled multi-objective symbiotic evolutionary algorithm for the hub and spoke location problem
- Multi-criteria analysis for evaluating the impacts of intelligent speed adaptation
- The development of Taiwan arterial traffic-adaptive signal control system and its field test: a Taiwan experience
Most Recent Business Publications
Most Popular Business Articles
- 7 tips for effective listening: productive listening does not occur naturally. It requires hard work and practice - Back To Basics - effective listening is a crucial skill for internal auditors
- FAS 109: a primer for non-accountants - Financial Accounting Standards Board's "Statement 109: Accounting for Income Taxes"
- Design a commission plan that drives sales - Sales Commissions
- Too Young to Rent a Car? - 25-years-old the minimum age for car renting - Brief Article
- LIFO vs. FIFO: a return to the basics


