Log in or Register for enhanced features | Forgotten Password?
Software Systems & Networks Communications Services The CIO Agenda
Computer Business Review
CBR TV
Return to: CBR Home | News

Qualys service automates PCI DSS compliance validation

CBR Staff Writer Published 22 September 2009

Adds to on-demand approach and PCI partner ecosystem

Qualys Inc, a company that delivers vulnerability management and policy compliance applications as an on-demand software service, has come out with a way businesses can automate the validation processes needed for PCI DSS compliance.

The PCI DSS is a wide-ranging set of requirements intended to help retailers strengthen their payment account data security.

Developed by the likes of American Express, MasterCard and Visa Inc, the consistent data security measures needed for PCI DSS impacts on security management, policies, procedures, network architecture, software design and touches firewalls, cardholder data, encryption systems, anti-virus software and ID controls.

The cost of becoming PCI compliant depends on a number of factors including the business type, number of transactions processed and current credit/debit card processing and storage practices.

It can run into many hundreds of thousands, and in many cases can cost up to 40% more than estimated. Even the smaller so-called Level 3 merchants, processing between 20,000 and 1,000,000 e-commerce transactions a year, are expected to spend $44,000 assessing and $81,000 for compliance, Gartner has said.

Qualys claims its QualysGuard PCI on-demand platform provides businesses with one of the most cost-effective ways to validate PCI DSS compliance through automation.

Announcing QualysGuard PCI Version 4, it said the new system adds network discovery capabilities to help merchants define systems that are in scope for PCI.

It also introduces PCI Connect features that automatically connects merchants to multiple partners and security solutions in order to document and meet all 12 requirements for PCI DSS.

“PCI compliance status and tracking is performed on an ongoing basis. Merchants who use QualysGuard PCI Connect can easily identify areas where they may not be meeting compliance requirements,” the company said.

QualysGuard PCI Connect automates the collection of data for validations, provides results for all requirements of PCI throughout the organisation, and provides workflow for merchants to track compliance status on an ongoing basis, it added.

Technology partners that have so far participated in the PCI Connect ecosystem for PCI compliance include AirTight Networks, Core Security, Imperva, RedSeal Systems, Splunk and Third Brigade.


Comments
Post a comment

Comments may be moderated for spam, obscenities or defamation.