PCI Compliance In The Cloud
Written by Walter ConwayMarch 8th, 2011
Can a retailer (or even a service provider) move its payment applications to the cloud and maintain PCI compliance? PCI Columnist Walt Conway believes the answer to this question is yes, it is possible to be PCI compliant in the cloud. Neither validation nor compliance will necessarily be easy, and success is not guaranteed, but achieving both is possible. A better question, though, is how can a merchant implement a payment application in the cloud be both PCI compliant and secure?
Achieving PCI compliance in a cloud-based environment will involve some intense negotiations between the merchant and its cloud provider. If a merchant is neither willing nor able to dig into the details and maybe do a little arm wrestling with its provider, moving a payment application to the cloud is not for that merchant. Negotiating a detailed, comprehensive service level agreement (SLA) will be perhaps the most important single step to achieving PCI compliance in the cloud. But before you can even begin to develop an SLA, a merchant needs to understand who does what. That is, the first thing you need to know is which services will be provided by the cloud provider and which are the merchant's responsibility.
This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.
Already a Subscriber? Login Here
Pages: 1 2
3 Comments | Read PCI Compliance In The Cloud
Leave a Reply
Readers, specifically those who want to comment on a story:
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.

-Christine

March 14th, 2011 at 10:24 am
Payment risks and cloud service quirks certainly call for putting together an appropriate SLA. Many small businesses as well as merchants have similar risks when putting other sensitive financial or sales data in the cloud. Small businesses are especially vulnerable to these risks since they may not realize there are technology holes or just do not have the technical expertise or staff to develop or negotiate a SLA.
March 22nd, 2011 at 6:45 pm
Dear Walter,
I’m not a PCI specialist and (because of this?) wonder if there is – so far – a real interest to move such a critical application to the wild wide cloud? The cloud magic lies in its amazing efficiency thanks to massive and virtualized infrastructure and a high level of automation/orchestration. The level of complexity and trust required by PCI compliance will likely limit suppliers to very specialized one. Hence, the true added value would be this specialized knowledge rather than plain computing power and flexibility. A bit like renting a cheap car driven by a rock star. Am I missing a point?
All the best, Thierry.
March 25th, 2011 at 5:56 pm
Thanks for the comments!
Dr. P: I agree it can be difficult to put together an SLA even with a lot of resources. I am hoping to try and do a little bit more on that in an upcoming column.
Thierry: You asked if there is any real interest in moving a mission-critical application like payments to the cloud. I can tell you from first hand experience that there most definitely is such interest, and it is not just merchants, but their service providers, too. I’ll not comment specifically on your analogy (I’d get the cloud providers mad at me for saying they are like “cheap cars”…), but you raise the first half of what I think is the key issue: trust.
The other half? It is: verify. And this will not be easy.