Qualys eases PCI compliance

Qualys tool should help firms meet the requirements of card payment rules

Written by Phil Muncaster

Vulnerability management specialist Qualys has launched a platform designed to help organisations that accept credit card transactions online comply with new Payment Card Industry (PCI) standards.

Recently in IT Week we reported the risks many firm face if they fail to comply with the standard, which focuses on the secure storage and processing of customers' card details.

The QualysGuard PCI On-Demand platform features an easy-to-use dashboard that helps to guide firms through all the processes they need to complete PCI certification, including the completion of a self-assessment questionnaire.

Qualys scanning technology is also built into the platform, enabling firms to locate and remediate vulnerabilities in accordance with PCI rules. Automated report preparation, meanwhile, eases the process of reporting compliance to the acquiring banks and leaves an audit trail enabling firms to show due diligence in the event of a data breach, explained Qualys chief marketing officer, Amer Deeba.

"We've tried to simplify and automate the compliance process, reducing costs and making it very easy for the end-user," he added. "It doesn't just impact retailers; anyone who accepts credit card transactions, such as hospitals, universities and local councils [are liable]."

Qualys is also offering banks a PCI dashboard to enable them to track the ongoing compliance status of online retailers and other organisations. Acquiring banks may have to cover the risks associated with data breaches if the merchants are unable to pay for card re-issuing and associated costs after a breach, according to Deeba.

Roy Harari of IT security consultancy Comsec Consulting said that in the past six months there has been a surge in interest in PCI. "The earliest versions were nice-to-haves but now [the PCI] has invested some effort in creating real best practices so the standard has pure security benefits as well as the incentive to firms of not being penalised [for non-compliance]," he added.

Tags:

reader comments

related articles

PCI Express 2.0 specs released

PCI Special Interest Group preps next-gen I/O standard 12 Oct 2006

 

UK firms face credit card security deadline

Firms handling credit card data must be compliant with PCI Data Security Standard 29 Sep 2006

Card standards ignored

The PCI Data Security Standard 1.1 came into effect in September, but are firms complying? 06 Nov 2006

Qualys offers compliance as a service

QualysGuard Policy Compliance delivers vulnerability scanning tools over the internet 21 Apr 2008

PCI council sets payment security standard

New rules on the storage of payment details 16 Apr 2008

Experts point out failings in WEEE scheme

UK exceeds IT kit disposal target but key procedures are not up to scratch 04 Jul 2008

related whitepapers

today's top stories

Computing launches all-new IT jobs site

Updated Computingcareers.co.uk provides enhanced feature for jobseekers 14 Oct 2008

Q&A: BT Business head of SaaS, Chris Lindsay

BT's head of software-as-a-service explains the benefits of the on-demand delivery model and how the current economic downturn could force firms to re-evaluate how they buy software 14 Oct 2008

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

Learning from the credit crunch to avoid a broadband crunch

While it might be the most pressing issue de jour , the financial system isn’t the only area where government needs to... 10 Oct 2008

How careerism can warp IT procurement

Many working in IT put their career interests before those of their employer when weighing up purchasing options 10 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job


IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Are you worried about your job prospects in IT over the next 12 months?

Are you worried about your job prospects in IT over the next 12 months?

Will the economic crisis affect your job prospects?

Previous poll results

Latest audio and video articles

Remote workerVideo

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Latest in-depth articles

BT TowerAnalysis

Q&A: BT Business head of SaaS, Chris Lindsay

BT's head of software-as-a-service explains the benefits of the on-demand delivery model and how the current economic downturn could force firms to re-evaluate how they buy software 14 Oct 2008

Financial Services Authority buildingAnalysis

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks 09 Oct 2008

Advertisement

Primary Navigation