We have relaunched: What's new at ZDNet Asia?

Card security rules hinder virtualization

Summary

Current guidelines for security card payment need updating as they conflict with virtualization practices and may hamper adoption of the technology, say industry experts.

Events

Microsoft MSDN/Developer Event
25 Mar 2010

One Marina Boulevard, Microsoft Singapore

IT Architect Regional Conference Singapore 2010
20 - 21 Apr 2010

Singapore Management University, Singapore

The Internet Show 2010
21-22 Apr 2010

Suntec Singapore

Current controls in the Payment Card Industry Data Security Standard (PCI DSS) are in conflict with virtualization practices and may hamper adoption of the technology, industry experts have warned.

Managed by the PCI Security Standards Council, the PCI DSS comprises a set of guidelines and controls to protect customer data, prevent fraud and eliminate security vulnerabilities. Organizations that handle payment data such as banks and retail merchants, are required to comply with the guidelines.

The policies are updated every two years with the next update scheduled for October 2010. The current version 1.2 took effect October 2008.

Jason Pearce, RSA's Asia-Pacific and Japan director of sales engineering, told ZDNet Asia the existing guidelines were established for traditional physical infrastructure and "do not provide adequate controls" for virtualized environments.

"As most organizations turn toward virtualization to optimize resource utilization and operational efficiencies, they are faced with the reality that while the PCI DSS is very detailed and specific, to date, it does not acknowledge or accommodate some of the unique challenges faced by an organization that chooses to deploy hardware or software virtualization technology within its PCI environment," the EMC executive explained in an e-mail. "In fact, some controls [outlined in the security standard] can be easily misinterpreted to mean that virtualization is incompatible with PCI DSS compliance.

"This is leading to confusion resulting in either failure to comply with the PCI DSS, or hesitation to deploy virtualization technology within PCI environments," Pearce said.

Patrick Chan, IDC Asia-Pacific's chief technology advisor for emerging technologies research, said in an e-mail interview the PCI DSS "definitely needs [an] update", as PCI compliance involving virtualized environments is currently reliant on "subjective guidance" of auditors.

According to Chan, one area within PCI DSS that conflicts with virtualization principles is 2.2.1, which mandates complying organizations to "implement only one primary function per server".

"This is an example [of a policy] that needs [to be addressed] in the next update, as hypervisor allows multiple systems to enjoy logical separation, even when they share the same underlying hardware," he pointed out in an e-mail interview. "Updates need to look into the logical layers as an additional layer of protection and security, rather than as a weakness."

"There are now emerging products that can help secure the entire perimeter of virtualized environments--to the extent of restricting certain protocols and types of traffics that traverse the different virtual machines," he said.

Lee Poh Wah, VMware's Asian South systems engineering manager, added that literally speaking, requirement 2.2.1 allows organizations to tap virtualization for consolidation of systems that perform the same function. However, the guidelines are not clear on whether a virtual machine (VM) is included in the definition of a server, Lee said in an e-mail.

"Without clear guidance from PCI DSS, it is up to each individual auditor to decide what satisfies PCI in their minds. This lack of consistency has made it very difficult for retailers to plan what to do," he noted. "Where we have seen success is when a customer proactively engages with their auditor ahead of time, so that they know what works and what will be frowned upon. Of course, you have to start with an auditor who is knowledgeable about virtualization, since most of them are not."

Virtualization catching on; update timely
Lee noted that "most" retail players are looking at virtualization as a means to optimize resource utilization and operational efficiencies. "Stores...can gain tremendous efficiencies from virtualization since there are often many computers at a store branch, each of which are often highly under-utilized," he said.

IDC's Chan added that among financial institutions, the majority of banks are "still hesitant to consolidate "heavy transactional front-end servers" but many are still studying how to gain benefits out of virtualization. Banks are already adopting client-side virtualization to optimize branch operational efficiencies and cost, he said.

Asia-Pacific organizations, in particular, would likely welcome or push for the PCI DSS guidelines to be revised more quickly, especially since server consolidation--according to an IDC study this year--was a major trend in the region.

RSA's Pearce said many organizations have become heavily dependent on virtual infrastructures, but are hesitant to deploy virtualization in areas that involve credit card data. "Because the PCI DSS standard hasn't included specific virtualization concerns, there have not been wider deployments," he said.

While the PCI DSS is not necessarily late incorporating virtualization guidelines, he acknowledged that "the time has come now where the market is demanding that these guidelines are included".

"The recent financial meltdown has caused many organizations to conserve tight IT budgets and deploy virtualization, and this has driven the [need for] an update in the PCI DSS standard to include this key technology," he said.

Pearce believes the update next year will address a number of key areas. For instance, the PCI Security Standards Council is likely to focus on the security of host servers as any VM containing credit card-related data would require its host server to be closely monitored. Custodians of the PCI DSS may also look into ensuring there are stringent security controls for clones and copies of virtualized servers, such as those used for disaster recovery, he added.

"The biggest challenge that will need to be addressed, and the one that will affect the merchants the most, will be whether or not virtualization provides adequate zoning and separation of functions," he noted. "That guideline should specify whether or not virtual servers are acceptable as long as they are only performing a single function."

According to Pearce, the workaround may be for a single hypervisor to only allow the PCI-compliant systems to handle data. "[This] would avoid the non-compliant state of having multiple classifications of data residing on the one storage medium", he explained.

"A current best practice is to not use virtual machines that run across multiple secure zones on the same host," he noted. "In the upcoming clarification document, it will also be important to monitor not just the VM workloads, but also the hypervisors. Comprehensive SIEM (security information and event management) monitoring offers reporting ability, which will certainly help toward demonstrating compliance."

He added that proper documentation, which will unlikely be covered in the update, should be included as a best practice.

"Good documentation can be used to prove there are sufficient controls in the virtualized environment, and this seems to be a common component of setups that have passed an audit," said Pearce. "The more documentation you can provide to a PCI Qualified Security Assessor, the better it will help them understand the security controls that have been deployed in your virtual environment."

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
Transform your business interactions with real-time voice, video and telepresence solutions.
Tech Vendor: Cisco

ZDNet Asia Live

RT @mistertechblog: I wrote about Nexus One and Touchdown, desktop dock, Bluetooth/USB tethering, ebooks here: http://bit.ly/bRdzx0

4 hours 55 minutes ago by yklee13 on topsy

Read my blog post on getting the most from your Nexus One: http://www.zdnetasia.com/blogs/m...

Data Centre Operator (Fresh Graduates Welcome to Apply) in ... http://bit.ly/bagYuu

5 hours 25 minutes ago by intmasterfeed on topsy

#Cisco #Cloud Cloud on ZDNet Asia: Aussie university joins Cisco cloud ยท Early-adopter criminals embrace cloud... http://bit.ly/d93C8S #TCN

6 hours 28 minutes ago by thetechgang on topsy

www.3w.com.au has seen it's outsourced IT Contracting Business in Manila grow at 4 times the rate of its traditional Australian Based...

13 hours 7 minutes ago by brucemills on Companies' outsourcing spend to increase

RT @3wconsulting: Whitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oY9f

Whitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oYbA

Whitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oYbz

Zdnetasia.com Estimated Worth $178,365 USD. Daily Ad Revenue:$244 USD, Daily Views:81,445 Pages... - http://www.haplog.com/www.zdneta...

recently estimated website net worth of zdnetasia.com - http://www.haplog.com/www.zdneta...

22 hours 59 minutes ago by haplog on topsy

When I create an event, I click on an approximate time during the day when I want the event to occur, then I click "edit event detail...

1 day 35 minutes ago by bessellbrowne on Google Calendar gets 'smart' rescheduling

ipads break alott i had one it broke three times in the month i had it so i got rid of the damn thing id just go for the laptop Top Grade...

1 day 37 minutes ago by bessellbrowne on Report: 'Hundreds of thousands' of iPad preorders

There are a number of websites that still require Internet Explorer to view and IE for Mac Stinks (it is really ies4osx which is the Wind...

1 day 39 minutes ago by bessellbrowne on Microsoft: Only minor tweaks in Windows 7 SP1

The receivers don't transmit back to the satellite. Unless there is a phone line attached to the receiver, they don't have any wa...

1 day 41 minutes ago by bessellbrowne on Apple to join the geolocation craze?

"Lead Cognos BI Developer Insurance - Jobs - ZDNet Asia" http://bit.ly/bRcxOG

1 day 36 minutes ago by rhrcognos on topsy

whatever little understanding I have we 'll only progress toward end of the world if we use HPCs to lenthen life of human being. Huma...

1 day 48 minutes ago by abhi32002@gmail.com on High computing promises elixir of life

Thanks for the knowledgeable article on SDDs. Allas...when all this reasearch will happen in Indian Universities. Hope the new bill on Fo...

2 days 1 minute ago by abhi32002@gmail.com on APAC HPC users eye solid-state drives

It was a good article. This brings a good opportunity for Indian IT firms to come up with new solutions in this field. HPC can become a b...

2 days 19 minutes ago by abhi32002@gmail.com on High computing most-wanted job in Asia

COL KR DHARMADHIKARY(RETD) its very late to reply the link, but if it is still alive and looking for opportunity, i would like to know th...

2 days 17 minutes ago by deb021280 on Education takes off in rural India, helped by PCs

It was just a matter of time until google was marginalised anyway. I'm afraid this will be forgotten in China very quickly. Still, it...

2 days 22 minutes ago by robinsmith on Report: Google to leave China on April 10

High performance computing (HPC) most-wanted job in Asia http://bit.ly/9vFC3i (via @zdnetasia) #singapore

He doesn't care if her shoes are of glass, All he wants to see is a huge rack and nice a*s. Sleeping beauty's not awoken by true ...

2 days 50 minutes ago by warlowdavies on One pair of 3D glasses to rule them all

RT @zdnetasia: EMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. (cont) http://tl.gd/i5jjd

EMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. http://bit.ly/9etOZW

Asian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08 via @zdnetasia

Asian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08

[TECH] URL Shorteners slow Web redirection. - http://bit.ly/bySnWK @zdnetasia

URL shorteners are great but they can slow web redirection & you pray it would never go down http://bit.ly/bySnWK via @zdnetasia

URL shorteners slow Web redirection. http://bit.ly/bySnWK

Chinese agencies cry foul over Google. http://bit.ly/by6rwV

all of sg's isps have been practising compulsory invisible proxy for all home subscribers at their backend since many years back alre...

3 days 298851 seconds ago by melvinchia on Web filters mean bad news for business

it is not to good for china.
Proactol

3 days 45 minutes ago by nathonastle on Chinese ad partners beg Google for information

Very good explanation of JMX

4 days 50 minutes ago by Babith B on Managing applications with JMX

The reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.

4 days 54 minutes ago by lonemavericks on diggs

Another ZTE story....

4 days 56 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G license