Credit card companies form security council

By Erica Ogg, CNET News.com
Friday, September 08, 2006 11:11 AM

The five major credit card companies have teamed up in the interest of better security.

American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa International announced Thursday the creation of an organization to develop and maintain security standards for credit and debit card payments. It's the first time the five brands have agreed on a single, common framework.

The newly formed Payment Card International (PCI) Security Standards Council will manage the PCI Data Security Standard, first established in January 2005 with the intention of making its implementation more efficient for all parties involved in a payment card transaction. That includes merchants, payment processors, point-of-sale vendors, financial institutions and more than a billion card holders worldwide.

The companies have come together despite being in competition with each other because they say ensuring better security will benefit everyone.

"First of all, it's to protect the information of our mutual customers and to make the process of data security compliance easier," said Rob Tourt, vice president of network services for Discover.

Having a single data security standard is a critical issue for the entire industry and will simplify the process, said Brian Buckley, Visa's senior vice president of international risk management.

"Our view is that this is first and foremost an important initiative to get data security in place for payment cards," he said.

Having the common accepted set of rules should foster broader compliance, said Bruce Rutherford, MasterCard's vice president of payments. Those rules include instructions on proper data encryption, common technical standards and security audit procedures.

The first action of the new council was to update the PCI security standard, which was promised in May. The revision gives instructions for how to implement the new standards and clarifies language that was previously considered vague. For example, terms such as "periodically" and "regularly" were swapped for definite deadlines like "annually" or "quarterly" where appropriate. A statement released by the newly formed council said the revisions were the result of feedback from vendors, merchants and payment processors.


See also:  Security
WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Developing peer-to-peer applications with Jabber

Web Development

Find out how to make use of the Extensible Messaging and Presence Protocol to P2P-enable your applications.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? Let Dr David Scott from Intel take you a for quick tour on developing HPC applications.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajen from Oracle highlights the important considerations ...
    Play video


  • HPC Architecture: Explained

    Why is High Performance Computing increasingly in demand in today's businesses? Find out which is the most widely deployed HPC architecture today.
    Play video

Tags

  1. apple
  2. attack
  3. attacks
  4. botnet
  5. credit
  6. data
  7. dns
  8. facebook
  9. fix
  10. flaw
  11. flaws
  12. fraud
  13. google
  14. iphone
  15. issues
  16. microsoft
  17. patch
  18. researcher
  19. researchers
  20. security
  21. sites
  22. spam
  23. storm
  24. symantec
  25. team
  26. uk
  27. us
  28. users
  29. warns
  30. worm

The business reality of being a S'pore gamer

Blog thumbnail

The Beijing Olympics came to a close last weekend, and Singapore spent much of this week celebrating the nation's lone medal--a silver piece from its women table tennis team. It's..... by Eileen Yu

Read more »