Industry View

Industry View: Sharing the PCI Load

Kip Miles of Rackspace identifies two key PCI considerations for hosted services

By Kip Miles, Rackspace

Page 3

In addition to helping carry part of the PCI responsibility, a hosted solution provider also has the ability to maintain a broad enough staff to ensure a consistent separation of duties for workers. Facilities managers might have access to the control of a data center but not the credit card data and vice versa. The data access should be controlled by a separate person who has access to the encryption keys.

The two categories of workers should be physically separated from the system so the employees who have access to the infrastructure can keep an independent log that is inaccessible to the workers who have access to the encryption keys.

Whether or not PCI compliance is something a CSO wants to manage in house is entirely based on their needs for a sense of control and availability of capital and IT resources. In the end it's a question of risk and capabilities.

Kiprian â¬SKip⬝ Miles is VP, Information Technology for Rackspace.

$firstKeyword

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors