Industry View
Industry View: Sharing the PCI Load
Kip Miles of Rackspace identifies two key PCI considerations for hosted services
By Kip Miles, Rackspace
In addition to helping carry part of the PCI responsibility, a hosted solution provider also has the ability to maintain a broad enough staff to ensure a consistent separation of duties for workers. Facilities managers might have access to the control of a data center but not the credit card data and vice versa. The data access should be controlled by a separate person who has access to the encryption keys.
The two categories of workers should be physically separated from the system so the employees who have access to the infrastructure can keep an independent log that is inaccessible to the workers who have access to the encryption keys.
Whether or not PCI compliance is something a CSO wants to manage in house is entirely based on their needs for a sense of control and availability of capital and IT resources. In the end it's a question of risk and capabilities.
Kiprian â¬SKip⬠Miles is VP, Information Technology for Rackspace.
$firstKeyword
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



