Payments News from Glenbrook Partners
Glenbrook   Book   Education   Jobs   Views   Archives   Store   Advertise   About         SUBSCRIBE:

IBM Announces End-to-End Solution for PCI Compliance

Tags » Data Security, PCI Compliance  » Comments (0)

IBM has announced "a new program that provides products and services to help customers achieve compliance with the Payment Card Industry Data Security Standard (PCI DSS). Unlike competitive offerings, the comprehensive program is designed to take companies through the entire PCI compliance process, from assessment to compliance to certification, helping them meet all 12 PCI requirements for safeguarding customer payment card data."

Hughes, the world's leading provider of broadband satellite networks and services, selected IBM to take its HughesNet® broadband network service through the PCI compliance process.

"As a leading managed services provider to major enterprises, Hughes strives to provide a wide range of services and applications to our customers," said Mike Cook, senior vice president, Hughes. "PCI DSS compliance is critical to our customers' operations, and it is imperative that the network services we provide meet those requirements. IBM's comprehensive program took us successfully through the entire process, from assessment through to certification."

"As many merchants have learned in recent years, meeting some or even most of the mandated PCI requirements is no longer sufficient," said Kristin Lovejoy, director of strategy for Governance and Risk Management at IBM. "As a global leader in security technology and consulting services, IBM has the knowledge and expertise to provide a comprehensive solution for helping merchants comply with the PCI standard."

The PCI Data Security Standard is a set of 12 requirements for safeguarding payment card data. These requirements range from installing and maintaining firewall configurations to encrypting transmission of cardholder data and maintaining proper policies and testing procedures.

To help customers meet all 12 of these requirements, the IBM PCI solution includes consulting services for compliance gap analysis, remediation, validation, ongoing testing and reporting, as well as a range of products that help organizations with each aspect of security planning, management and compliance reporting.

For example, IBM can offer security process assessment, security information and event management, storage management, encryption, identity and access management, change and configuration management, intrusion prevention systems, application layer testing and user activity monitoring software.

Additionally, IBM is one of only three companies in the world that is globally certified to perform PCI Assessments, PCI Quarterly Network Scanning, PCI Payment Application Assessments and PCI Incident Response Services.

IBM implements its PCI solution through a five-phase program that includes the following elements:

  • Assessment - This includes an overall "security health check" to understand areas for remediation and how to become and remain compliant.
  • Design - This phase involves development of security strategy, policies, standards and procedures, as well as incident response planning, security architecture design and implementation planning.
  • Deployment - This phase focuses on implementation and optimization of security software and hardware to help secure customer data, both in motion and at rest, as well as on migration services and vulnerability remediation.
  • Management - IBM provides ongoing support on this phase with security monitoring and management software solutions, as well as staff augmentation and emergency response, forensic analysis and threat-analysis services.
  • Education - IBM provides ongoing product courses, training and security awareness programs so customers can appropriately train personnel to maintain PCI compliance over the long term.

In addition to current product and service offerings, IBM is also adding specific PCI compliance capabilities to its IT Governance and Risk Management portfolio. For example, IBM Internet Security Systems recently upgraded the IBM Proventia Network Enterprise Scanner product with several PCI-specific vulnerability checks to simplify the process of performing network vulnerability assessments as part of a PCI compliance program. Additionally, the IBM Proventia Network Multifunction Security unified threat management solution alone addresses 10 of the 12 PCI security requirements in a single product.

For more information regarding IBM's PCI compliance offerings, please visit: http://www.ibm.com/security/pci.

Add your comment... (note that all comments are reviewed before they're published)

Feed You can follow this conversation by subscribing to the comment feed for this post.

If you have a TypeKey or TypePad account, please Sign In

Payments News on Facebook
Glenbrook Partners

PAYMENTS NEWS IS PRODUCED BY AND IS A SERVICE MARK OF GLENBROOK PARTNERS, LLC
ISSN 1556-4487

Glenbrook's Consulting Services

  • Innovation and Strategy
  • Payments Product Development
  • Payments Market Assessments
  • Payments Vendor Selection
  • Merchant Payments Optimization
  • Payments Risk Management
  •  
  • To discuss how Glenbrook can
    help you
    , email us:

Glenbrook's Payments Education

  • Payments Boot Camps
  • Payments Essentials Webinars
  • Private Payments Workshops
  •  
  •  
  •  
  •  
  • For more information on Glenbrook's payments education, email us:

Tools for Payments Professionals

  • Glenbrook Writings
  • Payments News
  • Payments Views
  • Payments Jobs
  • Payments Education
  • Payments Bookstore
  •  
  • To send us news that you'd like us to cover on Payments News, email us:

Contacts:                        
Compilation Copyright © 2002 - 2012 Glenbrook Partners LLC. All Rights Reserved.
Terms of Use        Privacy Policy        RSS Feed        Payments News RSS Feed

Subscribe to Payments News   

Follow Payments News on Twitter for Real-Time Updates