Q&A: No Alternative to PCI, Security Council Chief Insists

Robert Russo, the general manager of the Payment Card Industry Security Standards Council, fires back at critics of the PCI data security standard.

By Jaikumar Vijayan
Mon, June 29, 2009

Computerworld — As the general manager of the Payment Card Industry Security Standards Council,Robert Russohas borne the brunt of criticism about the PCI data security standard. Computerworld spoke with Russo last week as the council prepared to receive formal comments from industry stakeholders about the current version of the standard, which went into effect last fall. Russo stoutly defended the standard and said that despite questions about its effectiveness, there's no alternative when it comes to protecting payment card data.

A Guide to Practical PCI Compliance

What do you say to those who have said the PCI rules-making process is not as inclusive as it needs to be? The way it works is after we release a new standard, it stays out there for a approximately eight months and then a new comment period begins. All of our participating organizations, as well as all of the assessment community and approved software vendors and such will have the opportunity to give us formal feedback. We will ask them to tell us what their top five priorities are regarding the standard--what they would like to see addressed, what they'd like to see changed, what they'd like to see added or deleted. We take all of this information and we will digest that and put that in some form that can be distributed once again to the participating communities, saying: 'This is the result of everything we have gotten. And this is what we are proposing, based on what we heard should be in the newest version of the standard,' and then we will have another comment period. That information will be the basis for the new or evolved standard that will be released.

Representatives from seven trade groups sent you a letter earlier this month asking why the PCI standards development process can't be like the one used by the American National Standards Institute. What's your response? We are a global standard, so there are some issues...with just dealing with a standard that comes from one country or the other. As a matter of fact, when they published that letter, there was an article over in the U.K. saying, 'Hey this is a global standard. Why are you telling these guys to do something that is just U.S. centric?' We need to worry about stuff all over the world. That is specifically what we are doing at this point. Certainly, we look at all standards to see how we might be able to align our standards with those things. If there is a better way of doing it than the existing standards, we have no qualms about adopting it.

Continue Reading

As you know, everything is mobile, connected, interactive, and immediate. This is exactly why organizations need a highly agile IT infrastructure in order to keep pace with extreme fluctuations in business demand. This book will help you understand why infrastructure convergence has been widely accepted as the optimal approach for simplifying and accelerating your IT to deliver services at the speed of business while also shifting significantly more IT resources from operations to innovation.
For this white paper, IDC performed an in-depth analysis of the business value of VMware View, defined as the expected ROI associated with the use of the solution as a platform for the targeted deployment of a virtual desktop infrastructure.
This paper explains virtualization, its benefits for mid-sized business and how IBM's virtualization strategy can help these companies reduce costs, improve services and simplify management.
Forrester Research makes recommendations on best practices to optimize branch virtualization and consolidation initiatives. See how a "thin" branch architecture, with key servers, services and applications in the data center that relies on a high-performing WAN connection, can offer the greatest efficiencies.
When trying to achieve continuous compliance with internal policies and external regulations, organizations need to replace traditional processes with a new best practice approach and new innovative technology, such as that provided by IBM Tivoli Endpoint Manager.
IBM Tivoli Endpoint Manager helps organizations automatically manage patches for multiple operating systems and applications across hundreds of thousands of endpoints regardless of location, connection type or status.  
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as support considerations
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
Applications are changing - they're increasingly web-oriented, global in nature and run from multiple device types. Additionally, the volume of data is growing exponentially every year. How do you ensure your applications have fast, accurate, up-to-date information in this new world? Modern applications are data-intensive; delivering data the old way using monolithic databases isn't working. What's needed is a modern approach to data. One that scales-out as needed and delivers predictable high performance, but without sacrificing data consistency or integrity.
VMware View™ 5 simplifies IT management while increasing end user freedom by delivering desktop services from your cloud. Building upon VMware's leadership in desktop virtualization, VMware View 5 delivers a high-performance user experience while giving IT greater policy control.

View this webcast and find out how VMware View 5 can help you:
- Deliver the highest fidelity experience of desktop services across any device and any network
- Simplify and automate IT management, security and control of desktop services
- Reduce the costs associated with your desktop environment
IT professionals are being asked to deliver faster "time-to-value" than ever before. An IDG Research survey found that CIOs are eager to invest in technologies that will enable them to get new applications and services up quickly, achieving faster time-to-value.
Learn how to reduce IT management overhead, ease revision control, guarantee data security, scale systems more quickly and reduce server and software costs.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center