PCI Compliance in the Cloud

On this blog, the author posts a reply from Amazon about the level of PCI Security of EC2 and Amazone Web Services. 

As for PCI level 2 compliance, that requires external scanning via a 3rd party, PCI-approved vendor. It is possible for you to build a PCI level 2 compliant app in our AWS cloud using EC2 and S3, but you cannot achieve level 1 compliance. And you have to provide the appropriate encryption mechanisms and key management processes.

What strikes me as funny is that PCI Compliance is confusing enough without adding the cloud to it. Also, data security is almost a misnomer with the number of breaches that professional cyber-criminals perpetrate almost weekly. Cloud or no cloud, security is breached. 

I guess its like spam: we'll always have it. And unlike PGP encryption: hardly used at all.
The opinions and views expressed in comments, blogs, etc. are those of the authors alone and not necessarily those of TMC, TMCnet, or its editors. TMCnet reserves the right to edit, delete, or otherwise make changes to the content that appears on these pages at its own discretion and as it deems necessary.
| 1 Comment | 0 TrackBacks

Listed below are links to sites that reference PCI Compliance in the Cloud:

PCI Compliance in the Cloud TrackBack URL : http://blog.tmcnet.com/mt/mt-tb.cgi/40747

1 Comment

What some companies are doing now is proactively offering to pay for data breach fines should (when) a breach occur. Heartland and Mercury Systems just announced it in Security Management. Other companies are putting a breach mitigation plan in place before a breach occurs so they can quickly respond.

Leave a comment

Recent Comments

  • BethG: What some companies are doing now is proactively offering to read more

Subscribe to Blog

Blogroll

Recent Entry Images

  • one-on-one.jpg

Around TMCnet Blogs

Latest Whitepapers

TMCnet Videos