home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers






Rushing Headlong After E-Commerce Gold: Is the Mine Safe?
December 15, 1998

E-commerce merchants need to ensure that encryption occurs in their credit-card transactions with the consumer, as well as in any back-end transactions that forward credit-card information to banks or directly to the merchant (since the bulk of online orders are still processed manually or re-entered at the merchant's location).

Credit-card information also needs to be secured if it is stored on the CSP's server; many security experts recommend using a dedicated black box. Given that internal theft is more prevalent than over-the-wire theft, credit-card information tends to be most vulnerable right at the server. For this reason, it makes sense to restrict physical access to such servers--for example, placing them in a locked room with controlled access, or at least running automatic audits of server maintenance changes as a deterrent to internal theft. Ideally, credit-card numbers would be treated with the same level of care as passwords--always encrypted and never stored in the clear. But few CSPs seem to take such measures. On the contrary, many CSPs--if not most--run commerce servers that contain credit-card information alongside other equipment without adding any other physical security.

Exodus, on the other hand, is a co-location service provider (leaving the task of developing and maintaining commerce applications to customers and select partners) that prides itself on offering one-of-a-kind security. Exodus is upgrading its aluminum vaults to provide 3.5-inch, steel-lined, hermetically sealed, 8-x-12-foot vaults at each of its eight hosting facilities. The existing vaults, which can be used by a merchant for a fee of $12,500 a month each, include a fire-suppression system, motion and heat detectors, redundant power, a dedicated camera, biometric handprint scanners capable of discerning a live hand, locked-down floor tiles, a metal conduit for wiring and a "faraday cage-like" effect to attenuate radio frequencies or electromagnetic pulses.

One of Exodus' first vault customers is NextCard Visa, which is one of the largest distributors of Visa credit cards online.

You won't find anything like this, however, at most CSPs. "There is no question that in the rush to throw something together [to cash in on the e-commerce frenzy], security has gotten lost in the shuffle," says Forrester's Julian. "There are certain things that are fundamental and inexcusable, though--like not securing the servers and failure to use encryption."

Send your comments about our special report on e-commerce to Christy Hudgins-Bonafield at cbonafield@ nwc.com.


Print This Page


e-mail E-mail this URL





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights