Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

StillSecure's PCI Compliant Managed Service: Page 3 of 3

StillSecure underwent a two-stage certification process, said Rick Dakin, Coalfire president and co-founder. First, Coalfire assessed the design of controls against the industry standards, reviewing the documentation and administrative controls in StillSecure's services and in their guidance to customers. Second, the actual controls were subjected to effectiveness testing to determine if the controls worked and met the PCI standard before Coalfire certified the services offerings.

During the assessment Dakin asked, "If StillSecure provides a control, is there evidence they meet the standard, and secondly if StillSecure did not provide a specific control, is there adequate guidance and instruction in the service offering to the customer to tell them what they need to put in place?"

That latter point--communicating the customer's responsibility to meet those PCI obligations that the provider's technology and processes do not--is crucial. "There are gaps in everybody's solutions," he said. "The difference is that there is specific notification to the users that they have responsibilities in the process."

PCI Complete will be available in October. There will be an initial provisioning fee to implement the service in addition to monthly charges, which will be based on the size of the cardholder environment, including number of devices and bandwidth.