Upcoming Events

Cloud Connect
Santa Clara
Feb 13-16, 2012

Cloud Connect brings together the entire cloud eco-system to better understand the transformation we're experiencing and promises to be the defining event of the cloud computing industry. Learn about the latest cloud technologies and platforms from thought leaders in Cloud Connect’s comprehensive conference.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

Email Email  Print  Share


Visa Releases New Guidelines For Protecting Card Data

Tags: , , , ,

Channel: WAN Security

Visa has released guidelines on tokenization to help merchants and card processors better protect customer credit card data and potentially reduce the burden of complying with PCI rules. Tokenization transforms a credit card number into a random number that can be associated with the account number but can't be used for transactions. Merchants and retailers often have to store customer card data for functions such as customer refunds or voiding a purchase. By using tokens instead, merchants and retailers no longer have to store card data, reducing the risk of theft or exposure of their customers' account numbers.

The million dollar question is whether tokenization will make it easier to comply with the PCI Data Security Standards (PCI DSS). In theory it should, because the PCI rules only apply to networks and devices that store, process and transmit card account data. When properly implemented, tokens are not card data, so any system that uses tokens will likely fall outside the scope of the PCI rules. "A data warehouse that receives random tokens, and has no way to send tokens back across the firewall to redeem them as a credit card, that warehouse should be out of scope for an assessment," says Gary Palgon, vice president of product management at nuBridges, which sells encryption and tokenization software and services. Palgon is also a member of a scoping special interest group for the PCI Security Standards Council.

Of course, the PCI Security Standards Council will have the final say on whether and how tokenization will affect the scope of PCI. Bob Russo, general manager of the council, says it will release its own guidelines around tokenization after September of this year. Russo also notes that its guidelines will only be supplemental to PCI requirements, and not an official component of its standards. "A primary reason is that solutions such as tokenization minimize the value of data if compromised, whereas the PCI DSS standard is a set of criteria to protect cardholder data that has recognized value," says Russo.

In any case, tokenization can't happen overnight. Multiple parties, including merchants, the acquiring banks that accept card payments from merchants, and the card processors that manage the transactions between merchants and acquirers, all have to sign on to a tokenization system. There are also no industry standards around tokenization, including methods for generating tokens, which may make organizations reluctant to adopt a particular product. Of course, that hasn't stopped the market from moving forward. Several card processors offer tokenization, including Heartland Payment Systems, First Data and Merchant Warehouse. 

You can read Visa's guidelines on tokenization here. The guidelines are not yet official rules; the card brand is accepting feedback on its recommendations until August 31st. For more information on PCI and the potential impact of tokenization and other technologies, such as end to end encryption, check out a recent InformationWeek Analytics report here. Registration is required.

Related Stories

Related Reading


More wan-security Insights



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
 

WAN Security Reports

Research and Reports

Hypervisor Derby
August 2011

Network Computing: August 2011

TechWeb Careers