February 07, 2013, 8:22 PM — Cloud providers and cloud customers now have a roadmap that defines their security responsibilities in the cloud.
Since 2004, the PCI Security Standards Council (PCI SSC) has maintained the Payment Card Industry Data Security Standard (PCI DSS), a proprietary information security standard for the handling of payment card data.
Increasingly, organizations have taken the PCI standard as a guide for implementing security, even if they don't have responsibility for customer payment card data. But the question of whether and how PCI DSS covers cloud deployments has remained up in the air.
Today, the PCI SSC took a big step toward easing the confusion with the release of the PCI DSS Cloud Computing Guidelines Information Supplement, detailing what is required to secure customer payment data and support PCI DSS compliance in the cloud.
The organization says merchants that use or are considering using cloud technologies in their cardholder data environment will benefit from the guidance. PCI SSC says it also provides valuable guidance to third-party service providers that provide cloud services or products and to assessors reviewing cloud environments as part of a PCI DSS assessment.
"One of cloud computing's biggest strengths is its shared-responsibility model," says Chris Brenton, a PCI Cloud Special Interest Group (SIG) contributor and director of security for cloud server security platform provider CloudPassage.
"However, this shared model can magnify the difficulties of architecting a secure computing environment," Brenton says. "One of this supplement's greatest achievements is that it clearly defines the security responsibilities of the cloud provider and the cloud customer. With the PCI DSS as the foundation, this guidance provides an excellent roadmap to crafting a secure posture in both private and public cloud."
The new guidelines build on the work of the 2011 Virtualization SIG, but also draw from other industry standards. PCI SSC says it will help organizations with the following: