","showSummary":null,"url":"/pci-security-council-publishes-cloud-and-virtualization-guidelines","date":"2011-06-14T00:00:00","author":{"email":"devteam@ashday.com","uname":"ash_root","firstName":null,"lastName":null,"bio":null,"title":null,"picture":null,"phone":null,"contactForm":null},"byline":" ","hideByline":null,"digitalEdition":null,"sponsored":false,"sponsorship":{"overrideAds":null},"taggedPro":null,"relatedArticles":[],"teaserImage":{"id":43529,"url":"https://assets1.risnews.com/styles/secondary_articles_short/s3/DataSecurity_RIS_9-7-10_4.jpg?itok=ypdZrv0n","width":150,"height":150,"alt":null},"heroImageSrcset":null,"hideHero":null,"heroImage":null,"heroCaption":null,"attachedFiles":[],"businessTopic":[],"contentType":[],"company":[],"marketSegment":[],"topics":[{"id":107,"name":"Cloud Computing","url":"/cloud-computing"},{"id":126,"name":"Security","url":"/security"},{"id":30,"name":"Social Networking","url":"/social-networking"},{"id":13,"name":"Point of Sale","url":"/point-sale"},{"id":67,"name":"Virtual Reality","url":"/virtual-reality"}],"contentParagraphs":{"isGated":false,"gateType":null,"gateText":null,"paragraphs":[{"id":4052,"bundle":"basic","text":"Fast-rising interest in virtualization and cloud computing has been accompanied by concerns about potential data security risks from using these IT models. Seeking to address some of these concerns, the PCI Security Standards Council has released its Virtualization Guidelines Information Supplement for retailers, merchants and others in the payment chain, providing information on the use of virtualization technology in cardholder data environments in accordance with PCI DSS (Data Security Standards). \r\n \r\nThe guidelines document was produced by the Virtualization Special Interest Group chaired by Kurt Roemer, chief security strategist at Citrix Systems, and more than 30 participating organizations and it includes: \r\n \r\n· Explanations of the classes of virtualization often seen in payment environments including virtualized operating systems, hardware/platforms and networks \r\n· Definition of the system components constituting these types of virtual systems and high-level PCI DSS scoping guidance for each \r\n· Practical methods and concepts for deployment of virtualization in payment card environments \r\n· Suggested controls and best practices for meeting PCI DSS requirements in virtual environments \r\n· Specific recommendations for mixed-mode and cloud computing environments \r\n· Guidance for understanding and assessing risk in virtual environments \r\n \r\n\"This information supplement provides a more detailed view into the definitions and boundaries where PCI intersects with virtualization,\" said Roemer. \"Now merchants can identify the range of questions to ask their providers and then determine the risk mitigation options available.\" \r\n \r\nMore information can be found at www.pcisecuritystandards.org "}]}};
const country = "US";
const language = "en-US,en;q=0.5";
const SITE_LANGUAGE = "en";
const siteName = "RIS News";
const userRoles = ["anonymous"];
const userUid = 0;
const indexName = "risnews";
window.dataLayer = window.dataLayer || [];
const data = {};
data.entityTaxonomy = {};
const contentTypes = [
"article",
"blog",
"bulletin",
"embed_page",
"landing_page",
"event",
"image",
"page",
"product",
"whitepaper",
"video",
"tags",
];
if (
routeInfo &&
"bundle" in routeInfo &&
contentTypes.includes(routeInfo["bundle"])
) {
data.entityBundle = routeInfo.bundle;
data.entityTitle = `${routeInfo.title} | ${siteName}`;
data.entityId = routeInfo.id;
data.entityName = routeInfo.author?.uname;
data.entityCreated = routeInfo.created;
data.sponsored = routeInfo.sponsored;
data.sponsor = routeInfo.sponsoringCompany;
data.entityType = "node";
data.entityLangcode = SITE_LANGUAGE;
data.siteName = siteName;
data.drupalLanguage = language;
data.drupalCountry = country;
data.userRoles = userRoles;
data.userUid = userUid;
data.entityTaxonomyKeys = {};
data.entityTaxonomyHierarchies = {};
data.parentNaicsCode = {};
data.isPro = false;
data.algoliaIndexName = indexName;
// Add toxonomy data
const taxonomies = {
businessTopic: "business_topic",
contentType: "content_type",
company: "company",
marketSegment: "market_segment",
};
const getHierarchy = (term, terms = []) => {
terms.push({ id: term.id, name: term.name });
if (term.parentTerm != null) {
getHierarchy(term.parentTerm, terms);
}
return terms;
};
const getTerms = (term, useApiId = false) => {
return { id: useApiId ? term.apiId : term.id, name: term.name };
};
const getKeys = (term) => {
return { id: term.id, name: term.apiId };
};
Object.entries(taxonomies).forEach(([key, item]) => {
terms = routeInfo[key];
if (terms && terms.length > 0) {
data["entityTaxonomy"][item] = terms.map((term) =>
getTerms(term, key === "company")
);
if (key !== "company") {
data["entityTaxonomyKeys"][item] = terms.map(getKeys);
termGroups = [];
terms.forEach((term, termInd) => {
termGroups[termInd] = getHierarchy(term);
});
data["entityTaxonomyHierarchies"][item] = termGroups;
}
}
});
data["entityTaxonomy"]["tags"] = routeInfo["topics"] || [];
// Primary Topic is either the business topic or the top tag.
if (routeInfo["businessTopic"]?.length > 0) {
data["entityPrimaryTopic"] = routeInfo["businessTopic"][0]["name"];
} else {
if (routeInfo["topics"]?.length > 0) {
data["entityPrimaryTopic"] = routeInfo["topics"][0]["name"];
}
}
// Primary and secondary entityNaicsCodes come from the MarketSegment
if (routeInfo.marketSegment?.length > 0) {
data.entityNaicsCode = {};
data["entityNaicsCode"]["id"] = routeInfo["marketSegment"][0]["id"];
data["entityNaicsCode"]["name"] =
routeInfo["marketSegment"][0]["naicsCode"];
if (routeInfo["marketSegment"][0]["parentTerm"] != null) {
data["parentNaicsCode"]["id"] =
routeInfo["marketSegment"][0]["parentTerm"]["id"];
data["parentNaicsCode"]["name"] =
routeInfo["marketSegment"][0]["parentTerm"]["naicsCode"];
}
} else {
data.entityNaicsCode = [];
}
if (routeInfo.taggedPro) {
data.isPro = routeInfo.taggedPro;
}
window.dataLayer.push(data);
} else if (routeInfo && "vid" in routeInfo) {
data.entityBundle = "tags";
data.entityTitle = routeInfo.name;
data.entityId = routeInfo.id;
data.entityName = routeInfo.author?.uname;
data.entityCreated = routeInfo.created;
data.entityType = "taxonomy_term";
data.entityLangcode = SITE_LANGUAGE;
data.siteName = siteName;
data.sponsored = routeInfo.sponsored;
data.sponsor = routeInfo.sponsoringCompany;
data.drupalLanguage = language;
data.drupalCountry = country;
data.userRoles = userRoles;
data.userUid = userUid;
data.algoliaIndexName = indexName;
data["entityTaxonomy"]["tags"] = {
id: routeInfo["id"],
name: routeInfo["name"],
};
window.dataLayer.push(data);
}
})();
PCI Security Council Publishes Cloud and Virtualization Guidelines
PCI Security Council Publishes Cloud and Virtualization Guidelines
6/14/2011
Fast-rising interest in virtualization and cloud computing has been accompanied by concerns about potential data security risks from using these IT models. Seeking to address some of these concerns, the PCI Security Standards Council has released its Virtualization Guidelines Information Supplement for retailers, merchants and others in the payment chain, providing information on the use of virtualization technology in cardholder data environments in accordance with PCI DSS (Data Security Standards).
The guidelines document was produced by the Virtualization Special Interest Group chaired by Kurt Roemer, chief security strategist at Citrix Systems, and more than 30 participating organizations and it includes:
· Explanations of the classes of virtualization often seen in payment environments including virtualized operating systems, hardware/platforms and networks · Definition of the system components constituting these types of virtual systems and high-level PCI DSS scoping guidance for each · Practical methods and concepts for deployment of virtualization in payment card environments · Suggested controls and best practices for meeting PCI DSS requirements in virtual environments · Specific recommendations for mixed-mode and cloud computing environments · Guidance for understanding and assessing risk in virtual environments
"This information supplement provides a more detailed view into the definitions and boundaries where PCI intersects with virtualization," said Roemer. "Now merchants can identify the range of questions to ask their providers and then determine the risk mitigation options available."