PCI DSS is the security standard developed by American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa Inc. to provide fraud protection to their cardholders. Any organization that processes, stores or transmits cardholder data is required to comply with these security standards. To achieve compliance, a service provider must go through a thorough annual assessment.
Ilya Gutlin, SITA Vice-President for Airport Services, said: “SITA is meeting the increasing requirements of the air transport community as it brings common-use passenger processing environments to a more efficient and secure level. It is another milestone in our long history of community leadership as we continue to partner with airports and airlines to meet the evolving needs for common-use systems. SITA is now the first, and only, service provider to receive certification to the PCI DSS for a common-use platform, and be recognized by Visa as a PCI Compliant Service Provider.”
Airlines are offering more and more services that require payment from passengers at the airport including baggage fees, same-day upgrades, priority seating and lounge access. Wherever a card is swiped – at an agent’s desk or at a self-service kiosk – they must ensure that this action is in line with the payment card industry’s security standards and that their system suppliers are PCI Compliant.
Gutlin added: “Airports are ultimately responsible for their annual PCI compliance assessment across all areas and so they will need to add PCI compliancy as a required specification for all future system installations. But knowing part of the environment, namely their passenger processing provided and managed by SITA, is already compliant will make the airport's PCI assessment easier.”
Aleks Popovich, Senior Vice President of Industry Distribution and Financial Services at IATA, said: “IATA is working closely with its member airlines to support PCI DSS compliance in industry distribution channels, such as the Billing and Settlement Plan (BSP) and other shared infrastructure.
“Compliance to PCI DSS is mandated by the international card payment schemes but it is also sound business practice. It protects clients, avoids card fraud, and lowers the risk of fines and fees.”
SITA places the highest of priorities on maintaining the appropriate levels of security and data protection throughout its operations. SITA has an enterprise-level PCI Compliance initiative to address the company’s compliance obligations, and has staff fully trained in the adherence of PCI DSS. The organization is involved in the evolution of the PCI security standards through its membership of the PCI Standards Security Council (SSC) and a variety of air transport industry working groups, including IATA and Airports Council International.
SITA’s AirportConnect Open is used by more than 300 airlines to process millions of passengers every day in more than 400 airports around the world. It is a proven, stable platform that continues to meet evolving technology advancements and standards. SITA is now the only service provider of a fully-integrated common-use platform and managed services, supporting workstations and CUSS kiosk applications that is compliant with the latest security standard PCI DSS Version 2.0.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
How To Boost Security Via FFIEC Compliance
With just a smartphone, users can conduct nearly all their banking business at any time of the day or night. However, all this flexibility and convenience opens up new avenues for fraud and cybercrime. Guidelines laid out by the FFIEC several years ago predate many of the capabilities-and vulnerabilities-that are in place today. In this report, we examine the latest guidelines and provide advice on how you can extend the work done to comply with FFIEC guidelines to strengthen your organization's overall security posture and keep customers and their data safe.
Keeping Compliance In Check
Configuration mistakes, access control gaffes, poor documentation--it doesn?t take much for a compliance audit to go all wrong. In this special retrospective of recent news coverage, Dark Reading takes a look at the costs, common missteps and best practices for compliance, as well as the day the Internet nearly went dark due to the threat of new regulations.
FISMA Lifts All Compliance Boats
FISMA may not be on your radar now, but it likely will be at some point. Geared specifically toward the federal government and its affiliate agencies and third parties, FISMA is a very specific set of requirements aimed at establishing and maintaining at least a baseline level of computer and network security. FISMA requires unique categorization and classification of information assets, not to mention a boatload of documentation to prove compliance. But once your organization achieves FISMA compliance, it will likely be compliant with just about every security mandate out there.
Other reports from the Compliance Tech Center:
| Sponsored by: |
Log Management in 2012 and Beyond
2012 brings interesting changes to the log management world. Now, more than ever, it is critical to understand the impact to your log infrastructure and the solutions that will better prepare you to manage your security posture.
SANS Log Management Survey Report
Organizations are increasingly dependent on log management to support core business functions, including cost management, service level and line-of-business application monitoring, as well as traditional IT- and security-focused activities.
Cut the Time and Effort of Troubleshooting and Reporting
Organizations generate millions of logs a day and struggle with centralized collection, storage and analysis of those logs. ArcSight Logger is a universal log management solution that unifies searching, reporting, alerting and analysis across any type of IT data. It consolidates silos of logs into a single indexed repository for fast detection and mitigation of operational issues.
Get Turnkey and Automated PCI Compliance
PCI compliance monitoring is seamless with the self-contained ArcSight PCI Logger solution for log collection, storage and analysis. No database administration expertise is required and a web-based interface simplifies deployment and ongoing management.
Swiss Bank Meets Compliance Requirements and Protects Customer Data
Due to long-term data retention requirements, Swiss bank EFG needed a cost-effective way to collect, secure and store audit-quality log data in an easily accessible log repository. ArcSight Logger helps EFG meet key requirements of Switzerland?s banking laws fast and cost-effectively.
MORE NEWSFEED >>>