The PCI SSC quotes results from the Trustwave 2012 Global Security Report which states thatย 76% of the breaches they investigated were a result of security vulnerabilities introduced by a third party responsible for system support, development and/or maintenance of business environments.

Errors introduced during implementation, configuration and support of PA-DSSย validated payment applications by third parties into merchant environments was identifiedย as a significant risk to the security of cardholder data. Specifically, small businesses in the food and beverage industry that rely heavily on outsourcing are particularly vulnerable, as they made up the bulk of the compromises.

To help address this security challenge, merchants, acquirers, payment software vendors and card brands participated in a Council taskforceย to evaluateย market needs and make recommendations on how to address them. This included development of more guidance and best practices for integrators and resellers and a global list of PCI Council certified integrators and resellers.

The Qualified Integrators & Resellers (QIR)ย program will provideย integrators and resellers that sell, install and/or service payment applications on behalf ofย software vendors or others the opportunity to receive specialized training and certification on the secure installation and maintenance of validated payment applications into merchant environments in a mannerย that supports PCI DSS compliance. The PCI SSC will maintainย a global list of QIRs, ensuring merchants a trusted resource for selecting PCI approved partners. The PCI SSC will be offering training online in late summer 2012, and the validated list for merchants will be publishedย on the PCI SSC website shortly thereafter. More details on the program, including eligibility requirements and training course information and costs will be made available soon. In the meantime, those interested in participating in the program can click hereย or emailย questions to qir@pcisecuritystandards.org.

โ€œProduct solutions that are a good fit for a PCI compliant organization need to be installed, configured, and managed properly to support PCI DSS,โ€ said Diana Kelley, principal analyst at security IT research firm SecurityCurve.ย โ€œIntegrators and resellers need to understand what makes a solutionย effective for protecting cardholder data and the cardholder data environment in order toย provide the most value to their customers. That’s why I think the new integrator and reseller certification and training for 2012 is a welcome addition to the Council’s comprehensive training offerings.โ€

โ€œThis program comes as a direct result of industry feedback and stakeholder requests for greater quality assurance and accountability around the secure installation of payment software,โ€ said Bob Russo, general manager, PCI Security Standards Council. โ€œNot only will it help integrators and resellers better understand how to addressย some of the basic security flaws weโ€™re seeing that can beย easily avoided, but it will also make it easier for merchants to have confidence in the services being provided to them. Retailers and franchise operators alike will have a go-to resource they can trust for making sure their applications and systems are being installed and maintained properly.โ€

Reproduced from the PCI SSC Press Release.

.


One response to “PCI Security Standards Council announces qualified integrators and resellers certification program”

  1. php outsourcing Avatar

    I hardly leave a response, however i did some searching and wound up
    here PCI Security Standards Council announces qualified integrators and resellers certification program | Brian Pennington.
    And I do have a couple of questions for you
    if it’s allright. Is it only me or does it seem like some of these remarks look as if they are
    left by brain dead people? ๐Ÿ˜› And, if you
    are writing on additional social sites, I would like to keep up with everything fresh
    you have to post. Would you list of the complete urls of all your shared sites like your linkedin profile, Facebook page or twitter feed?

    Like

Leave a comment