The PCI Security Standards Council, the body managing the Payment Card Industry data security initiative, on Wednesday announced that it will anoint a set of best practices developed by Visa as the new security standard for third-party application software in the payment industry.
The new standard is called the Payment Application Data Security Standard (PA-DSS) and is based on Visa's Payment Application Best Practices (PABP).
Over the next few months, the PCI Security Standards Council, together with participating organizations, security auditors, and vulnerability scanning vendors, will offer comments and suggestions relating to the PA-DSS.
The security council will then incorporate this feedback and publish a final version of the application security standards in the first quarter of 2008, said Bob Russo, general manager of the security standards council.
The application security standards are designed to address growing security concerns related to the third-party payment applications used by retailers and other companies accepting credit card transactions. Many of these applications are old and lack many of the security controls mandated by the credit card companies under the PCI data security standard.
For instance, older payment application software products are designed to capture and store certain kinds of cardholder data by default, even though the practice is explicitly banned under PCI guidelines. Similarly, older payment applications seldom have the transaction-logging capabilities that are required by PCI.
Visa, which has been by far the most aggressive of the credit card associations in pushing PCI, has for some time now tried to address such issues by leaning on software vendors to adopt its set of payment application best practices. Though Visa cannot contractually require the software vendors to adopt these best practices, it has been pressuring them into doing so anyway, by making it mandatory for merchants to use only PABP-compliant third-party payment software.
Just two weeks ago, for instance, it announced formal schedules for companies to ensure that all of their third-party payment applications are PABP-compliant.
With the moved announced yesterday, the PCI council has taken Visa's requirements and forged them into a broader industrywide mandate -- meaning that soon it won't be just Visa that's pressuring payment software vendors to adopt security controls, but MasterCard, Discover Financial Services, American Express Co. and JCB International Credit Card Co. as well.