Modulo Launches Knowledge Base to Automate Compliance with PCI 1.1


Noncompliance With PCI DSS Can Result in Termination of Credit/Debit Card Affiliated Companies

NEW YORK, Jan. 18 / -- Modulo Security, specialized in technology for Risk Management, is launching a new knowledge base in Risk Manager(TM), its compliance, risk and knowledge management software application. Developed for organizations that accept credit and debit cards as a form of payment, this new knowledge base will help companies comply with the requirements set forth in the PCI-DSS. PCI-DSS guidelines were developed jointly by credit/debit card carriers, including Visa, MasterCard and American Express.

The PCI-DSS establishes security guidelines for organizations affiliated with credit/debit card companies, such as processors, payment gateways, and, soon, issuing banks. These requirements vary according to number of transactions performed by the commercial organization and aim to reduce the incidence of fraud involving credit cards.

The new PCI 1.1 knowledge base uses the newest version of PCI-DSS, approved in September 2006. It became effective in the United States as of January 2007 and helps companies guarantee compliance with best practices for handling, transmission, and storage. In addition, this new knowledge base will allow commercial organizations to better manage their risks, prioritizing actions to be implemented.

Impact on the Audits

The PCI standard has controls pertaining to network protection, data encryption, physical and logical access control, monitoring of activities, and others. Some of these controls stand out from the rest. These include those defining procedures for protecting information such as identifiers or passwords in various environments, physical stores and web-based applications in e-commerce.

"A case of fraud or security breach in any company which is not compliant with the standard set by PCI may cause the company to face heavy fines," says Alan Mattson, VP of Business Development at Modulo Security. "The foundation of the PCI Security Standard Council and the creation of the PCI Data Security Standard were fundamental and very positive initiatives. After a five-year period, during which companies doing credit card business will have adopted this standard, we should see a reduction in the amount of fraud, which should strengthen e-commerce a great deal. Our solution, Risk Manager(TM), will reduce substantially the time spent on audits and will allow companies to prioritize mitigation and track security improvements throughout the process," concludes Mattson.

Among businesses that will undergo this type of audit are retail networks and fast-food chains, aviation companies, large e-commerce organizations and telephone-based businesses.

"Companies are not currently required -- but they are encouraged -- to use online payment applications that are compatible with the PCI standard," says Mattson. "I believe that this use will proliferate in the coming years, and will be used as a competitive advantage among companies. After all, everyone wants to have safe shopping."

PCI-DSS Compensating Controls

On December 14, 2006, Modulo presented at the "PCI DSS 1.1 Compensating Controls Risk Analysis Best Practices Webinar," hosted by Protegrity, to show how Risk Manager(TM) can assist companies using credit and debit cards to guarantee adherence to best PCI-DSS practices.

To learn more about the presentation, please access http://www.modulo.com/

RSA Conference 2007

Modulo will be presenting Risk Manager's new Compliance facility (for FISMA, PCI-DSS, ISO 17799, COBIT and SOX) at a press conference during the RSA Security Conference in San Francisco the week of February 5th. This annual event brings together information security companies from the USA, Europe, and Japan.

The Modulo press conference is scheduled for February 6 at 2 PM in the event press area (Moscone North, room 120, 121 and 122). If you are a journalist and would like to take part in the press conference, please confirm your attendance by email with Charlie Warhaftig (cwarhaftig@modulo.com) or by phone (212 922-1789).

More information:

Charlie Warhaftig
Director
(212) 922-1789
cwarhaftig@modulo.com

Source: Modulo Security

Web site: http://www.modulo.com/

All Topics