If your business accepts credit cards, whether over the internet or on paper, then PCI applies to your business. The general rule states that if you process, store or transmit cardholder data then you must adhere to the Payment Card Industry Data Security Standard v1.2 (PCI DSS v1.2) which prohibits maintaining credit card information in multi-tenant environments.
Depending on the number of transactions performed annually, Merchants and Service Providers must conduct quarterly vulnerability scans and either fill out a Self Assessment Questionnaire or have a Qualified Security Assessor audit the business entity against the PCI DSS.
Visit Visa’s website below to learn more about the various Merchant and Service Provider levels. http://usa.visa.com/merchants/risk_management/cisp_overview.html
Next, go to the PCI Security Standards Council website at: https://www.pcisecuritystandards.org/saq/instructions_dss.shtml#navigating
On this page you will find the self assessment questionnaires. There are five self assessment questionnaires on this page so make sure you determine which questionnaire applies to your business.
Contact your acquiring bank or payment processor to determine their expectations for your business.
If you choose not to comply with the PCI DSS then you risk:
Because Cloud Sites is a multi-tenant environment it is not PCI-compliant. A Cloud Site can be used as a flexible front-end to a payment gateway. For more information, see this article on utilizing Cloud Sites in an e-commerce solution.
© 2011-2013 Rackspace US, Inc.
Except where otherwise noted, content on this site is licensed under a Creative Commons Attribution-NonCommercial-NoDerivs 3.0 Unported License

8 Comments
PCI DSS Compliance
Thank you.
re: PCI compliance
Multi-tenant not a specific failure
Confused
http://www.visa.com/splisting/searchGrsp.do
and in 2009 news release, it says PCI-DSS Level 1 certified. What am I missing to understand?
http://www.rackspace.co.uk/media-centre/news/article/rackspace-enhances-security-with-pci-accreditation/
RackSpace Blog Claims PCI DSS Compliance?
PCI Compliance Clarification
Rackspace maintains two PCI compliance regimes.
1. The first is our merchant compliance that you see listed on the VISA site. This compliance allows us to process credit cards for our services, but does not have any impact on a customer's solutions being compliant.
2. The second is our Service Provider compliance. This allows us to present evidence that our customers can use to run PCI compliant solutions on our services. Currently, Rackspace offers Service Provider compliance for dedicated and RackConnect environments. We are in the process of expanding that coverage to our Public Cloud and Managed Virtualization offerings.
Rackspace offers various services through our partners in dedicated, public and private cloud offerings. You can review the Cloud Tools partners here (http://www.rackspace.com/cloud/tools/) for tools like CloudPassage that can be used to meet the File Integrity Monitoring (FIM) requirements in PCI, as well as many other tools for various security needs.
In the dedicated space, we offer products for intrusion detection (IDS/IPS), log management, vulnerability scanning, anti-virus, denial of service protection and many other needs. I would encourage you to contact your sales representative to get a complete list of the products that would be appropriate for your solution.
Hopefully this clears up some of the confusion. If you have any questions, feel free to contact me at jarret.raim@rackspace.com or your Rackspace rep through ticket, phone or chat.
PCI compliance for Merchants
Do the customers hosting thier ecommerce sites on dedicated servers with you are aslo required for PCI compliance for merchants??
New Cloud PCI Compliance Documents
Add new comment