
{"id":1699,"date":"2011-12-12T00:00:00","date_gmt":"2011-12-12T00:00:00","guid":{"rendered":"http:\/\/otava.test\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/"},"modified":"2025-05-28T21:09:27","modified_gmt":"2025-05-28T21:09:27","slug":"risk-assessments-to-achieve-pci-compliance-in-the-cloud","status":"publish","type":"post","link":"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/","title":{"rendered":"Risk Assessments to Achieve PCI Compliance in the Cloud"},"content":{"rendered":"\n<p>One of the main concerns with <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud\/\">cloud computing<\/a> is security &#8211; when it comes to national industry security compliance standards such as PCI DSS or <a href=\"https:\/\/otavawebsite.wpengine.com\/compliance-security\/hipaa-compliant-cloud\/\">HIPAA<\/a>, additional precautions must be taken in order to protect confidential data during transmission. While PCI compliance calls for very specific requirements to protect customer cardholder data, it is possible to remain compliant while using the cloud.<\/p>\n\n\n\n<p>The PCI Security Council (PCI SSC) recently <a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/pci-compliance-and-virtualization-new-recommendations\/\">released<\/a> a set of guidelines and recommendations on configuring virtualized environments to meet PCI requirements in June. The council acknowledges there is no one-size-fits-all hosting solution that allows all businesses to meet the PCI requirements, but they do address potential new risks that may be associated with virtualization technology.<\/p>\n\n\n\n<p>According to Onestopclick.com\u2019s article on <em>PCI Compliance and the Public Cloud<\/em>, some experts suggest using a separate secure server for transactions while using a cloud platform for other business operations. However, the PCI SSC suggests some public clouds have certain characteristics that may introduce challenges in defining scope and responsibilities when it comes to meeting PCI compliance, including the fact that the hosted entity may have limited knowledge of other tenants in their hosted environment and limited control over CHD storage. In a <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud\/private-cloud\/\">private cloud<\/a>, dedicated hardware provides more security and control by allowing the tenant to know where their data lives.<\/p>\n\n\n\n<p>As a result, the PCI SSC states the burden of PCI compliance falls upon the cloud provider and their own controls and assessment of their own environment\u2019s compliance. When searching for a <a href=\"https:\/\/otavawebsite.wpengine.com\/compliance-security\/pci-compliant-cloud\/\">PCI compliant hosting<\/a> provider and solution, merchants should review which controls are in place to meet the requirements, what is included in the scope of their assessment and details of what is not covered, and what is ultimately the merchant\u2019s own responsibility.<\/p>\n\n\n\n<p>The PCI SSC also recommends conducting a <strong>risk assessment<\/strong> of their virtual environments to comply with PCI standards, including the following key elements:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Define the Environment<\/strong><br>Components, physical security\/site details, traffic flow, component visibility, virtual and physical hardware components, etc.<\/li>\n\n\n\n<li><strong>Identify Threats<\/strong><br>One example is new types of malicious code or logical attacks targeting virtual components (hypervisor) or unsecured communication channels between shared hardware components.<\/li>\n\n\n\n<li><strong>Identify Vulnerabilities<\/strong><br>While the PCI SSC acknowledges vulnerabilities may result from the complexity of virtualization layers, shared environments and lack of visibility, they also point out that vulnerabilities are not limited to technical issues &#8211; mistrained staff, operational processes errors, lack of control monitoring and more can be responsible for a point of weakness.<\/li>\n\n\n\n<li><strong>Evaluate and Address Risk<\/strong><br>With all threats, vulnerabilities and environmental aspects considered, a risk assessment\u2019s ultimate goal is to determine if any additional controls (on top of existing PCI compliance requirements) need to be implemented to protect CHD and avoid a PCI compliance breach.<\/li>\n<\/ul>\n\n\n\n<p>For more on PCI compliance, see our prerecorded <a href=\"https:\/\/www.onlinetech.com\/resources\/news-a-events\/events\/webinars\/pci-webinar-series\">PCI compliance webinar series<\/a>, including a <a href=\"https:\/\/www.onlinetech.com\/resources\/news-a-events\/events\/webinars\/pci-webinar-series\/item\/223\">PCI overview<\/a>, <a href=\"https:\/\/www.onlinetech.com\/resources\/news-a-events\/events\/webinars\/pci-webinar-series\/item\/224\">detailed PCI requirements<\/a> and <a href=\"https:\/\/www.onlinetech.com\/resources\/news-a-events\/events\/webinars\/item\/225-pci-compliance-penetration-testing-and-enhancing-security-for-network-and-applications\">PCI penetration testing<\/a> and enhancing network and application security, led by a PCI compliance expert, Adam Goslin of High Bit Security.<\/p>\n\n\n\n<p>Sources:<br><a href=\"https:\/\/security.onestopclick.com\/topic\/193\/512\/pci-compliance-and-the-public-cloud.html\">PCI Compliance and the Public Cloud<\/a><br><a href=\"https:\/\/www.pcisecuritystandards.org\/documents\/Rth87Wp\/Virtualization_InfoSupp_v2.pdf\">Information Supplement: PCI DSS Virtualization Guidelines<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of the main concerns with cloud computing is security &#8211; when it comes to national industry security compliance standards such as PCI DSS or HIPAA, additional precautions must be taken in order to protect confidential data during transmission. While PCI compliance calls for very specific requirements to protect customer cardholder data, it is possible to remain compliant while using the cloud. The PCI Security Council (PCI SSC) recently released a set of guidelines and recommendations on configuring virtualized environments to meet PCI requirements in June. The council acknowledges there is no one-size-fits-all hosting solution that allows all businesses to meet the PCI requirements, but they do address potential new risks that may be associated with virtualization technology. According to Onestopclick.com\u2019s article on PCI Compliance and the Public Cloud, some experts suggest using a separate secure server for transactions while using a cloud platform for other business operations. However, the PCI SSC suggests some public clouds have certain characteristics that may introduce challenges in defining scope and responsibilities when it comes to meeting PCI compliance, including the fact that the hosted entity may have limited knowledge of other tenants in their hosted environment and limited control over CHD storage. In&#8230;<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":true,"footnotes":""},"categories":[1],"tags":[],"other_category":[],"class_list":["post-1699","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Risk Assessments to Achieve PCI Compliance in the Cloud | OTAVA<\/title>\n<meta name=\"description\" content=\"One of the main concerns with cloud computing is security. If you&#039;re moving to the cloud and also need to meet PCI compliance, here&#039;s how to be successful.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Risk Assessments to Achieve PCI Compliance in the Cloud\" \/>\n<meta property=\"og:description\" content=\"One of the main concerns with cloud computing is security. If you&#039;re moving to the cloud and also need to meet PCI compliance, here&#039;s how to be successful.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/\" \/>\n<meta property=\"og:site_name\" content=\"OTAVA\" \/>\n<meta property=\"article:published_time\" content=\"2011-12-12T00:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-28T21:09:27+00:00\" \/>\n<meta name=\"author\" content=\"Irma Brillantes\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Irma Brillantes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/\"},\"author\":{\"name\":\"Irma Brillantes\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\"},\"headline\":\"Risk Assessments to Achieve PCI Compliance in the Cloud\",\"datePublished\":\"2011-12-12T00:00:00+00:00\",\"dateModified\":\"2025-05-28T21:09:27+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/\"},\"wordCount\":526,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/\",\"url\":\"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/\",\"name\":\"Risk Assessments to Achieve PCI Compliance in the Cloud | OTAVA\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/#website\"},\"datePublished\":\"2011-12-12T00:00:00+00:00\",\"dateModified\":\"2025-05-28T21:09:27+00:00\",\"description\":\"One of the main concerns with cloud computing is security. If you're moving to the cloud and also need to meet PCI compliance, here's how to be successful.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.otava.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Risk Assessments to Achieve PCI Compliance in the Cloud\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.otava.com\/#website\",\"url\":\"https:\/\/www.otava.com\/\",\"name\":\"OTAVA\u00ae\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.otava.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.otava.com\/#organization\",\"name\":\"OTAVA\u00ae\",\"url\":\"https:\/\/www.otava.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"contentUrl\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"caption\":\"OTAVA\u00ae\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\",\"name\":\"Irma Brillantes\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"caption\":\"Irma Brillantes\"},\"url\":\"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Risk Assessments to Achieve PCI Compliance in the Cloud | OTAVA","description":"One of the main concerns with cloud computing is security. If you're moving to the cloud and also need to meet PCI compliance, here's how to be successful.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/","og_locale":"en_US","og_type":"article","og_title":"Risk Assessments to Achieve PCI Compliance in the Cloud","og_description":"One of the main concerns with cloud computing is security. If you're moving to the cloud and also need to meet PCI compliance, here's how to be successful.","og_url":"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/","og_site_name":"OTAVA","article_published_time":"2011-12-12T00:00:00+00:00","article_modified_time":"2025-05-28T21:09:27+00:00","author":"Irma Brillantes","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Irma Brillantes","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/#article","isPartOf":{"@id":"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/"},"author":{"name":"Irma Brillantes","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263"},"headline":"Risk Assessments to Achieve PCI Compliance in the Cloud","datePublished":"2011-12-12T00:00:00+00:00","dateModified":"2025-05-28T21:09:27+00:00","mainEntityOfPage":{"@id":"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/"},"wordCount":526,"commentCount":0,"publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/","url":"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/","name":"Risk Assessments to Achieve PCI Compliance in the Cloud | OTAVA","isPartOf":{"@id":"https:\/\/www.otava.com\/#website"},"datePublished":"2011-12-12T00:00:00+00:00","dateModified":"2025-05-28T21:09:27+00:00","description":"One of the main concerns with cloud computing is security. If you're moving to the cloud and also need to meet PCI compliance, here's how to be successful.","breadcrumb":{"@id":"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.otava.com\/blog\/risk-assessments-to-achieve-pci-compliance-in-the-cloud\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.otava.com\/"},{"@type":"ListItem","position":2,"name":"Risk Assessments to Achieve PCI Compliance in the Cloud"}]},{"@type":"WebSite","@id":"https:\/\/www.otava.com\/#website","url":"https:\/\/www.otava.com\/","name":"OTAVA\u00ae","description":"","publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.otava.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.otava.com\/#organization","name":"OTAVA\u00ae","url":"https:\/\/www.otava.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","contentUrl":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","caption":"OTAVA\u00ae"},"image":{"@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263","name":"Irma Brillantes","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","caption":"Irma Brillantes"},"url":"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/"}]}},"_links":{"self":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/1699","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/comments?post=1699"}],"version-history":[{"count":0,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/1699\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/media?parent=1699"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/categories?post=1699"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/tags?post=1699"},{"taxonomy":"other_category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/other_category?post=1699"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}