PCI DSS Compliant Local Hosting Providers

Praemon

Expert Member
Joined
Jan 11, 2007
Messages
1,899
Reaction score
472
Location
Cape Town
Out of interest, are there any local hosting providers that are PCI DSS compliant in terms of their network offering? Obviously there's a lot involved in other areas for compliancy, specifically what the merchant must ensure from their side, but are there any hosting services that can cover the network side of things (physical security, firewalls, virus scans, vulnerability scans, threat management, etc.) to make sure the process is straight forward? Really, a lot of the requirements for compliancy on the network side is something all web hosting providers should offer anyways, but haven't seen many who will back it up and advertise it as a feature of their offering.

I see Teraco's co-location hosting is PCI-DSS compliant, but I'd imagine that's fairly pricey. Would be great if someone like Hetzner, or an affordable cloud provider, offered this.
 
Out of interest, are there any local hosting providers that are PCI DSS compliant in terms of their network offering? Obviously there's a lot involved in other areas for compliancy, specifically what the merchant must ensure from their side, but are there any hosting services that can cover the network side of things (physical security, firewalls, virus scans, vulnerability scans, threat management, etc.) to make sure the process is straight forward? Really, a lot of the requirements for compliancy on the network side is something all web hosting providers should offer anyways, but haven't seen many who will back it up and advertise it as a feature of their offering.

I see Teraco's co-location hosting is PCI-DSS compliant, but I'd imagine that's fairly pricey. Would be great if someone like Hetzner, or an affordable cloud provider, offered this.

Unfortunately you can't combine PCI-DSS compliance and affordable, they don't go together.
 
Yeah - any PCI DSS compliant provider is going to be expensive.
 
Your main webhosting (Webafrica) would still need to be PCI DSS Compliant though to fully pass any tests.

That would be highly uneconomical for them or any other hosting provider for that matter. The costs involved are too great and completely unnecessary for a server that does not host any user data. If they need to pass a PCI compliance audit they would need something like CloudFlare actively running on each server.

You are going to have a very hard time finding a hosting provider that is compliant apart from Teraco.

I don't see why you wouldn't pass compliance if you have CloudFlare on your hosting package. The server would be secure and that's the end of it.

These are the compliance requirements, which you can take care of yourself by enforcing a service like CloudFlare on your server and implementing policies within your organization in regards to the access and monitoring of the data.

Install and maintain a firewall configuration to protect cardholder data;
Do not use vendor-supplied defaults for system passwords and other security parameters;
Protect stored cardholder data;
Encrypt transmission of cardholder data across open, public networks;
Use and regularly update anti-virus software;
Develop and maintain secure systems and applications;
Restrict access to cardholder data by business need-to-know;
Assign a unique ID to each person with computer access;
Restrict physical access to cardholder data;
Track and monitor all access to network resources and cardholder data;
Regularly test security systems and processes;
Maintain a policy that addresses information security.
 
Enforcing Cloud-Flare would be nowhere NEAR enough to get PCI-DSS compliance...

All of those requirements apply to the WHOLE stream of data relating to card info and payment info... not just the end portal the user sees.
 
That would be highly uneconomical for them or any other hosting provider for that matter. The costs involved are too great and completely unnecessary for a server that does not host any user data. If they need to pass a PCI compliance audit they would need something like CloudFlare actively running on each server.

You are going to have a very hard time finding a hosting provider that is compliant apart from Teraco.

I don't see why you wouldn't pass compliance if you have CloudFlare on your hosting package. The server would be secure and that's the end of it.

These are the compliance requirements, which you can take care of yourself by enforcing a service like CloudFlare on your server and implementing policies within your organization in regards to the access and monitoring of the data.

Install and maintain a firewall configuration to protect cardholder data;
Do not use vendor-supplied defaults for system passwords and other security parameters;
Protect stored cardholder data;
Encrypt transmission of cardholder data across open, public networks;
Use and regularly update anti-virus software;
Develop and maintain secure systems and applications;
Restrict access to cardholder data by business need-to-know;
Assign a unique ID to each person with computer access;
Restrict physical access to cardholder data;
Track and monitor all access to network resources and cardholder data;
Regularly test security systems and processes;
Maintain a policy that addresses information security.

That doesn't give you PCI compliance. What about physical access to the server? How do you control that?
Or network traffic?
And what about the 3rd party applications you use, which you don't have control over?
 
Top
Sign up to the MyBroadband newsletter
X