hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Cloud Hosting : PCI-DSS and FreeBSD on EC2
Reply

Cloud Hosting Discussions involving Cloud Computing, grid computing and related technologies.
Forum Jump

PCI-DSS and FreeBSD on EC2

Reply Post New Thread In Cloud Hosting Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 01-26-2012, 10:37 AM
Crashus Crashus is offline
Corporate Member
 
Join Date: Apr 2009
Posts: 801
*

PCI-DSS and FreeBSD on EC2


Hello,

Maybe some of you guys know if Amazon providing Report of Compliance to their clients? I need to know is it possible to host pci-dss application on their cloud. Also I need to sign a contract with them in order to use them as pci-dss certified DC. Anyone did this before?

Also, just qurious - have anyone (except me and few other folks) user FreeBSD at EC2? It is already production-ready, still been created from windows instance so billed as windows one as well unfortunately. I tried to ask both questions to Amazon directly but no answer unfortunately.

Reply With Quote


Sponsored Links
  #2  
Old 01-26-2012, 10:43 AM
quantumphysics quantumphysics is offline
MACBOOKS EVERYWHEREEEEEEEEEEEE
 
Join Date: Mar 2009
Posts: 3,804

__________________
mirACL: firewalls in software.

Reply With Quote
  #3  
Old 01-26-2012, 10:47 AM
Crashus Crashus is offline
Corporate Member
 
Join Date: Apr 2009
Posts: 801
Except what I asked was Report of Compliance

Maybe someone now Amazon employee contact so I can directly mail him?

Reply With Quote
Sponsored Links
  #4  
Old 01-26-2012, 12:18 PM
FastServ FastServ is offline
Randy
 
Join Date: Aug 2006
Location: Ashburn VA, San Diego CA
Posts: 3,897
Amazon submits their reports directly to PCI not to you. When you fill out your PCI compliance questionnaire you will list AWS as your host. Unless amazon is actually processing payments for you (in a manner like Paypal where you redirect your users to their system for payment) you're still on your own to become PCI compliant yourself. You cannot rely on your host's compliance if you are processing/storing payments on your own unmanaged server instance.

__________________
Fast Serv Networks, LLC | AS29889 | Dedicated, Cloud, Streaming and more...
Auto OS Install | IPMI | Routed Private Network w/VPN | Managed Services


Reply With Quote
  #5  
Old 01-26-2012, 12:20 PM
Crashus Crashus is offline
Corporate Member
 
Join Date: Apr 2009
Posts: 801
Randy,

Whenever I'm applying for PCI compliance I must ensure my QSA that I have my datacenter pci compliant (as DC, not as merchant) as well. For this purpose I need contract with them, and complete report

Reply With Quote
  #6  
Old 01-26-2012, 01:44 PM
quantumphysics quantumphysics is offline
MACBOOKS EVERYWHEREEEEEEEEEEEE
 
Join Date: Mar 2009
Posts: 3,804
What QSA? When I had to deal with PCI on AWS it was basically "we use aws ec2/s3 they're validated" "okay." without further issues.

Amazon can give you a signed email or something (PGP?) if you need it, whine at their support or on the AWS forums.

__________________
mirACL: firewalls in software.

Reply With Quote
  #7  
Old 01-26-2012, 02:32 PM
Crashus Crashus is offline
Corporate Member
 
Join Date: Apr 2009
Posts: 801
Quote:
Originally Posted by quantumphysics View Post
What QSA? When I had to deal with PCI on AWS it was basically "we use aws ec2/s3 they're validated" "okay." without further issues.

Amazon can give you a signed email or something (PGP?) if you need it, whine at their support or on the AWS forums.
Have you received payment processor certificate?
Like this:
http://www.visaeurope.com/en/busines...providers.aspx

Reply With Quote
  #8  
Old 01-26-2012, 03:46 PM
Akisoft Akisoft is offline
Junior Guru
 
Join Date: Aug 2010
Location: United Kingdom
Posts: 199
Not sure why you need a certificate from them, we listed them as an infrastructure provider and everything was fine.

__________________
I do things. - Consumer and b2b IT solutions.

Reply With Quote
  #9  
Old 01-26-2012, 03:47 PM
Crashus Crashus is offline
Corporate Member
 
Join Date: Apr 2009
Posts: 801
Can you guys PM me your certified processor sites and companies which were certifying you?
Thanks

Reply With Quote
Reply

Similar Threads
Thread Thread Starter Forum Replies Last Post
Huge PCI-DSS Vulnerabilities... Crothers Web Hosting Lounge 12 08-12-2011 07:10 PM
pci dss shared webhosting suhasagg Hosting Security and Technology 0 06-04-2011 01:45 PM
PCI DSS compliance prashant1979 Running a Web Hosting Business 11 12-15-2010 04:52 PM
PCI-DSS Audit Crothers Ecommerce Hosting & Discussion 10 01-29-2010 04:01 PM
PCI DSS Compliance - What do I need to adhere to? luke_a Ecommerce Hosting & Discussion 7 09-30-2008 09:01 AM

Related posts from TheWhir.com
Title Type Date Posted
Web Host Rackspace Adds FreeBSD 9, CentOS 6.3 Support to Cloud Servers Web Hosting News 2012-07-30 12:47:10
Web Host ServerPronto Donates Hosting Resources to CentOS Web Hosting News 2012-07-05 14:06:27
NYI Network Administrator Launches New Version of Network Analysis Tool Net Sensor Web Hosting News 2012-06-26 13:53:47
Colocation Provider NYI Launches East Coast Mirror for FreeBSD Foundation Web Hosting News 2012-05-25 10:37:18
Host Virtual Expands Cloud Service in TelecityGroup London Data Center Web Hosting News 2012-02-02 16:55:29


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?