hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Colocation and Data Centers : Anyone that has a list of PCI certified hosting company ?
Reply

Colocation and Data Centers Find data centers, server hardware, bandwidth providers, and techniques for colocation purposes. Get advice on colocation web hosting, review providers and offer suggestions on choosing colocation hosting services and the right datacenter. If your service is unavailable, please click here.
Forum Jump

Anyone that has a list of PCI certified hosting company ?

Reply Post New Thread In Colocation and Data Centers Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 04-13-2008, 11:51 AM
fionix fionix is offline
Web Hosting Master
 
Join Date: Dec 2006
Location: Europe
Posts: 592
Question

Anyone that has a list of PCI certified hosting company ?


Has anyone a list of PCI certified hosting providers ?

For those of you that don't know what it is, here is a link :

https://www.pcisecuritystandards.org/

Thanks for your help.

Reply With Quote


Sponsored Links
  #2  
Old 04-14-2008, 10:21 AM
voipcarrier voipcarrier is offline
Aspiring Evangelist
 
Join Date: Mar 2007
Posts: 402
Correct me if I'm wrong, but doesn't the providers PCI DSS involvement only involve providing a locking cabinet or cage? Other than that, the requirements are all on your end (firewall, IDS, storage requirements, quarterly security assessment, etc.). Unless you're looking for a managed solution, it's all your equipment.

Also, it's probably easier to find an SAS70 facility. As far as I've seen, SAS70 requirements exceed PCI DSS.

Reply With Quote
  #3  
Old 04-14-2008, 11:04 AM
sjhwilkes sjhwilkes is offline
WHT Addict
 
Join Date: Jan 2003
Posts: 138
And having screened all employees with access to the environment. But yes if you're just taking straight co-lo that's it.
I've been doing PCI consulting (and CISP before that) for many years, and as the rules get tighter and tighter it just keeps getting better for me. I feel bad for some small companies that are above the transaction threshold for Level 2 though, it's hard for them...

Reply With Quote
Sponsored Links
  #4  
Old 04-17-2008, 04:38 AM
fionix fionix is offline
Web Hosting Master
 
Join Date: Dec 2006
Location: Europe
Posts: 592
Quote:
Originally Posted by voipcarrier View Post
Correct me if I'm wrong, but doesn't the providers PCI DSS involvement only involve providing a locking cabinet or cage? Other than that, the requirements are all on your end (firewall, IDS, storage requirements, quarterly security assessment, etc.). Unless you're looking for a managed solution, it's all your equipment.

Also, it's probably easier to find an SAS70 facility. As far as I've seen, SAS70 requirements exceed PCI DSS.
I'm sorry but it is not what I'm looking for and it is not that easy as you asking for. The hosting company need to be PCI certified itself for what I look for.

Reply With Quote
  #5  
Old 04-17-2008, 02:42 PM
appliedops appliedops is offline
NetOps Ninja
 
Join Date: Jan 2005
Location: San Francisco/Hot Springs
Posts: 984
Quote:
Originally Posted by fionix View Post
I'm sorry but it is not what I'm looking for and it is not that easy as you asking for. The hosting company need to be PCI certified itself for what I look for.
I'll look into it more, but I don't think colocation facilities are candidates for PCI audits...
If you need a PCI compliant setup in a colocation facility, thats relatively easy but you'd need to pay for the audit yourself in order for you to be PCI compliant...

__________________
AppliedOperations - Premium Service
Bandwidth | Colocation | Hosting | Managed Services | Consulting
www.appliedops.net

Reply With Quote
  #6  
Old 04-17-2008, 05:20 PM
voipcarrier voipcarrier is offline
Aspiring Evangelist
 
Join Date: Mar 2007
Posts: 402
Quote:
Originally Posted by fionix View Post
I'm sorry but it is not what I'm looking for and it is not that easy as you asking for. The hosting company need to be PCI certified itself for what I look for.
If you are looking for a truly colo scenario, then the data center is not responsible for the PCI compliance. The only requirement that might be affected by the individual provider is the employee screening, but they won't really have access to the data so I'm not even sure if that applies.

All of the security audits, firewall and IDS requirements, etc. are your responsibility unless you're in a managed hosting environment. I'm assuming you're not since this is the colocation and data center forum, but maybe I'm wrong.

In my basic understanding of the regulations, as long as you have a locking cage or cabinet from the data center you could make any facility compliant.

This is one of those scenarios where it often times makes sense to bring in an experienced consultant.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Web Hosts, IT Services Firms Make Inc 5000 Fastest Growing Companies Web Hosting News 2012-09-19 16:45:40
Web Host Certified Hosting Launches New Linux VPS Plans Web Hosting News 2012-08-22 09:08:38
Web Host Certified Hosting Offers CloudFlare Security and Performance Service Web Hosting News 2012-01-04 16:07:29
Indian Web Host BrainPulse to Expand Technical Support Staff Web Hosting News 2011-10-03 15:33:07
Web Host Online Tech Expands Data Center Staff, Adds Partner Certifications Web Hosting News 2011-06-29 20:49:34


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?