{"id":1301,"date":"2021-04-05T13:54:06","date_gmt":"2021-04-05T13:54:06","guid":{"rendered":"https:\/\/www.pcidssguide.com\/?p=1301"},"modified":"2023-10-09T16:30:25","modified_gmt":"2023-10-09T16:30:25","slug":"pci-compliance-in-the-cloud","status":"publish","type":"post","link":"https:\/\/pcidssguide.com\/pci-compliance-in-the-cloud\/","title":{"rendered":"PCI Compliance in the Cloud"},"content":{"rendered":"\n\n\n\n\n

While cloud services can offer attractive opportunities for organizations of all sizes, organizations must be aware of a particular cloud choice’s risks and challenges before moving their sensitive data or services to the cloud.<\/p>\n\n\n\n

Perhaps the most significant point of confusion regarding the Payment Card Industry Data Security Standard (PCI DSS) and cloud computing is who is in charge of compliance. In addition to business and risk considerations, implementing security controls in a cloud environment requires special technical knowledge and skills.<\/p>\n\n\n\n

See Also: What is PCI DSS and PCI Compliance?<\/a><\/strong><\/p>\n\n\n\n

As a result, before migrating payment card processing to the cloud, you can appoint technical, legal, due diligence, information security, and enforcement teams to collaborate and identify your needs, as well as determine potential cloud service services based on those needs.<\/p>\n\n\n\n

Ensuring that cloud services are securely designed, maintained, and used is a responsibility shared between the cloud provider and the client. It is important to note that not all cloud services are created equal.<\/p>\n\n\n\n

See Also: PCI DSS Requirements<\/a><\/strong><\/p>\n\n\n\n

Clear policies and procedures must be agreed upon between Customer and Provider for all security requirements. Operations, management, and reporting responsibilities for each requirement should be clearly defined, understood, and settled in writing by contractual agreements.<\/p>\n\n\n\n

Concerning third-party or public clouds, you should consider that while you can outsource the day-to-day operational management of your data environment, you will retain responsibility for the data you put in the cloud.<\/p>\n\n\n\n

See Also: Cloud Security Checklist<\/strong><\/a><\/p>\n\n\n\n

There are a few items to consider if your company wishes to move PCI DSS in-scope systems to the public cloud. Any organization wishing to migrate or evaluate cloud services should follow these steps:<\/p>\n\n\n\n