VPS Hosting-PCI Compliant?
#1
Posted 11 February 2010, 09:11
#2
Posted 11 February 2010, 12:37
markw10, on 11 February 2010, 09:11, said:
#3
Posted 12 February 2010, 00:01
It is mainly about who has access to it.
But provided you do not store cards it is not that hard to comply.
However there is the provision for code audits, PCI complicance by your suppliers etc. to be dealt with.
#4
Posted 14 February 2010, 10:42
mdtaylorlrim, on 11 February 2010, 12:37, said:
The restrictions imposed on providers to achieve PCI compliance make it impossible to offer a PCI compliant shared hosting environment. VPS would be open to debate since the physical hardware is a shared resource. Dedicated servers would be the only way to ensure 100% PCI Compliance IMO and even then would only apply if the whole hosting company itself was PCI Compliant.
The best solution though would be to speak with your bank and discuss the details since its them who will decide if you will receive a fine for non-compliance.
osCommerce Monkey & Lead Guitarist for "Sparky + the Monkeys" (Album on sale in all good record shops)
---------------------------------------
Software is like sex: It's better when it's free. (Linus Torvalds)
#5
Posted 14 February 2010, 16:04
Mark Evans, on 14 February 2010, 10:42, said:
#6
Posted 14 February 2010, 19:21
mdtaylorlrim, on 14 February 2010, 16:04, said:
Passing the PCI-DSS security scan is different from being PCI-Compliant. PCI-Compliance is much more than just passing a website scan, there are access restrictions to be placed on physical hardware and also limitations on what each of the users of a shared server can access such as server resources which are very complicated to get setup in a shared hosting environment hence pretty much every shared hosting company doesn't bother except when dealing with dedicated servers.
I don't know of any company providing PCI Compliant hosting on shared servers, if the company you use does I would be interested to speak with them as I know of others looking for a way to host sites and be PCI Compliant without going fully dedicated. If you could send me a link via PM I would be grateful
Disclaimer I am not a PCI-DSS "Expert" so take my advice with caution, for legal opinions always consult an official PCI-DSS Consultant and get all advice in writing
osCommerce Monkey & Lead Guitarist for "Sparky + the Monkeys" (Album on sale in all good record shops)
---------------------------------------
Software is like sex: It's better when it's free. (Linus Torvalds)
#7
Posted 14 February 2010, 20:26
Mark Evans, on 14 February 2010, 19:21, said:
I don't know of any company providing PCI Compliant hosting on shared servers, if the company you use does I would be interested to speak with them as I know of others looking for a way to host sites and be PCI Compliant without going fully dedicated. If you could send me a link via PM I would be grateful
#8
Posted 14 February 2010, 22:04
mdtaylorlrim, on 14 February 2010, 20:26, said:
Then your setup would be considered dedicated in the normal sense of hosting setups. Shared hosted is what I would consider mass virtual hosting with 200+ sites setup for a wide range of clients.
osCommerce Monkey & Lead Guitarist for "Sparky + the Monkeys" (Album on sale in all good record shops)
---------------------------------------
Software is like sex: It's better when it's free. (Linus Torvalds)
#9
Posted 17 February 2010, 04:59
Mark Evans, on 14 February 2010, 19:21, said:
Edited by AlanR, 17 February 2010, 05:00.
Tools: BBEdit, Coda, Versions (Subversion), Sequel Pro (db management)
#10
Posted 17 February 2010, 05:48
#11
Posted 17 February 2010, 08:42
AlanR, on 17 February 2010, 04:59, said:
That would make sense since VPS servers are just dedicated servers that use some kind of virtualisation to partition off resources
osCommerce Monkey & Lead Guitarist for "Sparky + the Monkeys" (Album on sale in all good record shops)
---------------------------------------
Software is like sex: It's better when it's free. (Linus Torvalds)
#12
Posted 19 February 2010, 15:23
From what I understood, the PCI compliance also means that the web site owner needed to do the questionaire / survey. The answers would depend on if the shop was compliant.
This entire process takes into account who has access to the credit card info, if it is stored and how are payments taken.
My servers are all shared and run with the compliance scans without issue. My clients also have taken the survey and based on the scans and the answers are compliant based on the initial level (they do not take credit card info and do not store it anywhere).
So a shared server can be compliant. Now when the credit card data is retained and saved, this is when the dedicated server and limited access to the customer credit card data etc is more restrictive and a shared server will not do.
So in effect, the compliance is not a simple answer of dedicaterd or shared being compliant, but rather what are youy saving who has access to it etc.
This is what I have found anyways....
cheers
-----------------------------
See my Profile (click here) for more information and to contact me for professional osCommerce support that includes SEO development, custom development and security implementation
#13
Posted 19 February 2010, 15:49
Mark Evans, on 17 February 2010, 08:42, said:
#14
Posted 20 February 2010, 14:11
cannuck1964, on 19 February 2010, 15:23, said:
Completely.
osCommerce Monkey & Lead Guitarist for "Sparky + the Monkeys" (Album on sale in all good record shops)
---------------------------------------
Software is like sex: It's better when it's free. (Linus Torvalds)
#15
Posted 20 February 2010, 14:14
mdtaylorlrim, on 19 February 2010, 15:49, said:
VPS is debatable IMHO, it all depends on the company and what they allow you to do with the VPS. There are many different ways to do VPS some would be possible to make compliant easily, some wouldn't ever be possible. They are still classed as VPS though.
My motto, if its important then always deal with a company who will guarantee they can provide compliant hosting rather than just assume because its VPS it is compliant.
osCommerce Monkey & Lead Guitarist for "Sparky + the Monkeys" (Album on sale in all good record shops)
---------------------------------------
Software is like sex: It's better when it's free. (Linus Torvalds)
#16
Posted 26 February 2010, 17:15
Mark Evans, on 20 February 2010, 14:14, said:
My motto, if its important then always deal with a company who will guarantee they can provide compliant hosting rather than just assume because its VPS it is compliant.
I use vps at the moment and am considering dedicated, but dont like the jump in cost involved.
The sites on my vps are pci compliant as it stands. I am pleased with my service and nothing seems to be any trouble and its all done for free. (well included in the price at the start).
Never go for a company on promises, find one that delivers quickly what you ask for.
#17
Posted 09 July 2010, 22:55
ken














