Nutanix, Inc. is pleased to report that Coalfire Systems, Inc. (Coalfire), a Payment Card Industry Qualified Security Assessor (QSA) company, has conducted an independent technical assessment of the core components of the software based Nutanix® Cloud Platform and found that Nutanix solutions can be used by the customer to effectively provide support for PCI DSS payment entities’ objectives and requirements. This opinion applies to common scenarios such as merchant point-of-sale (POS) and many other payment card applications.
You can read the full Coalfire opinion here.
Why is this a big deal? Companies running retail PCI workloads have to choose infrastructure that not only delivers excellent performance, reliability, ease of use, and economics, but also helps support their ability to remain compliant and secure.
Superior customer experience is often what differentiates the best retailers from the rest, and especially in the COVID era. The majority of customer interaction happens online and having an easy, secure, and intuitive point-of-sale is no longer optional for businesses.
People want personal online profiles that offer a convenient way to deal with recurring payments or quick checkouts with saved credit card information. Unfortunately, credit card fraud has gotten exponentially worse over the years and retailers have been hot targets for these cyber attacks.
Customers must be confident that retailers and online service providers are taking the appropriate measures to secure their sensitive card information against breaches. A recent survey sponsored by Centrify Corporation found that about 65 percent of victims report “loss of trust” with an organization as a result of a breach. This can result in reduced business and losing customers to more trustworthy competitors.
Merchant-based vulnerabilities may appear almost anywhere in the card-processing ecosystem including:
Vulnerabilities may also extend to systems operated by service providers and acquirers, which are the financial institutions that initiate and maintain the relationships with merchants that accept payment cards.
To tackle these issues, the top five payment card companies JCB International, MasterCard, American Express, Discover Financial Services, and Visa Inc. combined forces to establish the Payment Card Industry Security Standards Council (PCI SSC). PCI SSC’s mission is to govern payment processing while protecting their clients and businesses.
PCI SSC established Payment Card Industry Data Security Standards (PCI DSS) to safeguard information. Compliance helps to alleviate vulnerabilities and protect cardholder data. These standards and security best practices must be adopted by the payment card brands for all entities that process, store, or transmit cardholder data and sensitive authentication data. Any business that transacts via credit card has a responsibility to ensure global payment account data security. Breaches do more than impact customers; they can have a big impact on a company’s reputation.
Nutanix, the recognized industry leader for hyperconverged infrastructure (HCI), provides a modern, cloud-like datacenter to power retail business transformation. Digitally enabled user experiences in retail require robust infrastructure, but with solutions that are easy, intelligent, resilient, and secure. Nutanix solutions support retailers and delight their end customers across channels and offer immersive personalized experiences in smart stores and ensure a connected digital supply chain.
The Nutanix platform is powerful, flexible, and scalable to virtually all environments. Coalfire – a trusted cybersecurity advisor – reviewed the Nutanix core software product for its efficacy in assisting payment card entities and PCI service providers with deployments that may be subject to assessment for the PCI DSS compliance. Coalfire assessed:
Coalfire opines that the reviewed Nutanix solution can be effective in providing significant and substantial support for PCI DSS payment entities’ objectives and requirements.
Through a feature review and technical deep dive, Coalfire was able to evaluate the architectural integrity and completeness of Nutanix to support most of the technical controls in 11 of the 12 PCI DSS requirements.
According to Coalfire, Nutanix solutions can be effective in providing significant and substantial support for PCI DSS payment entities’ objectives and requirements. This opinion applies to common scenarios such as merchant point-of-sale (POS) and many other payment card applications.