Fri, June 11, 2010
Thu, June 10, 2010
Wed, June 9, 2010
Tue, June 8, 2010
Mon, June 7, 2010
Sat, June 5, 2010
Fri, June 4, 2010
Thu, June 3, 2010
Wed, June 2, 2010
Tue, June 1, 2010
Mon, May 31, 2010
Fri, May 28, 2010
Thu, May 27, 2010
Wed, May 26, 2010
Tue, May 25, 2010
Mon, May 24, 2010
Sun, May 23, 2010
Fri, May 21, 2010
Thu, May 20, 2010
Wed, May 19, 2010
Tue, May 18, 2010
Mon, May 17, 2010
Fri, May 14, 2010

Secure POS Vendor Alliance Releases End-to-End Encryption Security Requirements


  Copy link into your clipboard //house-home.news-articles.net/content/2010/05/2 .. end-to-end-encryption-security-requirements.html
  Print publication without navigation Published in House and Home on by Market Wire
          🞛 This publication is a summary or evaluation of another publication

ATLANTA, GA--(Marketwire - May 27, 2010) - The Secure POS Vendor Alliance ([ SPVA ]), a non-profit business organization founded by Hypercom (NYSE: [ HYC ]), Ingenico S.A. (EURONEXT: ING) and VeriFone (NYSE: [ PAY ]) today announced the release of its End-to-End [ Encryption Security ] Requirements related to [ payment card ] data in payment card reading devices. Targeted to vendors of POS devices, this newly released framework marks a critical step toward SPVA's mission of widespread understanding of payment security issues and the adoption of best practices.

"The SPVA's end-to-end security requirements guidelines set a baseline for the industry and represent the first step to further strengthen payment security standards globally," said T.K. Cheung, SPVA chairman and Hypercom vice president global quality & security. "We will be enhancing this guideline as the security environment evolves and will announce each update as it occurs."

Prepared by the association's End-to-End Encryption Technical Working Group, the newly released SPVA guideline allows companies to engage different solutions and select products that can be trusted and are secure. Key elements covered by the SPVA-approved standard include:

  • Data to be encrypted during transmission
  • Key management
  • Physical and logistical security of the Tamper-Resistant Security Module and key components
  • Encryption monitoring and management systems requirements

The SPVA defines end-to-end as: the transmission of cardholder data in an encrypted form, from its point of presentment, such that it prevents the data from being known in plain text until the point of decryption.

"SPVA does not endorse any specific vendor's solution, nor does it have any intention of supporting one solution over another," said Steven Hughes, SPVA president. "We recognize that end-to-end encryption requirements can be complex. Against this backdrop, our goal is to use existing published standards and provide an auditable set of requirements that creates a secure payment environment."

Since its launch in April 2009, SPVA has experienced rapid growth with prominent industry leaders joining, including Atos Worldline, Heartland Payment Systems, Chase Paymentech, Radiant Systems, Inc., Voltage Security and many others. All members are eligible to participate in SPVA's Technical Working Groups and contribute to future industry standard publications.

To download the association's End-to-End Encryption Security Requirements white paper and to learn more about the SPVA, visit [ www.spva.org ].

About Secure POS Vendor Alliance ([ www.spva.org ])
The Secure POS Vendor Alliance (SPVA) is a non-profit organization that works with the multiple stakeholders of the payment value chain. Its aim is to develop an end-to-end security framework and to enhance security elements of payment solutions which protect cardholder information and defend merchants and acquirers against security breaches, while helping reducing fraud and lowering risk for all electronic payment stakeholders.


Publication Contributing Sources