Virtually Speaking

Dan Kusnetzky, Paula Rooney and Ken Hess

FireHost Introduces PCI 2.0 Compliant Public Cloud Offering

By | April 28, 2011, 3:16am PDT

Summary: FireHost takes the extra steps needed to help organizations comply with PCI’s standards.

Almost all of the survey results I’ve seen concerning what’s holding back medium and large organizations’ cloud adoption plans point out security is a major concern. The constant litany of security breaches and loss of consumer personal information isn’t helping put aside that fear. The payment card industry (PCI) has responded to this fear by setting standards. These standards have come to be the foundation of many organizations’ security policy even though they’re not in the payment card industry.

Some cloud computing service providers are making the claim that their service complies with PCI’s most recent standard, PCI 2.0. FireHost, for example, just announced that they are offering PCI 2.0 compliant cloud services that can survive an audit. If I think back, I can recall several other service providers saying something similar. Chris Drake, CEO of FireHost, spent some time explaining what his company is doing that sets them apart from others claiming PCI 2.0 compliance.

Conversation with Chris Drake

FireHost’s Chris Drake spent some time explaining how his company evolved, what they’re offering and how that is different from the services others are offering.

A little FireHost history

Fire Host started out using Citrix’s XenServer as a virtualization platform. The company soon learned that that XenServer, at that time, was vulnerable to several attacks and couldn’t be a long term platform for its offerings. After looking at Microsoft’s Hyper-V, Red Hat’s KVM, VMware’s ESX Sever and the open source Xen environment, the company decided that VMware’s products, enfolded with the proper processes and procedures, could be the foundation of a PCI complient environment.

What Fire Host is offering

Here’s what Fire Host says about its offerings:

FireHost provides a secure managed cloud hosting experience to protect valuable websites and business assets. We provide HIPAA compliant hosting and PCI compliant hosting solutions that’s ready for your secure data. Your HIPAA and PCI data will be secured in our managed hosting environment to the highest of enterprise standards. The FireHost AdvantageAll the features your business demands without the costs you’d expect:

Advanced Security
  • Secure Network Design
  • Application-Level Protection
  • DoS/DDoS Mitigation
  • PCI & HIPAA Compliant Ready
Easily Scalable
  • Grow to 42 GB Memory
  • Add up to 8 Processors
  • TBs of Storage Available
  • Load Balancing Available
Fully Managed
  • Advanced Security Included
  • Encrypted Backups Included
  • Full Monitoring Included
  • Fast Response Included

What is FireHost doing differently

FireHost would make the point that it is doing the following things that are quite different from what others are offering under the banner of PCI 2.0 compliance:

  • Card holder data is placed on systems behind the demilitarized zone (DMZ) and so, is not directly accessible from outside
  • Web application firewall is provided and is not a separate option
  • Two factor authorization a standard part of their product
  • System, application and other logs are reviewed daily
  • One year audit trail history is kept

Snapshot analysis

It is clear to me that security has to be baked into the architecture of a workload. It has to be considered a way of life rather than a set of add-on products. FireHost appears to talk that talk and also to walk the walk. Most other service providers that are claiming PCI 2.0 compliance don’t automatically take the extra steps FireHost takes. While those things might be available, they are often extra cost options that organizations might skip if they’re in a hurry.

While version 2.0 of the PCI DSS requirement didn’t please everyone (see  “PCI 2.0: Is that all there is?” by Jon Geater is Director of Technical Strategy at Thales), it is at least a start.

If your organization believes that PCI 2.0 compliance is an important part of its cloud implementation, a chat with FireHost is in order.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Daniel Kusnetzky is a distinguished analyst and the founder of the Kusnetzky Group LLC.

Disclosure

Dan Kusnetzky

The Kusnetzky Group LLC is an independent technology industry research firm that focuses on system software, virtualization and cloud computing technology.

Dan's opinions are based upon research, personal experiences and actual use of technology. They are not based upon the relationships the company may or may not have with suppliers, end user organizations, the media, consultants or other analysts.

Dan's research is available on a subscription basis through the Kusnetzky Group LLC. Dan's attendance at industry events or at client meetings may be sponsored by the client. Clients may provide hardware or software for testing prior to the publication of analysis that includes that product. Clients may also provide shirts, jackets, coffee cups, folders, backpacks, pens and other event chotchkies. While nice, these don't effect Dan's opinions or insight about those clients or their products.

Biography

Dan Kusnetzky

Daniel Kusnetzky, Analyst and Founder of Kusnetzky Group LLC, is responsible for research, publications, and operations. Mr. Kusnetzky has been involved with information technology since the late 1970s. Mr. Kusnetzky has been responsible for research operations at the 451 Group; corporate and marketing strategy for Open-Xchange; system software and virtualization research at IDC; and program and product management at Digital Equipment Corporation.; Today, Mr. Kusnetzky focuses on system software, virtualization technology and cloud computing.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
3
Comments

Join the conversation!

Just In

RE: FireHost Introduces PCI 2.0 Compliant Public Cloud Offering
upinson 28th Sep
@filhomarques
Deal Special dari KrisKros.com
Deal Special dari KrisKros.com
Deal Special dari KrisKros.com
Where does Idaho rank? We have been living in Montana for the past 5 years and I am not supri sexy shop to find it #3 on the "worst" list. Considering a sexshopmove to Idaho to escapthe high cost of living a low income in MT. There may not be a sales tax here but they get you if you own property!
@filhomarques
Deal Special dari KrisKros.com
Deal Special dari KrisKros.com
Deal Special dari KrisKros.com
Does the PCI compliant hosting solution come with a shared firewall, virtual private firewall or a dedicated firewall?

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix