The Body Shop safeguards credit card info
By Miya Knights,
The Body Shop has revealed it has taken on new log management and reporting software to boost its information security.
One key requirement is the Payment Card Industry Data Security Standards (PCI DSS) from VISA and MasterCard, which all large and mid-sized retailers must comply with, to ensure sensitive transactional data, such as customer credit card details, is stored and handled securely.
The health and beauty retailer will use LogLogic software to gain visibility of security events within the infrastructure environment where it handles, processes and stores credit cardholder information.
It is planning to use the PCI-specific and customisable reporting capabilities of the new software to automatically verify security processes and deliver real-time, automated alerts on log-related IT security policies and controls. The reports will also help protect the integrity of log data for auditing and possible litigation purposes.
“Meeting the PCI DSS mandate and its deadlines for compliance is very important to us as a retailer,” said Jon Granville, The Body Shop's head of international e-commerce and IT. “Customer credit card information security is critical to maintaining confidence in our brand.”
Granville said the decision to take on LogLogic software came after reviewing the market for both suitable and PCI compliant products.
“We then went into a detailed review process and looked at a number of factors – including ease of installation and configuration, standards of reporting, scalability, usability and vendor commitment and ongoing support,” he added.
The retailer was working to very tight PCI DSS deadlines that required it to have a compliant systems in place within the Americas region by the 31 March 2008. Granville said this helped to further to differentiate the software from competitors.
“Right from outset, the vendor bought into our requirements and understood the key business drivers," he said. "It was extremely responsive to our time pressures and were, in fact, the only vendor who would give us a guarantee that they would deploy the solution into our environment by the deadline – that was very important to us."
The Body Shop is now working to make its systems in the UK, Europe, Middle East and Africa (EMEA) and Asia Pacific markets PCI compliant before the 2008 deadline for these regions.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
Who to trust after the VeriSign hack?
Davey Winder questions what data was stolen from VeriSign and wonders why the company hasn't been more forthcoming.
- Striving to solve the security skills crisis
- Would you employ a hacker or malware writer?
- Q&A: Raj Samani, CTO McAfee
- Erase and rewind: the EU and privacy
- My email address is [CENSORED]
- Is there such a thing as a secure tablet?
- 2011: The year in news
- BYOD: Old or new, good or bad?
- Are the cookie laws crumbling already?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Google releases Chrome for Android beta
- Will someone rid me of these troublesome Macs?
- OneNote hits Google?s Android
- BlackBerry Bold 9790 review
- Google sends in Bouncer to sort out malicious apps
- Ubuntu vs. Windows 7 on the business desktop
- Who to trust after the VeriSign hack?
- Head to Head: Mac OS X 10.7 Lion vs Windows 7
- ACTA: the basics, the controversies, and the future
- BT considering Ofcom price cap appeal
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





