The Body Shop
PCI deadlines have prompted the roll out of log management tools at The Body Shop

Body Shop rolls out PCI system

Retailer hopes to benefit from improved customer data analysis

Written by Angelica Mari

Cosmetics retailer The Body Shop is about to roll out a logging system to manage credit card information in line with Payment Card Industry Data Security Standard (PCI DSS) requirements, following a successful initial implementation in the Americas.

The company had to install a log management system to serve its operations in the Americas in time for a 31 March PCI compliance deadline, and is now set to implement the technology in the UK before rolling it out to businesses in the Europe, Middle East, Africa and Asia-Pacific regions.

Following an auditing process, the company selected the new system based on criteria such as compatibility with its existing IT set-up, scalability, ease of use and cost.

"We configured each test solution to talk to our systems and analysed how easy the system was to set up, how the vendor worked with us, and how well the product performed," said Body Shop director of global e-commerce and IT Jon Granville. "We wanted to be comfortable with both the tool and the vendor."

The US platform went live in March. Benefits gained from its use so far include improved reporting capabilities and secure long-term storage capacity for encrypted data to support forensic analysis.

"PCI sets standards which, from a security perspective, make common sense," said Granville. "We should be able to demonstrate that we are secure, compliance mandates or not."

Training was provided to users and IT support staff at The Body Shop during the testing and installation phase.

"We have not lost valuable time with staff going off for training courses. There's simply been no need," said Granville.

A secure network area for a system that handled credit cards at The Body Shop was also used to transmit some non-credit card data. With the log data provided by the new system, the retailer could identify how to establish links between systems outside of the secure zone.

The retailer also said the new log management system helped it to solve bandwidth-related issues with its point-of-sale software.

With compliance achieved in the Americas, the retailer now intends to roll out the LogLogic-supplied system in the UK and is currently assessing its infrastructure as well as the design for the logging tool.

"It's partly technical assessment but it's also a business process assessment: how do we process credit cards as a business? We need to map everything and see what is in scope," said Granville. "Once that has been established, we'll begin implementation."

reader comments

related articles

Credit cardSecurity

PCI DSS version 1.2 tackles wireless security

Latest iteration of data security standard released 01 Oct 2008

 

Payment card security standard under fire

PCI DSS a "joke", according to security expert 10 Sep 2008

Somerfield tests its payment card security

PCI compliance can drive good corporate governance, says supermarket 06 Nov 2007

Gala marks compliance card

Gaming group rolls out system to improve data reporting capabilities 24 Jul 2008

Payment data rules criticised

John Lewis IT chief says changing requirements hinder PCI compliance 10 Jul 2008

Protegrity set to target growing EMEA channel

New EMEA boss tasked with pushing the data protection vendor further into the UK 03 Jul 2008

Cotton Traders tightens credit card protections

Retailer deploys 'tokenisation' middleware 20 Nov 2008

Infosec: Reputation driving information security

Security is now everyone's problem 23 Apr 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation