The Body Shop
PCI deadlines have prompted the roll out of log management tools at The Body Shop

Body Shop rolls out PCI system

Retailer hopes to benefit from improved customer data analysis

Written by Angelica Mari

Cosmetics retailer The Body Shop is about to roll out a logging system to manage credit card information in line with Payment Card Industry Data Security Standard (PCI DSS) requirements, following a successful initial implementation in the Americas.

The company had to install a log management system to serve its operations in the Americas in time for a 31 March PCI compliance deadline, and is now set to implement the technology in the UK before rolling it out to businesses in the Europe, Middle East, Africa and Asia-Pacific regions.

Following an auditing process, the company selected the new system based on criteria such as compatibility with its existing IT set-up, scalability, ease of use and cost.

"We configured each test solution to talk to our systems and analysed how easy the system was to set up, how the vendor worked with us, and how well the product performed," said Body Shop director of global e-commerce and IT Jon Granville. "We wanted to be comfortable with both the tool and the vendor."

The US platform went live in March. Benefits gained from its use so far include improved reporting capabilities and secure long-term storage capacity for encrypted data to support forensic analysis.

"PCI sets standards which, from a security perspective, make common sense," said Granville. "We should be able to demonstrate that we are secure, compliance mandates or not."

Training was provided to users and IT support staff at The Body Shop during the testing and installation phase.

"We have not lost valuable time with staff going off for training courses. There's simply been no need," said Granville.

A secure network area for a system that handled credit cards at The Body Shop was also used to transmit some non-credit card data. With the log data provided by the new system, the retailer could identify how to establish links between systems outside of the secure zone.

The retailer also said the new log management system helped it to solve bandwidth-related issues with its point-of-sale software.

With compliance achieved in the Americas, the retailer now intends to roll out the LogLogic-supplied system in the UK and is currently assessing its infrastructure as well as the design for the logging tool.

"It's partly technical assessment but it's also a business process assessment: how do we process credit cards as a business? We need to map everything and see what is in scope," said Granville. "Once that has been established, we'll begin implementation."

reader comments

related articles

Credit cardSecurity

PCI DSS version 1.2 tackles wireless security

Latest iteration of data security standard released 01 Oct 2008

 

Payment card security standard under fire

PCI DSS a "joke", according to security expert 10 Sep 2008

Somerfield tests its payment card security

PCI compliance can drive good corporate governance, says supermarket 06 Nov 2007

Gala marks compliance card

Gaming group rolls out system to improve data reporting capabilities 24 Jul 2008

Payment data rules criticised

John Lewis IT chief says changing requirements hinder PCI compliance 10 Jul 2008

Protegrity set to target growing EMEA channel

New EMEA boss tasked with pushing the data protection vendor further into the UK 03 Jul 2008

Cotton Traders tightens credit card protections

Retailer deploys 'tokenisation' middleware 20 Nov 2008

Infosec: Reputation driving information security

Security is now everyone's problem 23 Apr 2008

related whitepapers

today's top stories

Nine priorities for 2009

Computing editor Bryan Glick looks at the workplace trends, policy issues, business drivers and technological developments that are most likely to influence IT agendas in the year ahead 07 Jan 2009

Panning for data gold - a guide to information management

Progressive IT chiefs are teaming up with business leaders to provide users with compelling new ways to sift through and make sense of corporate data 06 Jan 2009

Review 2008: Top 10 most-read stories of the year

We reveal the 10 articles from 2008 that you read more than any others on Computing.co.uk during the year 02 Jan 2009

Flash teddy

A reader who didn't sign his name sent us a very useful compendium of amusing USB drives, from which we take this... 06 Jan 2009

Using business process management to thrive through the downturn

Our panel of experts discuss how to bridge the IT-business gap 06 Jan 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Should the government cut costs by scrapping major IT projects?

Should the government cut costs by scrapping major IT projects?

Tell us what you think

Previous poll results

Latest audio and video articles

Podcast imageAudio

Computing podcast - the highlights of 2008

The Computing team pick their personal favourites of the year 18 Dec 2008

Xperia X1Video

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1 12 Dec 2008

Latest in-depth articles

panning for data goldFeatures

Panning for data gold - a guide to information management

Progressive IT chiefs are teaming up with business leaders to provide users with compelling new ways to sift through and make sense of corporate data 06 Jan 2009

Microsoft-YahooAnalysis

The stories that failed to materialise in 2008

vnunet.com looks at the events that were set to unfold this year but never did, and the likelihood that they will occur in 2009 02 Jan 2009

Advertisement

Primary Navigation