DrupalSecurityTeam / drupalpcicompliance

Official github repo for the Drupal PCI compliance white paper.
http://drupalpcicompliance.org
Other
56 stars 15 forks source link

Provide More Thorough List of PCI Compliant Hosting Options #22

Closed rickmanelius closed 10 years ago

rickmanelius commented 10 years ago

In the 1.0 release, the only PCI compliant cloud solution that I felt comfortable/confident with recommending was amazon AWS. Since then, it has come to my attention that there are several other options that need exploring/vetting.

Example Candidates:

Note: I've seen some vendor claims that later turned out to be false/misleading. Therefore some level of vetting needs to be done to ensure they are legitimate. At the very least, I would like to find 3-4 alternatives to Amazon AWS.

rcross commented 10 years ago

Perhaps a better (and more indelible) approach would be to provide some guidelines about how to vet a host for PCI compliance (among your other hosting requirements). Depending on how comprehensive it is, this might even be a separate article/paper.

While I would also like to see a few alternative examples to AWS, I think it is a slippery slope if we start providing a list of vetted/recommended hosts. We may also want to consider whether to comment on the suitability/compliance of Acquia, Pantheon, Omega8, AberdeenCloud, Blackmesh, Bluehost, A2, Arvixe or any other Drupal-specialised hosting for PCI requirements.

FatherShawn commented 10 years ago

+1 to the approach that @rcross suggests about how to vet.

rickmanelius commented 10 years ago

Hi @rcross and @FatherShawn. I agree with your line of reasoning. How about this... the paper itself outlines the criteria and then references a blog post that can review some of the options. This keeps the paper concise and more timeless while the blog post is accurate as of the publish date and can go into more detail. This is similar to the "myths" article that we wrote and took pieces into the paper while then flushing out in more detail here

http://drupalpcicompliance.org/article/2013/08/24/top-12-drupal-pci-compliance-myths/

rickmanelius commented 10 years ago

Hi @rcross and @FatherShawn. This is addressed here https://github.com/rickmanelius/drupalpcicompliance/blob/9480cf6664abdd38e08cec8651b5ffbeae8057c8/DrupalPCICompliance.md#i-can-achieve-pci-compliance-using-cloud-hosting.

I'm going to close this out before opening up a more formal review process in another issue thread. Thanks for the feedback!