E-commerce on Azure increases security with Payment Card Industry Three-Domain Secure compliance

More customers than ever are shopping from home in the current health environment, and companies are responding by rapidly deploying cloud-based e-commerce solutions. Azure is helping these companies meet their customers' needs with robust, customizable, and scalable e-commerce solutions that process transactions quickly and securely.

Source: E-commerce on Azure increases security with Payment Card Industry Three-Domain Secure compliance

Security is paramount for both e-commerce providers and customers, and we are always working to make Azure as secure as possible. 

Today we’re announcing that Azure is one of the first hyperscale cloud service providers to achieve Payment Card Industry Three-Domain Secure (PCI 3DS) certification. 

Azure retained a qualified 3DS Assessor Company to conduct an assessment of Azure's PCI 3-D Secure Environment (3DE) in accordance with the PCI 3DS Core Security Standard. The PCI 3DS Core Security provides a framework for implementing security controls that support the integrity and confidentiality of card-not-present transactions using the EMV 3-D Secure (3DS) messaging protocol. EMV 3DS provides an additional layer of security for card-not-present transactions by enabling cardholders to authenticate to their card issuers before making online transactions. 

The Azure cloud platform offers various product offerings that may be used by customers to support their own PCI 3DS payment solutions. Although the Azure cloud platform does not manage 3DS Domains or their functions, Azure’s PCI 3DS certification enables Azure customers to implement their own 3-D Secure Environment (3DE) on the Azure cloud platform and unblocks them from pursuing their own PCI 3DS certification. 

Azure’s PCI 3DS certification offers great news to customers looking to create more secure e-commerce solutions while complying with the PCI 3DS Core Security Standard.

Customers can download the Azure PCI 3DS 1.0 Package which contains all of the information necessary to leverage Azure’s PCI 3DS certification including the following documents as described below:
•    Azure PCI 3DS Shared Responsibility Matrix
•    Azure PCI 3DS White Paper
•    Azure PCI 3DS Attestation of Compliance

Advertisements

Azure PCI 3DS Shared Responsibility Matrix

SaleBestseller No. 1
EIGHTREE Smart Plug, Smart Plugs That Work with Alexa & Google Home, Compatible with SmartThings, Smart Outlet with WiFi Remote Control and Timer Function, 2.4GHz Wi-Fi Only, 4Packs
  • APP Remote Control: Easily control your home...
  • Voice Control: Smart plugs that work with Google...
  • Easy Setup: It takes less than two minutes for the...
  • Other Features: Diverse timer scheduling...
  • 7*24 Customer Service: If you encounter any issues...
Bestseller No. 2
All-new Echo Show 8 (3rd Gen, 2023 release) | With Spatial Audio, Smart Home Hub, and Alexa | Charcoal
  • BETTER INSIDE AND OUT – Entertainment is more...
  • VIBRANT SIGHTS, FULL SOUND – Content on Prime...
  • SMART HOME, SIMPLIFIED – Pair and control...
  • STAY IN THE LOOP – Video call hands-free using...
  • SHOW OFF YOUR GOOD TIMES – Amazon Photos turns...

Last update on 2024-04-05 / Affiliate links / Images from Amazon Product Advertising API

The Azure PCI 3DS Shared Responsibility Matrix describes the Azure PCI 3DS assessment scope and illustrates the PCI 3DS compliance responsibilities for Azure and its customers. It is intended to be used by Azure customers and their compliance advisors to understand the scope of the Azure PCI 3DS assessment and expectations for responsibilities when using Azure services as part of the customer's 3DE.
Understanding the shared responsibility for implementing security controls in a cloud environment is essential for customer building systems and utilizing services in Azure. The Azure PCI 3DS Shared Responsibility Matrix supports Azure customers implementing and documenting security controls for a system built on Azure by clearly delineating each PCI 3DS requirement's responsibilities. Implementing a specific security control may be the responsibility of Azure, the responsibility of Azure's customers, or a shared responsibility between Azure and its customers.

Azure PCI 3DS White Paper

Our new Microsoft Azure Cloud Platform for PCI 3DS White Paper provides guidance to Azure PCI 3DS customers on the PCI 3DS Core Security Standard and how the Azure 3DE can be utilized to implement a 3DE on the Azure cloud platform. The paper was produced on behalf of Microsoft Azure by Original Postayments-services" target="_blank" rel="noreferrer noopener">Coalfire Systems, who conducted assessment activities including document reviews, staff interviews, and data center walkthroughs to validate the Azure 3DE against PCI 3DS Core Security Standard 1.0. The paper also examines the relationship between the PCI Data Security Standard (PCI DSS) and 3DS Core Security Standard and defines the responsibilities shared by Azure and its customers to meet the PCI 3DS Core Security Standard requirements.

Azure PCI 3DS Attestation of Compliance

Azure’s PCI 3DS Attestation of Compliance (AoC) provides evidence that Azure complies with the PCI 3DS Core Security Standard based on an assessment conducted by a qualified 3DS assessor company and is accessible through the Service Trust Portal. Azure’s PCI 3DS AoC was issued January 29, 2021.

Notes on PCI 3DS deployment on Azure

Customers should note that different cloud service models affect how responsibilities are shared between Azure and its customers. Azure does not directly perform the functions of a 3DS Server (3DSS), 3DS Directory Server (DS), or 3DS Access Control Server (ACS), and Azure customers may host their own 3DS environment on Azure using services offered. It is the customer's responsibility to assess and understand their full scope of responsibility for implementing security controls and ensuring security controls are implemented in accordance with their compliance obligations.

New
CUSTOS WWD Water Leak Detector, Smart Water Monitor, Battery Operated Smart Home Devices, Sub-Lipstick Design Water Alarm Leak Detector, No Wi-Fi Required, 2 Pack
  • Smart Water Detector: Our water detector alarm...
  • Quick & Accurate Leak Detection: Our WWD Water...
  • All-Orientation Operation: Our water sensor alarm...
  • Compact & Easy to Install: Our wireless water...
  • Durable & Long-lasting: is made to last, with a...
New
RCA Cable 3.5mm to 2RCA Splitter RCA Jack 3.5 Cable RCA Audio Cable for Smartphone Amplifier Home Theater AUX Cable RCA 22aCotton-Braided-Cable-KIMLEYS-|10m,1pc
  • Super Durability】10000+ flex life and double...
  • Gold-plated connectors and aluminum
  • ★ Surround Sound Capability ★ Truely supports...
  • ★ Multi-device support ★ Compatible with...
New
RCA Cable 3.5mm to 2RCA Splitter RCA Jack 3.5 Cable RCA Audio Cable for Smartphone Amplifier Home Theater AUX Cable RCA 22aCotton-Braided-Cable-KIMLEYS-|3m,1pc
  • Super Durability】10000+ flex life and double...
  • Gold-plated connectors and aluminum
  • ★ Surround Sound Capability ★ Truely supports...
  • ★ Multi-device support ★ Compatible with...

Last update on 2024-04-05 / Affiliate links / Images from Amazon Product Advertising API

A 3DS entity can choose to outsource the hosting and management of its hardware security module (HSM) infrastructure to a third-party service provider if the applicable requirements are met. Entities performing 3DS functions that use the Azure environment to host their 3DE are still subject to the PCI 3DS Core Security Standard and must have their environment assessed for all applicable requirements.

Microsoft continues to be at the forefront of e-commerce solutions to leverage the power of the cloud. Our e-commerce platform lets you analyze site traffic and browse-to-buy conversion rates to define special offers and new products based on customer behavior. Create personalized shopping experiences with targeted content and offers and increase satisfaction through ongoing engagement—before, after, and at the point of sale. When demand for your products or services takes off—predictably or unpredictably—be prepared to handle more customers and more transactions automatically.

Resources