ecommerce news

Camelot Goes PCI DSS Compliant

Camelot, the licensed operator of the UK National Lottery, has implemented measures including log management, log analysis and event management solutions to secure its web based services and ensure Payment Card Industry Data Security Standard (PCI DSS) and ISO27001 compliance.

Previously, much of Camelot’s log data was processed manually, but with sales in excess of £5 billion and handling over 30 million lottery wagers per week, the company has worked alongside LogRhythm to provide an integrated security information and event management (SIEM) solution for their web based services.

The first element of the implementation will focus primarily on PCI DSS compliance, with emphasis placed on storing and analysing log data from Camelot's various payment processing applications, in line with the log data stipulations outlined in the PCI DSS.

Once PCI DSS compliance is addressed, LogRhythm will be extended to cover as many Camelot production systems as possible. It will also play a pivotal role in its network security strategy, working alongside Camelot's intrusion detection and prevention system, as well as supporting vulnerability management.

Paul Jay, head of information security at Camelot, said: “My team is responsible for ensuring a secure environment for transacting our online lottery sales which in turn generate revenue for good causes in the UK. Integrity of our services and player protection are our highest priority.”