Sabtu, 26 Mei 2012

A Guide to the PCI Compliance Standards

By Kate Bailey


Every business should make maintaining PCI compliance a priority in order to safeguard customer information. From restaurant to retail, service and government industries, every corporation that deals with card payments must ensure that it is following the PCI compliance standard. As technology continues to evolve, so must our commitment to securing customer data against those who would steal it and engage in fraudulent activity.

One of the internet's biggest issues is security; as an e-retailer you need to ensure that your online shop is safe and secure throughout the payment process, handling sensitive information efficiently and securely. This brings me on to this week's blog topic; PCI Data Security Standards (PCI DSS). In laymen's terms this is the framework and set of regulations compiled by the PCI Security Standards Council within which online merchants must operate in order to be compliant. It demands that merchants develop a tenacious online card payment system, incorporating processes for prevention, detection and appropriate responses to security incidents.

Level 1: Your company has over 6 million Visa and/or Mastercard transactions processed per year. This level requires yearly on-site reviews by an internal auditor, and a network scan by an approved scanning vendor (ASV). Level 2: You have 1 million to 6 million Visa and/or Mastercard transactions processed per year. You must complete a Self-Assessment Questionnaire (SAQ) annually, and this level requires a network scan with an approved scanning vendor.

Level 3: Your company has 20,000 to 1 million Visa and/or Mastercard e-commerce transactions processed per year. You must complete a Self-Assessment Questionnaire (SAQ) annually, and this level also requires a network scan with an approved scanning vendor. Level 4: You have less than 20,000 Visa and/or Mastercard e-commerce transactions processed per year. Must complete a Self-Assessment Questionnaire (SAQ) annually, and requires a network scan with an approved scanning vendor.

When you stay compliant, you are part of the solution - a united, global response to fighting payment card data compromise. Compliance has indirect benefits as well. Through your efforts to comply with PCI Security Standards, you'll likely be better prepared to comply with other regulations as they come along, such as HIPAA, SOX, etc.




About the Author:



Jasa Pembuat toko Online

Tidak ada komentar:

Posting Komentar