PCI Compliance
Payment Card Industry Data Security Standards (PCIDSS)
PCI Compliance defines the standard for securing Visa and MasterCard cardholder data, wherever it is located. Compliance is required of all entities storing, processing, or transmitting cardholder data. Acquiring Banks must comply with PCI and are responsible for ensuring the compliance of their merchants for all payment channels, including retail (brick-and-mortar), mail/telephone-order, and ecommerce.
The PCI Requirements
A defined list of 12 basic security requirements with which all Merchants must comply and detailed sub-requirements, which tie back to the basic requirements:
- Install and maintain a working firewall to protect data
- Keep security patches up-to-date
- Protect stored data
- Encrypt data sent across public networks
- Use and regularly update anti-virus software
- Restrict access by "need to know"
- Assign unique ID to each person with computer access
- Don't use vendor-supplied defaults for passwords and security parameters
- Track all access to data by unique ID
- Regularly test security systems and processes
- Implement and maintain an information security policy
- Restrict physical access to data
|