Ecommerce - PCI Compliance

So now that you are deciding to get involved online,access to it. Access to it should be strictly limited to
you may come across a situation where you feel it isother employees if you have any.
necessary to hold onto your customers' credit cardThis goes a step further for online transactions.
information. While I would highly recommend that youWhen you accept a credit card, all of that
do not do this unless it is absolutely necessary, Iinformation needs to be encrypted while the server
understand that there may be times where it isis processing it. It has to be encrypted to a 128 bit
needed depending on what type of business modelSSL certificate minimum.
you are running.#3: There must be a vulnerability management
The reason that I discourage you from doing this isprogram
because the major credit card providers have startedThis primarily relates to keeping everything up to
what is called PCI compliance. PCI is short fordate. Unfortunately, there are plenty of people out
Payment Card Industry. This basically is an agreementthere who enjoy working their way around firewalls
that if you accept their form of credit cards and holdand anti-virus protection. When this occurs, the
onto card holders information that you areanti-virus software should have regular updates to fix
responsible for keeping it secure. If it leeks out, theany problems it encounters. The sad part is that this
credit card companies can come to you foris an ongoing battle and you will need to keep all of
reimbursement of those illegal charges on the cards ifyour software up to date as well. You must regularly
they find that you were not handling the informationupdate your system to keep new viruses from
properly. With that said, they left plenty of loopholesinfecting your computer and leaking important data.
in there to catch companies who run into the#4: Monitoring the Network and Information is a
problem of having their system hacked to gainrequirement
access to that information. Below are several thingsYou are not allowed to simply set it up and forget
that you are required to do to make yourself PCIabout it. You are required to regularly monitor access
compliant.to this information. You will need to have each
#1: You are required to keep a secure network.person who accesses the information have a unique
This is generally done anyhow but smaller businessesidentifier that they login with. You need to monitor
can frequently overlook this. For example, you arewho access the information, at what time, and
not allowed to simply keep the information in anwhere they go, etc. This can be rather complicated,
excel file on your personal computer that is notespecially if you have multiple people with access to
secured behind a firewall and other featuresthe data. This monitoring is also used to track those
implemented to protect it. When you simply have thiswho may not be associated with your business and
information on your computer and are connected tohave malicious intentions. You might be able to catch
the internet with no security measures in place, youthis type of activity before it becomes a huge
risk having that computer hacked and having thatproblem.
information stolen. You then become the source of#5: You must maintain a security policy
the problem and could be liable for fraudulent chargesWhen you have hired employees, you must make
to those credit cards.them aware and sign a security policy that states
#2: You have an obligation to protect the information.importance of keeping this information secure. This is
Let us say that you are on a network and it isparticularly necessary if they are going to be handling
secure from outside sources other than thethe credit card information. They should know and
employees of your company. This is generallyunderstand what type of responsibility they have to
considered to be non-compliant. This informationkeep the cardholder information secure.
should only be available to people who actually need