Pci Compliance for Dummies

The Payment Card Industry Data Security Standard12. Maintain a policy that addresses information
(PCI DSS) is a protocol set up by the major creditsecurity
card companies to help protect against securityThe object of the PCI Data Security Standard is to
threats when payment cards are processed. Thecompel merchants to implement the necessary
major credit card companies formed the PCI Securitymeasures to protect cardholder information from
Standards Council to create a set of minimumhackers and con artists. That way, cardholders do
standards for merchants who store, process andnot have to worry that when they pay for
transmit cardholder data. A number of high profilesomething in a retail store or online they may be
breaches of cardholder information at the merchantinadvertently supplying con artists with the
level inspired the implementation of the PCI DSS.information they need to steal their identities and
Now, merchants of all sizes are required to be PCIbring devastation to their credit report. Obtaining PCI
compliant in order to handle payment cardcompliance is not always easy for small merchants,
transactions. The different payment brands allbut establishing and enforcing these standards can
enforce the standards. The standards (version 1.1)help prevent some identity theft horror stories.
are broken up into 6 principles and requirements forPCI compliance is assessed on an annual basis. Small
achieving each principle:companies can self-assess their compliance through a
Build and Maintain a Secure Networkquestionnaire and provide supporting documentation
1. Install and maintain a firewall configuration toto their acquiring bank. Larger companies that handle
protect cardholder datamore cardholder transactions are evaluated by
2. Do not use vendor-supplied defaults for systemQualified Security Assessors (QSAs). Updates to the
passwords and other security parametersstandards are issued periodically as criminals become
Protect Cardholder Datamore cunning and more ways to protect consumers
3. Protect stored cardholder dataare discovered.
4. Encrypt transmission of cardholder data acrossIn order to obtain PCI compliance through
open, public networksself-assessment, a merchant must have a PCI SSC
Maintain a Vulnerability Management ProgramApproved Scanning Vendor (ASV) perform a
5. Use and regularly update anti-virus softwarevulnerability scan and provide evidence of a passing
6. Develop and maintain secure systems andreport. HackerGuardian from Comodo provides
applicationsseveral levels of PCI Scan Compliancy for merchants
Implement Strong Access Control Measuresof all sizes. A PCI Free Scan Compliancy is also
7. Restrict access to cardholder data by businessoffered. The various services are differentiated by
need-to-knowhow many scans can be performed on how many IP
8. Assign a unique ID to each person with computeraddresses as well as additional features available in
accessthe upgraded services. Comodo’s Painless PCI
9. Restrict physical access to cardholder dataprogram guides you though the compliance process
Regularly Monitor and Test Networksusing a free web-based wizard that takes you
10. Track and monitor all access to networkthrough each step. This program takes all of the
resources and cardholder dataguesswork out of getting your business to be PCI
11. Regularly test security systems and processescompliant.
Maintain an Information Security Policy