Securing Credit Transactions: the Pci Data Security Standard

The Payment Card Industry (PCI) Data Securityand often used to penetrate systems.
Standard is a list of rules that define a set ofProtect Cardholder Data
regulations for credit card security over the Internet.The amount of cardholder data stored should be the
It was developed by a group of major credit cardminimum needed to do business; for example,
companies in order to standardize the waytruncating the primary account number (PAN) when
information should be transmitted and what securitythe full number is not needed, and properly disposing
features merchants and service providers needed toof data once it is no longer needed. In addition,
implement in order to bill through these credittransmission and storage of cardholder data must be
companies. The PCI Standard went into effect inencrypted across public networks.
2004.Maintain a Vulnerability Management Program
Prior to the PCI Standard, all credit card companiesNew viruses and malware are developed every day,
such as Visa and MasterCard had their own standardsand anti-virus software must be kept up-to-date in
of data security. For a merchant or service providerorder to mitigate these threats. Software applications
to use a major credit company for billing, severaland systems should be updated with the latest
different standards had to be conformed to. Thisvendor supplied security patches, and further secured
became a major hassle for companies trying to keepthrough data input validation and anti-hacking
up with evolving standards, so representatives frommeasures.
several major credit companies including Visa,Implement Strong Access Control MeasuresOnly
MasterCard, American Express, Discover, and JCBemployees who require access to data for
got together and formed the PCI Security Standardsbusiness-related reasons should be allowed access,
Council, which in turn developed the PCI Dataand each individual user must be assigned a unique
Security Standard.identification. Physical access to the servers where
It should be noted that the PCI Standard is not adata is stored must be restricted and secured as
government regulation – merchants and servicewell, because hardware can easily be stolen,
providers cannot be held legally accountable to thiscompromised, or otherwise tampered with.
standard. What can happen, however, are fines andRegularly Monitor and Test Networks
other business-related action for non-compliance.All network activity must be monitored to ensure no
Service providers, such as third party billing agents,unauthorized access occurs. If security holes are
are required to be fully compliant with the PCIfound, they must be fixed immediately. Systems and
Standard because they are responsible for theprocesses should be tested regularly to ensure the
integrity of client transactions as well as their own.security of the network.
Merchants, on the other hand, process only their ownMaintain an Information Security Policy
payments and are held to different levels ofStrict policies regarding information security must be
compliance based on the number of transactionsimplemented and enforced in order to maintain
processed per year.information security. This includes threat
The detailed requirements of the PCI Standard areassessments, definition of acceptable equipment use,
extensive and precise. The main points are separateddata backup systems, and incident response and
into twelve basic requirements, spread over sixdisaster recovery procedures.
categories, each requirement having severalThe full text of the PCI Standard can be downloaded
sub-requirements. The six main categories arein Adobe PDF format from the PCI Security
summarized below:Standards Council website.
Build and Maintain a Secure NetworkTo find out whether a particular company is
Appropriate firewall and access control measurescompliant with the PCI Standard, anyone can contact
must be implemented to secure data transmissionsone of the five major credit companies directly, or
and protect cardholder information. Vendor-suppliedvisit Visa's website to view a list of
defaults for passwords and other security featurescurrently-compliant companies.
should not be used, as these are commonly known