Self Assessing Your PCI Compliance

PCI compliance is one of the most important aspectsyour company stores, processes, or transmits
in gaining consumer confidence, and a requirementcardholder data.
developed by the major credit card companies toFor example, some larger merchants are required to
help ensure safety. As commerce in today'sundergo on-site data-security assessments, but
fast-paced business environment continues to relysmaller companies that don't process as many cards
more and more on electronic transactions, whetheronly have to complete an abbreviated assessment
online or off, reliable security is going to receive even(PCI SAQ A). This shortened assessment also applies
greater importance.to those merchants who choose to outsource their
Any merchant that processes, stores, or transmitspayment processing needs.
sensitive credit card information is required to reachYour self assessment, and PCI compliance in general,
PCI compliance. This means that a merchant mustwill be further improved by employing a few general
adhere to the PCI DSS (Payment Card Industry Datatips, strategies, and practices.
Security Standard) if they intend to accept creditThe first step is to make sure you are not storing
cards. This standardized set of requirements consistsany data that you don't absolutely have to. It should
of 12 different items, which can then be separatedgo without saying (yet here I am saying it) that a
into more than 200 individual measures and controls.criminal cannot steal what isn't there in the first place.
The unfortunate corollary here is that PCI complianceCutting out that information makes you less of a
is not a simple or quick process. There is a steeptarget, and therefore makes for a safer environment
learning curve, and it is a time consuming endeavor.for the information you do have to store.
Some companies or merchants likely have alreadyWhich brings us to the next point. Some information
completed certain aspects of PCI compliance. Manymust be kept for either legal or record-keeping
requirements of the PCI DSS are, after all, commonpurposes, so this information must be properly
sense. (Which is why it can be so distressing thatidentified, isolated, and stored in a controlled,
many merchants still fail to implement those commonprotected, centralized system. This makes it easier to
sense measures.) And other companies may still havetrack and discover where the flaws were if a breach
a very long road ahead of them.should occur.
But how do you know where you stand? How doPCI compliance can be a time consuming, costly
you know how large the gap is between you andendeavor, but by approaching the process
compliance? How can you be sure that you won't bemethodically and consistently, you can start to ease
just re-doing many procedures that you might havesome of the inherent burden.
already sufficiently taken care of?The final question, then, is how much of a burden is
To help companies along those lines, the Paymentit really? Complex? Yes. Resource intensive? Certainly.
Card Industry Security Standards Council hasBut is it a burden?
developed the PCI SAQ (Payment Card Industry SelfThe way to answer this question is an analysis of
Assessment Questionnaire). This is a validation toolwhat, exactly, you can expect from failure to reach
designed to help merchants evaluate their PCIcompliance. This analysis is not complex at all. You
compliance and keep records of their compliancecan simply expect severe fines, the possibility of
activities.loosing the ability to accept credit cards at all, and,
Originally, the PCI SAQ had a sort of one-size-fits-allworst of all, the destruction of your reputation.
design, but more recently it has been adopted to fitPCI compliance is necessary and required for long
a more individualized approach. These new versionsterm success in our modern business world, and a
of the SAQ (there are five of them) were designedstructured self assessment is a great way to get
to address different scenarios depending on howstarted.