border
border leftborder right
Webmaster resources, webmaster tools  - Article Details
CATEGORIES
Statistics
  • Active Links: 7752
  • Pending Links: 1047
  • Todays Links: 0
  • Total Articles: 60
  • Total Categories: 13
  • Sub Categories: 553
top left cornertop right corner

Pci Dss Compliance Do S and Don'ts

Date Added: September 17, 2008 08:59:52 AM
Author: Phil Williams
Category: eCommerce



Pci Dss Compliance Do S and Don'ts



Author: hubert o donoghue


PCI DSS Dos





  1. Secure your network, deploy firewalls and disable unnecessary services and protocols. Even if you are a Card Present merchant, you most likely have internet connectivity which may indirectly expose sensitive data. Be particularly careful with wireless (remember TJX)





  2. When you make changes to systems carry out security testing to ensure you are not introducing vulnerabilities into your card environment.





  3. Get rid of card data if not absolutely needed. If needed apply strong encryption to both data and data encryption keys. Have a strict key management policy and if you transmit data make sure the link is encrypted.






  4. Encrypt and securely store all data back-ups – make sure 3rd party providers are PCI DSS compliant.





  5. Restrict access to card data on a need-to-know basis





  6. Deploy comprehensive monitoring tools to monitor activity in your systems and networks – use tools so that suspicious activity is alerted





  7. Document your information security policies and follow them. Don't buy “off-the-self” PCI DSS policy statements – they may not work for your organisation and if you can't follow them they are useless to you.





  8. If you develop your own payment solutions and interfaces document and implement secure coding standards and make sure they're followed.





  9. Get PCI DSS compliance statements from your suppliers and check the status of 3rd party applications you use for PA-DSS compliance (Payment Application Data Security Standard).





  10. Apply strict physical access control to your data centre.




 


PCI DSS don'ts:






  1. Never ever store Track, PIN of CVV data in either logs or in the database.





  2. If possible, don't store card data after authorisation in logs or in the database.





  3. If your servers which store, transmit or process data are co-located or hosted don't assume that the provider's generic firewall is adequate. You may be on the same network as hundred of insecure servers which could compromise you.





  4. Don't allow undocumented or untested change to take place in your environment – it could open up exposures.





  5. Don't allow staff to download data containing full card numbers for use in the general office environment or to store off on laptops for analysis.





  6. Don't allow production card data to be used in test environments.





  7. Don't allow card data to be sent via unencrypted email.





  8. Don't leave data files on file servers – move them off to secure servers for processing and delete them when processed




 


Hubert O'Donoghue, Managing Partner O-C Group


For more info go to: http://www.o-cgroup.com/service-pci.shtml


 



Article Source: Link



About the Author:

Hubert O'Donoghue is a globally acknowledged expert in the Payments Industry and has owned and managed Payment Processing Companies providing processing services in all regions. He now provides consulting services to Merchants, Card Issuers and Acquirers and Payment Service providers on all issues relating to Payments and in particular, Payment Card Industry Data Security Standard PCI DSS


Ratings:

You must be logged in to leave a rating.

Average rating: ( votes)

Comments:

No Comments Yet.

You must be logged in to leave a comment.


bottom corner leftbottom corner right
Search
Users & Authors
Login  |  Register
Articles
5 Reasons Why an Internet Business is Rewarding
The idea of setting up a website has been rolling around in your head for quite some time, but you are still a little nervous. The Internet is waiting for you and here are some reasons that will give you the nudge you need to get started....
What’s a Fair Price for Your Internet Ebiz Item?
If you charge too much you will probably miss your Internet audience or only snag a few of them, however, if you charge too little, you'll leave money on the website table, this article gives you practicle advice on how to price your items....
5 Traits That Can Kill Your Internet Business
If you can avoid some of the common mistakes of Internet marketing and website building, you'll have a much better chance of having an Internet business that will succeed, despite all of the competition, here a few traits that you should avoid if...
Self-assessing Your Pci Compliance
No matter how large or small your business is, if you take credit/debit cards or paycards from American Express, Discover, MasterCard and/or Visa, you will have to meet PCI Data Security Standards. These preventative measures are used to protect...
Pci Compliance for Dummies
The Payment Card Industry Data Security Standard (PCI DSS) is a protocol set up by the major credit card companies to help protect against security threats when payment cards are processed. The major credit card companies formed the PCI Security...