Business, E commerce.
Pci data security: the standard that raised the bar - when consumers offer their bank or credit card over the internet, phone or from some point of sale somewhere, it' s usually never a second thought for someone to wonder if that data is safe or not. Every credit card agency has its own unique standard on how transaction and personal data is handled.
Well, if it weren' t for standards that credit card companies and merchants adhere to, information could be hanging out there for any cyber thief to try their hand at grabbing. - from mastercard to visa they all touch on similar aspects of how to maintain card data properly, from merchant to card agency. In light of this type of news, the big names in the Credit Card industry coalesced their security knowledge and have come up with the standard rules, a reference for all of those involved in the transaction called the Payment Card Industry Data Security Standard. Since then big stories on the tech news circuit came about in regards to card numbers being stolen from agencies and merchants alike. How to be PCI Compliant. PCI Security Standards Organization laid out 12 main points for all the card data handlers to adhere to become PCI DSS compliant: - Regular testing of their security systems and processes. - Create and maintain an in - house policy for addressing security issues. - Restrict physical access to credit card data and owner' s information. - Have a tracking system to monitor all access to the network and credit card data. - Those who have access maintain and use an unique ID. - Keep a policy that restricts access to only a need - to - know basis. - Routinely run up to date antivirus software. - Maintain a sound secure system and application software. - Encrypt cardholder data and sensitive information across the network. - Protect data that is stored. - Create own system passwords, never use the network software' s defaults. - Maintain a sound firewall.
Credit card data is transmitted, stored and processed so there are a variety points where hackers try to interfere with the process to leak information. - any company that accepts, or stores credit, processes card information becomes pci dss compliant based on the number of transaction they process a year. For a point of reference, level one processors run 6 million or more transactions a year, while a level four would transact under 20, 00All must maintain compliance or risk heavy fines if there is a breach in their data control. There are four levels of degrees that the industry distinguishes.
No comments:
Post a Comment